Phishing Statistics

331 STATS74 SOURCES

Latest Statistics

88% of internal audit leaders identify AI-powered phishing attacks as a top risk.

The Internal Audit Foundation and AuditBoardInternal Audit and AI-Enabled Fraud·2mo ago
AI-Powered PhishingCybersecurity RiskInternal Audit

51% of organizations have faced sophisticated, personalized phishing emails powered by deepfake technology.

PhishingDeepfakeSocial Engineering

In Q4 2025, callback phishing increased from 3% to 18% of all phishing incidents, a 500% spike.

VIPRE Security GroupQ4 2025 Email Threat Trends Report·3mo ago
PhishingCallback PhishingEmail SecuritySocial Engineering

82% of malicious files have unique hashes that traditional pattern-matching fails to detect.

Malicious FilesThreat DetectionPhishingEmail Attack

Credential phishing campaigns using .es domains increase 51 times year-over-year, with the .es top-level domain jumping from the 56th to the 3rd most-abused TLD.

PhishingDomain AbuseCredential TheftCredential PhishingEmail Security

76% of initial infection URLs in abalyzed phishing attacks were unique and have not appeared in other campaigns across Cofense's customer base.

PhishingMalicious URLsEmail AttackEmail Security

Conversational attacks comprise 18% of all malicious emails.

PhishingEmail SecurityEmail Attack

In 2025, a malicious email attack occurs every 19 seconds, more than doubling from 2024’s pace of one every 42 seconds.

PhishingEmail SecurityEmail Attack

Abuse of legitimate remote access tools increased by 900% by volume.

Remote Access ToolsPhishingEmail SecurityEmail Attack

Fifty percent of affected consumers cite immediate financial fraud as their primary fear, and 54 percent of consumers report an increase in targeted phishing attempts after a breach (2025)

Financial FraudPhishing

Eighty-eight percent of consumers who received a data breach notice experience at least one negative consequence after a breach; 40 percent experience an increase in phishing or scam attempts; 49 percent experience an increase in spam emails or robocalls; 40 percent experience attempted takeover of an existing account (2025)

Consumer HarmPhishingSpam

Clicks on phishing links decreased by 27%, from 119 per 10,000 users last year to 87 per 10,000 users this year.

PhishingPhishing LinksUser Behavior

87 out of every 10,000 users clicked on a phishing link each month in 2025.

PhishingPhishing LinksUser Behavior

77% of advanced email attacks failed SPF, DKIM, or DMARC authentication yet still reached inboxes.

Email SecurityEmail ThreatsPhishingDMARC

Approximately 45% of advanced email attacks showed indicators of AI assistance, projected to rise to 75–95% within the next 18 months

Email SecurityEmail ThreatsAIPhishing

77% of advanced email attacks impersonated business-critical brands such as DocuSign, Microsoft, and Google.

Email SecurityPhishingDocuSignMicrosoftGoogle

100% of advanced email threats bypassed incumbent email security, including Microsoft E3/E5 and leading secure email gateways.

Email SecurityEmail ThreatsEmail GatewayPhishing

DocuSign accounted for more than 20% of all advanced email attacks analyzed.

Email SecurityEmail ThreatsDocuSignPhishing

In 2025, attacks bypassing multifactor authentication (MFA) were reported in 48% of phishing attacks.

PhishingMFAMFA BypassPhishing Techniques

In 2025, malicious QR codes were observed in 19% of phishing attacks.

PhishingQR CodesPhishing Techniques

In 2025, obfuscations to hide URLs from detection were seen in 48% of phishing attacks.

PhishingPhishing TechniquesObfuscationPhishind Detection

The number of known phishing kits doubled during 2025, reaching a significant increase in active use.

PhishingPhishing Kits

In 2025, 'ClickFix' social engineering techniques were used in 1% of phishing attacks.

PhishingPhishing TechniquesSocial EngineeringClickFix

In 2025, 90% of high-volume phishing campaigns utilized Phishing-as-a-Service (PhaaS) kits.

PhishingPhishing KitsPhishing-as-a-Service

In late 2025, there were 10 million Mamba 2FA phishing attacks recorded.

Phishing2FA

In 2025, malicious attachments were present in 18% of phishing attacks.

PhishingMalwarePhishing Techniques

In 2025, the abuse of trusted, legitimate online platforms was noted in 10% of phishing attacks.

PhishingPhishing Techniques

In 2025, the use of 'Blob URIs' was noted in 2% of phishing attacks.

PhishingPhishing Techniques

In 2025, attacks leveraging generative AI were reported in 10% of phishing attacks.

PhishingGenerative AI

In 2025, CAPTCHA was leveraged for added authenticity in 43% of phishing attacks.

PhishingPhishing TechniquesCAPTCHA

In 2025, 'polymorphic' attacks that varied the email header, body, and destination were seen in 20% of phishing attacks.

PhishingPhishing TechniquesPolymorphic

89% of schools experienced at least one cyber incident in the past year, primarily phishing, unauthorized access, and malware.

Cyber IncidentEducationPhishingUnauthorized AccessMalware

92% of school IT leaders expect AI-powered phishing to be the most dangerous threat in the coming year

EducationIT LeadershipPhishingAI-Powered Phishing

68% of all phishing infrastructure tracked operates on Cloudflare as of the current year.

PhishingPhishing InfrastructureCloudflare

Almost 60% of the observed indicators of compromise (IOCs) are linked with Phishing-as-a-Service (PhaaS).

PhishingIOCsPhishing-as-a-Service

The mean DNS resolution rate for phishing operators was 96.16%, indicating high availability and minimal downtime.

Phishing

51.54% of the phishing infrastructure is directly hosted, while 48.46% is protected by CDN/proxy services.

PhishingPhishing Infrastructure

IT leaders estimate only 5% of known phishing attacks are reported by healthcare employees to their security teams.

Email SecurityEmail BreachHealthcarePhishing

Over the past four months, 20 distinct phishing clusters were identified based on shared infrastructure fingerprints.

PhishingPhishing Infrastructure

In the last quarter, over 42,000 validated URLs and domains were identified as actively serving phishing kits, command-and-control infrastructure, or payload delivery.

PhishingPhishing KitsComman and Control InfrastructurePayload Delivery