Ransomware vs Phishing

Ransomware

814

statistics from 83 sources

Phishing

331

statistics from 74 sources

Latest Ransomware

70% of global ransomware activity targets English-speaking countries.

RansomwareRansomware Targets

In the second half of 2025, 40% of all ransomware attacks targeted US-based companies.

RansomwareRansomware TargetsUnited States

In the second half of 2025, ransomware attacks against Canada and the UK accounted for a combined 30% of attacks.

RansomwareRansomware TargetsCanadaUnited Kingdom

Scattered Spider accounted for 42.9% of all actor-related alerts in the second half of 2025.

Threat ActorsRansomwareScattered Spider

44% of attacks in the Automotive and Smart Mobility ecosystem are ransomware-related, more than double the volume in 2024.

RansomwareAutomotiveSmart Mobility

90% of ransomware incidents exploit firewalls through a CVE or a vulnerable account.

RansomwareFirewallCVEVulnerable Account

The fastest ransomware case observed, involving Akira ransomware, takes just three hours from breach to encryption.

RansomwareBreachEncryptionAkira

96% of incidents involving lateral movement end with the release of ransomware.

RansomwareLateral Movement

Ransomware attacks against industrial organizations increased 64% year-over-year.

RansomwareIndustrial Security

Organizations with comprehensive OT visibility detect and contain OT ransomware incidents in an average of 5 days, compared to the industry-wide average of 42 days.

Operational TechnologyIncident ResponseRansomwareOT Ransomware

The average dwell time for ransomware in OT environments is 42 days.

RansomwareOperational TechnologyDwell Time

Manufacturing accounts for more than two-thirds of all ransomware victims.

ManufacturingRansomwareIndustrial Security

The number of ransomware groups targeting industrial organizations increased 49% year-over-year to 119 groups, collectively impacting 3,300 organizations globally.

RansomwareIndustrial SecurityOperational Technology

In 2025, 55% of Chief Information Security Officers (CISOs) in the US and UK reported that their organization experienced a cyberattack, ransomware infection, compromise, or data breach that rendered mobile, remote, or hybrid endpoint devices inoperable.

RansomwareData BreachesEndpointUKUS

In 2025, 61% of CISOs indicated that their organization’s board and C-suite expect the cybersecurity group to guarantee zero breaches and ransomware incidents.

Board ExpectationsBreachRansomware USUK
View all Ransomware

Latest Phishing

88% of internal audit leaders identify AI-powered phishing attacks as a top risk.

The Internal Audit Foundation and AuditBoardInternal Audit and AI-Enabled Fraud·2mo ago
AI-Powered PhishingCybersecurity RiskInternal Audit

51% of organizations have faced sophisticated, personalized phishing emails powered by deepfake technology.

PhishingDeepfakeSocial Engineering

In Q4 2025, callback phishing increased from 3% to 18% of all phishing incidents, a 500% spike.

VIPRE Security GroupQ4 2025 Email Threat Trends Report·3mo ago
PhishingCallback PhishingEmail SecuritySocial Engineering

82% of malicious files have unique hashes that traditional pattern-matching fails to detect.

Malicious FilesThreat DetectionPhishingEmail Attack

Credential phishing campaigns using .es domains increase 51 times year-over-year, with the .es top-level domain jumping from the 56th to the 3rd most-abused TLD.

PhishingDomain AbuseCredential TheftCredential PhishingEmail Security

76% of initial infection URLs in abalyzed phishing attacks were unique and have not appeared in other campaigns across Cofense's customer base.

PhishingMalicious URLsEmail AttackEmail Security

Conversational attacks comprise 18% of all malicious emails.

PhishingEmail SecurityEmail Attack

In 2025, a malicious email attack occurs every 19 seconds, more than doubling from 2024’s pace of one every 42 seconds.

PhishingEmail SecurityEmail Attack

Abuse of legitimate remote access tools increased by 900% by volume.

Remote Access ToolsPhishingEmail SecurityEmail Attack

Fifty percent of affected consumers cite immediate financial fraud as their primary fear, and 54 percent of consumers report an increase in targeted phishing attempts after a breach (2025)

Financial FraudPhishing

Eighty-eight percent of consumers who received a data breach notice experience at least one negative consequence after a breach; 40 percent experience an increase in phishing or scam attempts; 49 percent experience an increase in spam emails or robocalls; 40 percent experience attempted takeover of an existing account (2025)

Consumer HarmPhishingSpam

Clicks on phishing links decreased by 27%, from 119 per 10,000 users last year to 87 per 10,000 users this year.

PhishingPhishing LinksUser Behavior

87 out of every 10,000 users clicked on a phishing link each month in 2025.

PhishingPhishing LinksUser Behavior

77% of advanced email attacks failed SPF, DKIM, or DMARC authentication yet still reached inboxes.

Email SecurityEmail ThreatsPhishingDMARC

Approximately 45% of advanced email attacks showed indicators of AI assistance, projected to rise to 75–95% within the next 18 months

Email SecurityEmail ThreatsAIPhishing
View all Phishing