Phishing Statistics
Phishing by Industry
Latest Statistics
Organizations reduce phishing susceptibility by 79% after one year of consistent security awareness training.
Before any training, roughly one in three employees is likely to engage with a phishing attempt.
Africa records the highest baseline Phish-prone Percentage at 35.9%, followed by North America at 34.5%, South America at 31.5%, and Asia at 24.9%.
Global average Phish-prone Percentage (PPP) starts at 33.2% before training, drops to 20.1% after 90 days of security awareness training, and falls to 4.2% after one year.
Organizations reduce phishing susceptibility by 40% within the first 90 days of ongoing security awareness training.
Large enterprises with 10,000+ employees face a baseline Phish-prone Percentage of 39.5%, compared to 24.7% for small businesses.
The three most vulnerable industries at baseline are Healthcare & Pharmaceuticals (42.7%), Insurance (38.1%), and Retail & Wholesale (36%).
Almost 86% of phishing attacks contain AI-generated elements.
The number of mobile devices where employees clicked a malicious link grew 110% in 2025 compared to 2024.
Phishing events detected on employee mobile devices have grown 380% since January 2025.
Phishing was the primary means of gaining initial access in over half of Cisco Talos Incident Response engagements this quarter, up from approximately one-third of engagements last quarter.
The ARToken panel exposed 80+ API endpoints for device code phishing, primary refresh token persistence, email access, BEC operations, and SharePoint exfiltration.
Microsoft was the most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts.
The top five impersonated brands — Microsoft, LinkedIn, Google, Apple, and Amazon — together accounted for more than 50% of all brand phishing attempts this quarter.
Open AI’s ChatGPT entered the top ten most impersonated brands for the first time.
Phishing emails and other email-based social engineering are the initial entry vector in 34% of ransomware incidents.
34% of ransomware incidents begin with phishing emails or other email-based social engineering.
Malicious email (26%) and phishing (24%) together account for 50% of ransomware incidents.
51% of IAM leaders and stakeholders cite the inability to support legacy apps and infrastructure as an obstacle to universal phishing-resistant MFA.
36% of restaurants experienced phishing targeting staff credentials as a form of social engineering in the past year.
Only 28% of the MFA used for workforce authentication in financial services is phishing-resistant.
79% of IAM leaders and stakeholders cite technical or architectural complexity as an obstacle to universal phishing-resistant MFA.
53% of IAM leaders and stakeholders cite cost and budget constraints as an obstacle to universal phishing-resistant MFA.
94% of IAM leaders and stakeholders at financial services firms report that phishing attacks increased over the past year.
After 90 days of security awareness training, the global average PPP drops to 20.1%.
The three industries with the highest baseline PPP are Healthcare & Pharmaceuticals at 42.7%, Insurance at 38.1%, and Retail & Wholesale at 36%.
Baseline PPP by region is: Africa 35.9%, North America 34.5%, South America 31.5%, and Asia 24.9%.
The global average Phish-prone Percentage (PPP) is 33.2% before training.
Phishing accounted for 49% of blocked harmful content and phishing volume grew 94% year-on-year.
After one year of security awareness training, the global average PPP falls to 4.2%.
Organizations reduce phishing susceptibility by 40% within the first 90 days of training and by 79% after one year of ongoing security awareness training.
Large enterprises with 10,000+ employees have a baseline PPP of 39.5%, compared to 24.7% for small businesses.
Phishing websites account for 10.5% of critical exposures, up sharply from 1.0% the year before.
60% of UK cybersecurity professionals say threats are already moving beyond email
66% of UK cybersecurity professionals believe employees are more likely to trust messages received through internal collaboration platforms
62% of cybersecurity professionals are seeing attacks move beyond email
54% of UK cybersecurity professionals consider traditional phishing emails the biggest threat to their organization
45% of organizations cite reducing phishing and credential-based breach risk as the leading driver for moving to passwordless authentication.
52,185 threats were hosted on domains that enterprise security stacks are configured to trust, including Google Drive, Dropbox, and SharePoint.
Manus AI accounted for 15.6% of attributed AI site builders, Blackbox AI accounted for 14.3%, and Anything AI accounted for 9.8% of attributed builders.