











“You’ve been gifted a voucher!”.
“Your account will be closed unless you act now”.
“Late payment demand. Invoice # 207”.
Phishing scams come in many shapes and sizes. And, in 2026, they remain, by far, the most common attack vector targeting both individuals and organizations.
To help you understand the scale of the threat, I’ve compiled this list of the most recent phishing statistics from around the world. I’ve gathered data on phishing published by independent industry bodies, law enforcement agencies, cybersecurity vendors and academia to give as full and broad a picture as possible.
Here’s our rundown of the most significant phishing statistics in 2026.
Before I dig into 2026 phishing statistics, it’s valuable to have a working definition. Here’s a definition:
Phishing is a malicious technique based on deception, used to steal sensitive information from users. The attackers pretend to be a trustworthy entity to trick the victims into revealing their confidential data.
There are several kinds of phishing, including email phishing, smishing (SMS phishing), vishing (voice phishing) and QR code phishing, among others.
I’ve only included phishing statistics and data that has been published in 2026 or very late in 2025 in certain cases. This will give you the most up to date insights into phishing today.
In this section, I look at the big picture of the scale of phishing.
Phishing is by far and away the most common kind of cybercrime in 2026. Every year, the UK government conducts a survey with businesses and charities. This year’s study found that phishing affects 38% of all businesses and 25% of all charities. This equates to 69% of businesses that experienced a breach or attack.
Similarly, the FBI’s Internet Crime Complaint Center’s most recent statistics (from 2025) show they received almost 192,000 complaints about phishing last year, making it by far the most prevalent kind of reported cybercrime. The next most common issue was extortion, at 89,000 complaints.
The data on phishing rates in 2026 is equivocal. Different authorities may be gathering data in different ways and on different timescales, so the picture is a little unclear.
The UK government survey mentioned above found a slight decrease in phishing rates this year, from 42% last year, to 38% in 2026.
However, the Anti-Phishing Working Group (APWG), which collates data from many international partners, found that phishing attacks rose by 13.8% in early 2026 – from a total of 853,244 in Q4 2025 to 971,181 in Q1 2026.
The APWG’s data also shows an increase in unique phishing email campaigns at the start of the year:

While there may be a slight upward trend in phishing this year, it’s important to put things in context.
An academic study published in late November last year analyzed reports of phishing incidents between 2009 and 2024. Data from three separate databases showed a massive rise from about 2012 which peaked in 2016, before sharply dropping by 2019.
This isn’t to trivialize the issue. But there is often a narrative that this kind of crime is endlessly rising. The reality is somewhat different.
There are several kinds of phishing which use different vectors of attack. Data from 2026 shows some interesting trends.
Email remains the attackers’ preferred method. Verizon reports that phishing represents 80% of all email-based attacks in 2026. And ENISA (the EU’s cybersecurity agency) reported that email phishing was the dominant intrusion vector, accounting for approximately 60% of all cases (N.B. this report was from October 2025).
Vast numbers of phishing emails get sent daily. Microsoft Threat Intelligence detected around 8.3 billion email-based phishing threats in the first quarter of 2026 alone.
Other phishing techniques are still important. Microsoft’s data shows:
Although email is the main attack vector, these alternative phishing techniques may be more effective. Verizon estimates that phone-based phishing has a success rate of 2% compared to 1.4% with email.
Microsoft also records the different kinds of payload methods used by phishing criminals. This shows there’s quite a diverse range:

The costs of phishing are tricky to ascertain. Again, this is because different organisations measure things differently. Do you count the direct impact on the individual victim’s work? Or do you also include the cost of time spent investigating, business disruption, or even penalties for failing to protect customer data?
According to the UK government’s survey, the median perceived cost of phishing was £400 (US $542). However, about 5% of businesses reported costs mounting up to £15,000 ($20,300).
Meanwhile, the FBI reported total losses from phishing in 2025 mounted to almost $216 million.
These figures, however, are dwarfed by those of IBM. In their 2026 Cost of a Data Breach report, they estimate that individual phishing incidents cost businesses US $5.29 million, on average.
IBM explains that the costs of detection, escalation and lost business account for a large part of this figure. That may explain the disparity with the FBI and UK government’s data, which just focus on the direct cost.
Like any tool, AI can be used for both good and for ill. And criminals are certainly turning to it for support.
According to Hoxhunt, a security training provider, there was a 14x increase in AI-generated phishing emails that bypassed email security filters at the start of 2026. Their report also discovered that:
Meanwhile, Verizon looked at how AI is being used in different forms of attack in 2026. They found that:
So, who’s being targeted by phishing this year? The data provides some valuable insights.
KnowBe4, a training company, produces an annual analysis of phishing simulations. Their data shows that in 2026, 33.2% of workers are ‘phish prone’. This means an individual is more likely to open a phishing email and become a victim.
KnowBe4’s data also shows that employees at larger companies are more likely to be phishing-prone.

In 2026, the APWG’s data suggests that the telecom industry is most likely to be targeted by phishing:

Phishing is a global phenomenon. However, it affects different regions in different ways. According to Verizon’s data, initial access vectors where breaches are successful range quite considerably.

This data shows that phishing is more likely to be successful in the EMEA and LAC region than in North America or APAC. Overall, phishing is least successful in the North America region.
The FBI provides some interesting insights into the age groups of phishing victims in the United States. For their 2025 figures, people in the 60+ group are most likely to be victims:

A fascinating academic study was published in 2026 which analyzed data from many other studies into the individual characteristics of phishing victims. Some insights include:
Few crime agencies provide detailed data about arrests for phishing specifically. However, there have been some important news stories this year:
As these 2026 phishing statistics show, this form of cyber crime remains extremely widespread. And with the emergence of AI and new phishing categories, it’s constantly evolving.
But, with a combination of tools and training, organizations can stay on top of the threat. See how Heimdal’s email security products can help you guard against BECs, CEO fraud, impersonation and other forms of phishing.
If you liked this article, follow us on LinkedIn, Reddit, X, Facebook, and Youtube.
Newsletter
If you liked this post, you will enjoy our newsletter.
Get cybersecurity updates you'll actually want to read directly in your inbox.
Communications and PR Officer
Livia Gyongyoși is a Communications and PR Officer within Heimdal®, passionate about cybersecurity. Always interested in being up to date with the latest news regarding this domain, Livia's goal is to keep others informed about best practices and solutions that help avoid cyberattacks.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。