Phishing Statistics
Phishing by Industry
Latest Statistics
Between 89% and 95% of email phishing attachments lead to credential theft efforts.
93% of voice phishing attacks keep the victim on the line long enough for social engineering to begin.
50% of security leaders rank threat detection and alerting among their top AI-for-security priorities, followed by fraud detection (43%) and phishing detection and response (42%).
Organisations are most comfortable authorising autonomous agents for threat intelligence enrichment and correlation (49%), phishing email quarantine or deletion (47%), and malware removal and system remediation (46%).
Senior executives specializing in IP law rate phishing as a top concern at 39%
79% of chief information security officers report at least one e-mail phishing, spear-phishing, or business e-mail compromise incident in the last 12 months.
Custom fake CAPTCHAs grow by 437% from Q1 to Q2 2026.
OAuth device-code phishing surges by 483.7% from Q1 to Q2 2026.
Google's name appears in scam content at least twice as often as Amazon's name.
39% of phishing messages featured novel social engineering techniques.
Vishing intrusions increased by 2x in 1H 2026.
17% of reported cybercrime cases in Africa in 2025 involved online scams, including phishing.
Monthly device code phishing attempts increased 15x in 1H 2026.
In the first half of 2026, 67% of phishing emails passed DMARC.
VIP users were targeted in 25.8% of phishing attacks.
The three most vulnerable industries at baseline are Healthcare & Pharmaceuticals (42.7%), Insurance (38.1%), and Retail & Wholesale (36%).
Organizations reduce phishing susceptibility by 79% after one year of consistent security awareness training.
Before any training, roughly one in three employees is likely to engage with a phishing attempt.
Almost 86% of phishing attacks contain AI-generated elements.
The number of mobile devices where employees clicked a malicious link grew 110% in 2025 compared to 2024.
Phishing events detected on employee mobile devices have grown 380% since January 2025.
The ARToken panel exposed 80+ API endpoints for device code phishing, primary refresh token persistence, email access, BEC operations, and SharePoint exfiltration.
Phishing was the primary means of gaining initial access in over half of Cisco Talos Incident Response engagements this quarter, up from approximately one-third of engagements last quarter.
Microsoft was the most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts.
The top five impersonated brands — Microsoft, LinkedIn, Google, Apple, and Amazon — together accounted for more than 50% of all brand phishing attempts this quarter.
Open AI’s ChatGPT entered the top ten most impersonated brands for the first time.
Phishing emails and other email-based social engineering are the initial entry vector in 34% of ransomware incidents.
34% of ransomware incidents begin with phishing emails or other email-based social engineering.
Malicious email (26%) and phishing (24%) together account for 50% of ransomware incidents.
51% of IAM leaders and stakeholders cite the inability to support legacy apps and infrastructure as an obstacle to universal phishing-resistant MFA.
Only 28% of the MFA used for workforce authentication in financial services is phishing-resistant.
53% of IAM leaders and stakeholders cite cost and budget constraints as an obstacle to universal phishing-resistant MFA.
36% of restaurants experienced phishing targeting staff credentials as a form of social engineering in the past year.
Phishing accounted for 49% of blocked harmful content and phishing volume grew 94% year-on-year.
Phishing websites account for 10.5% of critical exposures, up sharply from 1.0% the year before.
60% of UK cybersecurity professionals say threats are already moving beyond email
66% of UK cybersecurity professionals believe employees are more likely to trust messages received through internal collaboration platforms
62% of cybersecurity professionals are seeing attacks move beyond email
45% of organizations cite reducing phishing and credential-based breach risk as the leading driver for moving to passwordless authentication.
Services industry phishing hits surged 65.5% year-over-year from 330.9 million to 547.7 million hits.