Ransomware vs Phishing
Ransomware
1,216
statistics from 113 sources
Phishing
444
statistics from 102 sources
Latest Ransomware
Cloud-related threats (40%), third-party breaches (34%), and ransomware (33%) rank after AI as major preparedness gaps.
49% of organizations that experienced or suspected a deepfake attack also experience follow-on cyberattacks such as ransomware.
Ransomware attacks on manufacturers have more than doubled since 2023.
The average manufacturing or distribution ransomware victim scores 0.552 on the RSI.
In the first half of 2026, ransomware attacks on manufacturers increased nearly 40% year over year.
83% of organizations fell victim to a successful ransomware attack in the last 24 months, up from 66% in 2024.
Of organizations hit by ransomware, 75% experience multiple service interruptions.
83% of technology leaders view backup storage as the last line of defense against ransomware.
Twelve vulnerabilities carry confirmed "multi-nexus" attribution, being independently exploited across five distinct threat categories (China, Russia, DPRK, Iran-nexus, and criminal actors).
More than half of mid-market ransomware victims generate less than $50M in annual revenue.
Mid-market organizations accounted for approximately 72–75% of ransomware victims each year.
Compromised credentials accounted for 67% of ransomware intrusions investigated by Beazley Security, down from 74% in Q1.
Public ransomware leak-site postings totaled 2,268, remaining nearly 60% above Q2 2025.
73% of ransomware attacks in North America and Europe hit companies with $10M to $1B in annual revenue from 2023 through the first half of 2026.
27% of healthcare organizations cite cybersecurity threats and ransomware as the #1 network challenge, 23% cite staffing shortages and lack of expertise, 20% cite rising operational and compliance costs, 16% cite network reliability impacting clinical systems, and 15% cite aging or fragmented infrastructure.
Latest Phishing
Between 89% and 95% of email phishing attachments lead to credential theft efforts.
93% of voice phishing attacks keep the victim on the line long enough for social engineering to begin.
50% of security leaders rank threat detection and alerting among their top AI-for-security priorities, followed by fraud detection (43%) and phishing detection and response (42%).
Organisations are most comfortable authorising autonomous agents for threat intelligence enrichment and correlation (49%), phishing email quarantine or deletion (47%), and malware removal and system remediation (46%).
Senior executives specializing in IP law rate phishing as a top concern at 39%
79% of chief information security officers report at least one e-mail phishing, spear-phishing, or business e-mail compromise incident in the last 12 months.
Custom fake CAPTCHAs grow by 437% from Q1 to Q2 2026.
OAuth device-code phishing surges by 483.7% from Q1 to Q2 2026.
Google's name appears in scam content at least twice as often as Amazon's name.
39% of phishing messages featured novel social engineering techniques.
Vishing intrusions increased by 2x in 1H 2026.
17% of reported cybercrime cases in Africa in 2025 involved online scams, including phishing.
Monthly device code phishing attempts increased 15x in 1H 2026.
In the first half of 2026, 67% of phishing emails passed DMARC.
VIP users were targeted in 25.8% of phishing attacks.