Statistics

🪝 Phishing Statistics 2026: 46 Data-Backed Facts

By Ateeq Y Tanoli, BestPasswordGenerator.org · 31 July 2026 · 11 min read
Bottom Line Up Front: Phishing is now the front door to most cyberattacks. It was the most-reported cybercrime to the FBI in 2024 (193,407 complaints), the most common cause of data breaches in 2025 (16% of incidents, averaging $4.8M each), and it moves fast: the median user clicks a phishing link in 21 seconds and 1 in 3 who click then type in their credentials (Verizon DBIR). The 46 statistics below, each tied to a named primary source, map how big phishing has become, how much it costs, how AI is scaling it, and which defenses actually work.

These phishing statistics are drawn from primary sources published in 2024, 2025 and 2026: the FBI Internet Crime Complaint Center (IC3) Annual Report, the Verizon Data Breach Investigations Report (DBIR), the Microsoft Digital Defense Report, the IBM Cost of a Data Breach Report, the APWG Phishing Activity Trends Reports, Google, Proofpoint, the FIDO Alliance and NIST. Every figure is attributed inline so journalists, researchers and AI assistants can cite the original source.

They answer the questions people actually ask: how common is phishing, how fast do people fall for it, how much money is lost, and what stops it? Where a number depends on methodology or reporting year, the source and year are stated so you can verify it.

Key Statistics at a Glance

193,407
phishing/spoofing complaints — the #1 cybercrime reported to the FBI in 2024 (FBI IC3)
21 sec
median time for a user to click a phishing link (Verizon DBIR 2025)
1 in 3
users who click a phishing link then enter their credentials (Verizon DBIR 2025)
16%
of data breaches start with phishing — the single most common cause (IBM 2025)
$4.8M
average cost of a phishing-initiated data breach (IBM 2025)
>99%
of identity attacks blocked by multi-factor authentication (Microsoft)

The Scale of Phishing

Phishing is not a niche threat — it is an industrial-scale flood of email, text and voice lures. The largest email and identity providers measure it in the billions.

  1. Google blocks around 15 billion unwanted emails every day, stopping more than 99.9% of spam, phishing and malware before it reaches inboxes. (Google)
  2. Microsoft tracks more than 600 million identity attacks per day, and over 99% of them are password-based. (Microsoft Digital Defense Report 2024)
  3. Microsoft blocks more than 7,000 password attacks every second — many delivered by phishing. (Microsoft Digital Defense Report 2024)
  4. The phishing volume Microsoft tracks doubled in two years: from about 1 million (2021) to 1.5 million (2022) to 2 million (2023). (Microsoft Digital Defense Report 2024)
  5. APWG logged 989,123 phishing attacks in Q4 2024 and 1,130,393 in Q2 2025 — the busiest quarter since Q2 2023. (APWG Phishing Activity Trends Reports)
  6. Phishing rose 13.8% heading into 2026, from 853,244 attacks in Q4 2025 to 971,181 in Q1 2026. (APWG)
  7. Proofpoint detects roughly 66 million targeted business email compromise (BEC) attacks every month. (Proofpoint, State of the Phish 2024)
  8. 73% of organizations faced at least one BEC attempt in the prior year. (Proofpoint, State of the Phish 2024)

Phishing as the Entry Point for Breaches

When a breach happens, phishing is now the most likely way it started — and one of the most expensive. The IBM and Verizon reports quantify the cost and the human factor.

  1. Phishing was the most common cause of data breaches in 2025, at 16% of incidents — overtaking stolen credentials. (IBM, Cost of a Data Breach 2025)
  2. Phishing-initiated breaches cost an average of $4.8 million. (IBM 2025)
  3. Breaches that began with compromised credentials cost $4.67 million on average. (IBM 2025)
  4. The global average data-breach cost was $4.44 million; in the United States it hit a record $10.22 million. (IBM 2025)
  5. Phishing breaches take about 254 days on average to identify and contain. (IBM 2025)
  6. The human element is present in 62% of all breaches — phishing, misuse and error. (Verizon DBIR 2026)
  7. Social engineering drove 16% of breaches, with email the primary delivery channel. (Verizon DBIR 2025)
  8. Stolen credentials were the initial access vector in 22% of breaches — the fuel phishing collects. (Verizon DBIR 2025)
  9. 88% of basic web-application attacks involve stolen credentials. (Verizon DBIR 2025)
  10. Just 8% of employees account for 80% of security incidents, showing how a few repeat clickers drive most risk. (Verizon DBIR 2025)

How Fast Phishing Works

The gap between a phishing email landing and a victim reacting is measured in seconds, not hours. The chart below shows how phishing attack volume has climbed quarter after quarter.

Global phishing attacks per quarter (APWG Phishing Activity Trends Reports)
Q2 2024877,536
Q3 2024932,923
Q4 2024989,123
Q1 20251,003,924
Q2 20251,130,393

Data visualisation: a horizontal bar chart of reported phishing attacks per quarter from Q2 2024 to Q2 2025. Volume rises steadily from 877,536 to 1,130,393 — the largest quarterly total the APWG had recorded since Q2 2023. Bar lengths are scaled to the Q2 2025 peak.

  1. The median time to click a phishing link is 21 seconds from the moment the email is opened. (Verizon DBIR 2025)
  2. The median time to report a phishing email is 28 minutes — a wide window in which credentials are already gone. (Verizon DBIR 2025)
  3. 1 in 3 users who click a phishing link go on to enter their credentials on the attacker's page. (Verizon DBIR 2025)
  4. The median phishing-simulation click rate sits at about 1.5% and has plateaued despite years of awareness training. (Verizon DBIR 2025)
  5. 68% of employees knowingly take actions, such as reusing or sharing passwords, that leave them exposed to phishing. (Proofpoint, State of the Phish 2024)

The U.S. Picture: FBI IC3 2024

The FBI's Internet Crime Complaint Center gives the clearest year-on-year read on reported cybercrime in the United States — and phishing leads it.

  1. Phishing/spoofing was the most-reported cybercrime of 2024, with 193,407 complaints. (FBI IC3, 2024 Internet Crime Report)
  2. That is more than double the next category (extortion) and three times personal data breaches, which drew 64,882 complaints. (FBI IC3, 2024)
  3. IC3 received 859,532 complaints in total in 2024. (FBI IC3, 2024)
  4. Reported losses topped $16.6 billion in 2024, up 33% year on year — a record. (FBI IC3, 2024)
  5. Reported phishing/spoofing losses exceeded $70 million in 2024. (FBI IC3, 2024)
  6. Business email compromise caused $2.77 billion in losses across 21,442 complaints in 2024. (FBI IC3, 2024)
  7. The FBI now calls BEC "the $55 billion scam," its estimate of global exposed losses from 2013 to 2023. (FBI IC3 Public Service Announcement, 2024)
  8. Investment fraud was the costliest cybercrime by dollars ($6.5B+), but phishing still led by complaint volume — a reminder of how widely it is used. (FBI IC3, 2024)

AI-Powered and Multi-Channel Phishing

Generative AI has removed the two things that used to limit phishing: the time to write a convincing lure and the language barrier. Attacks are now faster, cleaner and spreading beyond email into QR codes, SMS and voice.

  1. Generative AI cut phishing-email creation from about 16 hours to 5 minutes, collapsing the cost of a convincing lure. (IBM 2025)
  2. AI was used in 16% of breaches, largely to power phishing and deepfakes. (IBM 2025)
  3. Among AI-assisted initial-access breaches, phishing was the single largest category at 44%. (Verizon DBIR 2026)
  4. Mimecast detected 716,306 unique malicious QR codes in Q3 2025, up 13% from 635,672 the previous quarter. (Mimecast, 2025)
  5. Roughly 12% of phishing attacks carried a QR code ("quishing") in 2025, a channel that slips past many email filters. (Mimecast, 2025)

Why Phishing Pays Off: Password Reuse

A single phished password is dangerous only because so many people use it in more than one place. Reuse turns one successful phish into access to many accounts — which is why the defenses below focus on unique credentials and phishing-resistant sign-in.

  1. 62% of people always or mostly reuse the same password or a variation across accounts. (LastPass, Psychology of Passwords)
  2. 66% of Americans reuse passwords across multiple accounts, so one phished login can unlock several. (Google/Harris Poll)

The Defenses That Actually Stop Phishing

The good news: phishing has well-tested countermeasures. Multi-factor authentication, passkeys and a password manager that only fills credentials on the real domain each break a different link in the attack chain.

  1. Multi-factor authentication blocks over 99% of identity-based attacks, even when the attacker already has the password. (Microsoft)
  2. Yet only 41% of Microsoft enterprise users are protected by MFA, leaving most accounts phishable. (Microsoft Digital Defense Report 2024)
  3. About 5 billion passkeys are now in use worldwide as passwordless sign-in scales. (FIDO Alliance, 2026)
  4. 90% of people are now aware of passkeys. (FIDO Alliance, 2026)
  5. 75% of people have enabled a passkey on at least one account. (FIDO Alliance, 2026)
  6. Passkeys are phishing-resistant by design — the private key never leaves your device and will not authenticate to a look-alike domain. (FIDO Alliance / W3C WebAuthn)
  7. Only about 30% of organizations use passkeys as the primary workforce sign-in; 57% still rely on passwords or another phishable method. (FIDO Alliance, 2026)
  8. NIST advises screening new passwords against known-breach lists and favouring length over complexity to blunt credential attacks. (NIST, SP 800-63B)

🛡️ Cut off phishing at the source: unique passwords everywhere

Phishing only spreads when a stolen password unlocks more than one account. A password manager fixes that by giving every login its own strong password — and it only autofills on the genuine domain, so it will not hand your credentials to a look-alike phishing site. NordPass adds phishing-resistant passkeys, a data-breach scanner and secure sharing.

Get NordPass →

Affiliate link — we may earn a commission at no extra cost to you. See our disclosure.

What These Numbers Mean

Read together, the 46 statistics tell one story: phishing has become the default way attackers get in, and speed is on their side. It leads the FBI's complaint list (193,407), causes the most breaches (16%), and works in seconds (21 to click, 1 in 3 hand over credentials). AI has made lures cheaper and cleaner, and the attack has spread from email into QR codes, SMS and voice. But the defenses are unglamorous and effective: MFA stops over 99% of identity attacks, passkeys remove the phishable password entirely, and a password generator plus a manager ensures a phished password can only ever unlock one account. For the wider picture, see our roundups of password security statistics, password reuse statistics and two-factor authentication statistics, plus our explainer on credential stuffing.

Frequently Asked Questions

How common is phishing in 2026?

Extremely common. Phishing/spoofing was the most-reported cybercrime to the FBI in 2024, with 193,407 complaints — more than double the next category. The APWG recorded over 1.1 million phishing attacks in a single quarter (Q2 2025), and Google blocks around 15 billion unwanted emails a day. Microsoft tracks more than 600 million identity attacks daily, over 99% of them password-based.

What percentage of data breaches start with phishing?

Phishing was the most common cause of data breaches in 2025, accounting for 16% of incidents, according to the IBM Cost of a Data Breach Report. Those breaches cost an average of $4.8 million and take about 254 days to identify and contain. The Verizon DBIR adds that the human element — largely phishing and error — is present in 62% of all breaches.

How fast do people fall for phishing emails?

Very fast. The Verizon 2025 DBIR found the median time to click a phishing link is 21 seconds, and 1 in 3 users who click then enter their credentials on the fake site. Because the median time to report a phishing email is 28 minutes, attackers usually have the credentials long before anyone raises the alarm.

How much money is lost to phishing?

Reported U.S. cybercrime losses topped $16.6 billion in 2024, up 33% year on year (FBI IC3). Phishing/spoofing losses alone exceeded $70 million, and business email compromise — a targeted form of phishing — caused $2.77 billion across 21,442 complaints. The FBI estimates BEC has exposed roughly $55 billion globally from 2013 to 2023.

Does multi-factor authentication stop phishing?

It stops most of it. Microsoft reports that MFA blocks over 99% of identity-based attacks, even when the attacker already has the correct password. It is not perfect — adversary-in-the-middle phishing kits can relay one-time codes — which is why phishing-resistant passkeys are the stronger option where available. Still, only about 41% of enterprise users have MFA enabled, so the biggest gain for most people is simply turning it on.

What is the best defense against phishing?

Layer three things. First, use a unique, strong password for every account so a single phished login cannot unlock others — a generator and password manager automate this, and the manager only autofills on the genuine domain. Second, turn on MFA everywhere. Third, adopt passkeys where available: they are phishing-resistant by design because the private key never leaves your device and will not authenticate to a fake site. NIST also recommends screening passwords against known-breach lists.

Methodology and Sources

Every statistic on this page is attributed inline to the organisation that published it, with the year of the source where applicable. Figures are quoted as reported by each primary source and were current as of July 2026. Primary sources:

Note: figures are reproduced as published by each source and are not combined across differing samples or reporting years. Vendor telemetry (Google, Microsoft, Proofpoint, Mimecast) reflects each provider's own visibility. Where a survey or report year is relevant it is stated with the figure so readers can verify it.

More Password Security Tools

🔑 SecureKeyGen⚔️ TitanPasswords🔐 Free Strong Password⚡ Instant Password🗝️ Iron Vault Keys🔑 Random Pwd Tool👨‍👩‍👧‍👦 Safe Pass Builder👪 Trusty Password
We use cookies to improve your experience. Learn more

🛡️ Security Picks This Week

Hand-picked security tools — updated weekly.

YubiKey 5 NFC

YubiKey 5 NFC

Hardware security key — phishing-proof 2FA for all your accounts.

Check price →
Yubico Security Key C NFC

Yubico Security Key C NFC

USB-C 2FA key — affordable FIDO2/WebAuthn authentication.

Check price →
TP-Link ER605 VPN Router

TP-Link ER605 VPN Router

Multi-WAN VPN gateway — secure every device on your network.

Check price →

As an Amazon Associate we earn from qualifying purchases.