Phishing vs Data Breach
Phishing
436
statistics from 98 sources
Data Breach
542
statistics from 127 sources
Latest Phishing
Google's name appears in scam content at least twice as often as Amazon's name.
39% of phishing messages featured novel social engineering techniques.
Vishing intrusions increased by 2x in 1H 2026.
17% of reported cybercrime cases in Africa in 2025 involved online scams, including phishing.
Monthly device code phishing attempts increased 15x in 1H 2026.
In the first half of 2026, 67% of phishing emails passed DMARC.
VIP users were targeted in 25.8% of phishing attacks.
The three most vulnerable industries at baseline are Healthcare & Pharmaceuticals (42.7%), Insurance (38.1%), and Retail & Wholesale (36%).
Organizations reduce phishing susceptibility by 79% after one year of consistent security awareness training.
Before any training, roughly one in three employees is likely to engage with a phishing attempt.
Almost 86% of phishing attacks contain AI-generated elements.
The number of mobile devices where employees clicked a malicious link grew 110% in 2025 compared to 2024.
Phishing events detected on employee mobile devices have grown 380% since January 2025.
The ARToken panel exposed 80+ API endpoints for device code phishing, primary refresh token persistence, email access, BEC operations, and SharePoint exfiltration.
Phishing was the primary means of gaining initial access in over half of Cisco Talos Incident Response engagements this quarter, up from approximately one-third of engagements last quarter.
Latest Data Breach
62% of UK organisations experience material data loss, down from 74% in 2025.
Among UK organisations that experienced material data loss, compromised insiders were the leading cause at 48%, with malicious or criminal insiders cited by 44% and careless insiders by 37%.
95% of UK CISOs at organisations experiencing material data loss say departing employees played a role.
76% of organizations report their largest data loss event exceeded their Recovery Point Objective (RPO) targets.
In the second quarter (Q2) of 2026, analysis of publicly disclosed victim data and ransomware groups’ postings on Data Leak Sites (DLS) identified 1,140 ransomware incidents affecting industrial organizations worldwide, a 12% increase over the 1,020 incidents recorded in Q1.
In the past 12 months, 27% of organizations reported data breaches tied to AI use.
Sensitive information disclosure ranks as the second biggest LLM threat for a second consecutive year.
11% of reported cybercrime cases in Africa in 2025 involved data breaches.
AI-enabled malicious breaches increased by 56% over the previous year.
Financial services breaches cost on average $6.3 million.
73% of organizations have found their workforce’s credentials in breach, Dark Web, or infostealer data in the past year
Nearly 693,000 records are known to have been breached in the confirmed education-sector ransomware attacks in H1 2026.
Only 24% of H1 2026 breach notices contained attack-vector details, the lowest rate ever recorded by the ITRC.
Financial services recorded the highest frequency of compromises by sector at 387.