KnowBe4

175 STATS13 REPORTS

All Statistics

93% of cybersecurity leaders reported incidents caused by cybercriminals exploiting employees.

KnowBe4The State of Human Risk 2025·Dec 10, 2025
Human RiskInsider Threats

Email-related incidents increased by 57%.

KnowBe4The State of Human Risk 2025·Dec 10, 2025
Email SecurityIncident Trends

90% of organizations experienced incidents caused by employee mistakes.

KnowBe4The State of Human Risk 2025·Dec 10, 2025
Human ErrorRisk Management

97% of cybersecurity leaders feel the need for increased budget allocations to bolster the security of the human element.

KnowBe4The State of Human Risk 2025·Dec 10, 2025
Budget Human Risk

Incidents relating to the human element surged by 90%.

KnowBe4The State of Human Risk 2025·Dec 10, 2025
Human RiskSecurity Incidents

AI applications experienced a 43% increase in security incidents over the past 12 months, marking the second-largest increase across all channels.

KnowBe4The State of Human Risk 2025·Dec 10, 2025
AI SecurityIncident Trends

45% of cybersecurity leaders cited constantly evolving AI threats as their greatest challenge when tackling behavioral risk.

KnowBe4The State of Human Risk 2025·Dec 10, 2025
AI ThreatsBehavioral RiskHuman Risk

64% of organizations fell victim to external attacks that exploited employees through email.

KnowBe4The State of Human Risk 2025·Dec 10, 2025
Email SecurityExternal AttacksHuman Risk

Malicious insiders accounted for incidents at 36% of organizations.

KnowBe4The State of Human Risk 2025·Dec 10, 2025
Insider ThreatsRisk ManagementMalicious Insiders

56% of employees are unhappy with their company's approach to AI tools, which can drive them toward unsanctioned platforms and creating 'shadow AI' risks.

KnowBe4The State of Human Risk 2025·Dec 10, 2025
AI ToolsEmployee SentimentShadow AI

32% of organizations reported increased incidents related to deepfakes.

KnowBe4The State of Human Risk 2025·Dec 10, 2025
DeepfakesIncident Trends

In 2025, cybercriminals increased their abuse of legitimate platforms like QuickBooks, Zoom, SharePoint, and PayPal by 67% year-to-date.

KnowBe4KnowBe4 Uncovers Surged Abuse of Legitimate Platforms by Cybercriminals in 2025.html·Oct 29, 2025
Phishing

In 2025, 77% of callback numbers used AI-generated voices, while 69% of vishing attacks were financially motivated, requesting bank detail changes, fraudulent refunds, or transfers.

KnowBe4KnowBe4 Uncovers Surged Abuse of Legitimate Platforms by Cybercriminals in 2025.html·Oct 29, 2025
PhishingAI

Phone-based vishing attacks increased by 449% in 2025 compared to 2024, with phone numbers appearing as the sole payload in 5.5% of phishing emails.

KnowBe4KnowBe4 Uncovers Surged Abuse of Legitimate Platforms by Cybercriminals in 2025.html·Oct 29, 2025
PhishingPhonevishing

65% of organisations plan to increase cybersecurity budgets.

KnowBe4Navigating Cyber Threats Infosecurity Europe 2025 Findings·Aug 26, 2025
Budget

32% of respondents believe that AI-based cybersecurity tools have the greatest impact.

KnowBe4Navigating Cyber Threats Infosecurity Europe 2025 Findings·Aug 26, 2025
AIAI tools

Nearly 90% of respondents express confidence in their ability to respond to cyberattacks

KnowBe4Navigating Cyber Threats Infosecurity Europe 2025 Findings·Aug 26, 2025
Cyber attackPreparadness

43% of cybersecurity professionals identified distraction as a primary reason employees fall victim to cyberattacks.

KnowBe4Navigating Cyber Threats Infosecurity Europe 2025 Findings·Aug 26, 2025
Cyber attackInsider threatHuman error

26% of respondents indicated that AI-based cybersecurity tools are prioritised for funding.

KnowBe4Navigating Cyber Threats Infosecurity Europe 2025 Findings·Aug 26, 2025
AIAI toolsFundingInvestment

74% of respondents stated that phishing is the leading threat, with impersonation of executives or trusted colleagues being the most common tactic.

KnowBe4Navigating Cyber Threats Infosecurity Europe 2025 Findings·Aug 26, 2025
Phishing Impersonation

60% of organisations fear the rise of AI-generated threats.

KnowBe4Navigating Cyber Threats Infosecurity Europe 2025 Findings·Aug 26, 2025
AIAI threats

41% of cybersecurity professionals identified lack of security awareness training as a primary reason employees fall victim to cyberattacks.

KnowBe4Navigating Cyber Threats Infosecurity Europe 2025 Findings·Aug 26, 2025
Cyber attackSecurity awareness training

74% of respondents stated that phishing is the leading threat, with impersonation of executives or trusted colleagues being the most common tactic.

KnowBe4Navigating Cyber Threats Infosecurity Europe 2025 Findings·Aug 26, 2025
Phishing Impersonation

68% of attacks originate from email.

KnowBe4Financial Sector Threats Report·Aug 21, 2025
Financial Email

Financial service firms globally experience up to 300 times more cyberattacks annually than other industries.

KnowBe4Financial Sector Threats Report·Aug 21, 2025
Financial Cyber attack

100% of Europe's top financial firms suffered supplier breaches.

KnowBe4Financial Sector Threats Report·Aug 21, 2025
Financial EuropeSupplier breach

A single day's disruption in payments by major banks could affect 38% of network banks globally

KnowBe4Financial Sector Threats Report·Aug 21, 2025
Financial Disruption

Almost all (97%) of major U.S. banks experienced third-party breaches in 2024.

KnowBe4Financial Sector Threats Report·Aug 21, 2025
Financial USBankThird-party breach

Targeted intrusions against financial institutions increased by 109% year-over-year.

KnowBe4Financial Sector Threats Report·Aug 21, 2025
Financial Intrusion

Comprehensive security awareness training can reduce phishing susceptibility to below 5%.

KnowBe4Financial Sector Threats Report·Aug 21, 2025
Financial Phishing

There has been a 25% year-on-year increase in financial institution intrusion events for 2024.

KnowBe4Financial Sector Threats Report·Aug 21, 2025
Financial Intrusion

Infostealer infection attempts increased 58% in 2024.

KnowBe4Financial Sector Threats Report·Aug 21, 2025
Financial Infostealer

Analysis of over three million dark web posts shows stolen credentials far outpace credit card theft.

KnowBe4Financial Sector Threats Report·Aug 21, 2025
Financial Dark webStolen credentialsCredit card theft

Initially, large financial institutions show 44.7% Phish-prone™ Percentage (PPP) rates, meaning nearly 45% of employees were susceptible to phishing attacks or likely to click on a malicious link or download an infected file.

KnowBe4Financial Sector Threats Report·Aug 21, 2025
Financial Phishing

The U.S. accounts for 60% of all ransomware attacks against financial institutions.

KnowBe4Financial Sector Threats Report·Aug 21, 2025
Financial USRansomware

The U.S. and U.K. together represent over 70% of ransomware attacks.

KnowBe4Financial Sector Threats Report·Aug 21, 2025
Financial USUKRansomware

80.6% of the top 20 clicked links originated from internally-themed simulations.

KnowBe4Q2 2025 KnowBe4 Simulated Phishing Roundup Report·Jul 17, 2025
Phishing

HR-related themes were cited in 42.5% of phishing failures.

KnowBe4Q2 2025 KnowBe4 Simulated Phishing Roundup Report·Jul 17, 2025
Phishing

71.9% of interactions with malicious landing pages involved branded content.

KnowBe4Q2 2025 KnowBe4 Simulated Phishing Roundup Report·Jul 17, 2025
Phishing

80.6% of the top 20 clicked links originated from internally-themed simulations.

KnowBe4Q2 2025 KnowBe4 Simulated Phishing Roundup Report·Jul 17, 2025
Phishing

PDF attachment clicks in phishing simulations increased by 8.1% compared to Q1 2025.

KnowBe4Q2 2025 KnowBe4 Simulated Phishing Roundup Report·Jul 17, 2025
Phishing

Among internally-themed links, 68.2% utilised domain spoofing techniques.

KnowBe4Q2 2025 KnowBe4 Simulated Phishing Roundup Report·Jul 17, 2025
Phishing

Internal-themed topics accounted for 98.4% of the top 10 most-clicked email templates in the phishing simulations.

KnowBe4Q2 2025 KnowBe4 Simulated Phishing Roundup Report·Jul 17, 2025
Phishing

Internal-themed topics accounted for 98.4% of the top 10 most-clicked email templates in the phishing simulations.

KnowBe4Q2 2025 KnowBe4 Simulated Phishing Roundup Report·Jul 17, 2025
Phishing

PDFs comprised the majority, 61.1%, of the top 20 attachments clicked in phishing simulations.

KnowBe4Q2 2025 KnowBe4 Simulated Phishing Roundup Report·Jul 17, 2025
Phishing

PDF attachment clicks in phishing simulations increased by 8.1% compared to Q1 2025.

KnowBe4Q2 2025 KnowBe4 Simulated Phishing Roundup Report·Jul 17, 2025
Phishing

71.9% of interactions with malicious landing pages involved branded content.

KnowBe4Q2 2025 KnowBe4 Simulated Phishing Roundup Report·Jul 17, 2025
Phishing

IT-related themes were cited in 21.5% of phishing failures.

KnowBe4Q2 2025 KnowBe4 Simulated Phishing Roundup Report·Jul 17, 2025
Phishing

Average ransom per attack on state, local, tribal, and territorial (SLTT) governments reached $872,656 between 2018 and December 2024, with total costs exceeding $1.09 billion.

KnowBe4State and Local Cybersecurity: Facing New Burdens Amid Rising Threats·May 27, 2025
GovernmentRansomwareRansom

70% of surveyed state, local, tribal, and territorial (SLTT) organizations cite lack of sufficient funding as their top security concern

KnowBe4State and Local Cybersecurity: Facing New Burdens Amid Rising Threats·May 27, 2025
GovernmentBudget