Phishing vs Data Breach
Phishing
444
statistics from 102 sources
Data Breach
545
statistics from 128 sources
Latest Phishing
Between 89% and 95% of email phishing attachments lead to credential theft efforts.
93% of voice phishing attacks keep the victim on the line long enough for social engineering to begin.
50% of security leaders rank threat detection and alerting among their top AI-for-security priorities, followed by fraud detection (43%) and phishing detection and response (42%).
Organisations are most comfortable authorising autonomous agents for threat intelligence enrichment and correlation (49%), phishing email quarantine or deletion (47%), and malware removal and system remediation (46%).
Senior executives specializing in IP law rate phishing as a top concern at 39%
79% of chief information security officers report at least one e-mail phishing, spear-phishing, or business e-mail compromise incident in the last 12 months.
Custom fake CAPTCHAs grow by 437% from Q1 to Q2 2026.
OAuth device-code phishing surges by 483.7% from Q1 to Q2 2026.
Google's name appears in scam content at least twice as often as Amazon's name.
39% of phishing messages featured novel social engineering techniques.
Vishing intrusions increased by 2x in 1H 2026.
17% of reported cybercrime cases in Africa in 2025 involved online scams, including phishing.
Monthly device code phishing attempts increased 15x in 1H 2026.
In the first half of 2026, 67% of phishing emails passed DMARC.
VIP users were targeted in 25.8% of phishing attacks.
Latest Data Breach
About half of organisations have fully implemented data classification policies (49%) and data loss prevention across key egress channels (48%).
Among healthcare organizations that experience an identity-related incident, 33% incur costs above $250,000, compared with 21% in other industries.
At least 21% of users are logging in with a credential that has appeared in a known data breach.
62% of UK organisations experience material data loss, down from 74% in 2025.
Among UK organisations that experienced material data loss, post-attack recovery costs rose to 36% from 26% in 2025.
Among UK organisations that experienced material data loss, compromised insiders were the leading cause at 48%, with malicious or criminal insiders cited by 44% and careless insiders by 37%.
76% of organizations report their largest data loss event exceeded their Recovery Point Objective (RPO) targets.
In the second quarter (Q2) of 2026, analysis of publicly disclosed victim data and ransomware groups’ postings on Data Leak Sites (DLS) identified 1,140 ransomware incidents affecting industrial organizations worldwide, a 12% increase over the 1,020 incidents recorded in Q1.
In the past 12 months, 27% of organizations reported data breaches tied to AI use.
Sensitive information disclosure ranks as the second biggest LLM threat for a second consecutive year.
11% of reported cybercrime cases in Africa in 2025 involved data breaches.
AI-enabled malicious breaches increased by 56% over the previous year.
Financial services breaches cost on average $6.3 million.
73% of organizations have found their workforce’s credentials in breach, Dark Web, or infostealer data in the past year