Email Phishing Statistics 2026: The Latest Data on Attacks, Costs, and Trends
Email phishing remains the single most common cyberattack vector facing businesses today. In Q1 2026 alone, the APWG recorded 971,181 phishing attacks, a 13.8% jump from the previous quarter.
Table of Contents
Email phishing remains the single most common cyberattack vector facing businesses today. In Q1 2026 alone, the APWG recorded 971,181 phishing attacks, a 13.8% jump from the previous quarter. Meanwhile, the FBI's IC3 found that phishing losses surged 208% year over year to $215.8 million, even as complaint volume held steady at 191,561 reports. With AI-generated phishing emails becoming nearly indistinguishable from legitimate messages and phishing-as-a-service kits fueling high-volume campaigns, organizations of every size need to understand the threat landscape heading into the second half of 2026.
Key Email Phishing Statistics at a Glance
The APWG observed 971,181 phishing attacks in Q1 2026, up 13.8% from Q4 2025 (APWG)
Phishing losses hit $215.8 million in 2025, a 208% year-over-year increase (FBI IC3)
Business email compromise (BEC) caused $3.04 billion in losses in 2025, with 86% transmitted via wire transfer or ACH (FBI IC3)
Email-origin fraud now accounts for over $4 billion in combined annual losses across phishing, BEC, and government impersonation (FBI IC3)
58% of all email attacks are phishing-based, according to analysis of 800,000 attacks across 4,600+ organizations (Abnormal AI)
One in four malicious data breaches are now AI-enabled, costing an average of $6 million per incident (IBM)
90% of high-volume phishing campaigns now use phishing-as-a-service (PhaaS) kits (Barracuda)
1 in 3 emails received by businesses are malicious or unwanted spam (Barracuda)
Mobile phishing has a 40% higher click rate than traditional email phishing (Verizon DBIR)
70% of malicious PDFs now contain QR codes that redirect to phishing sites (Barracuda)
34% of companies experience at least one account takeover incident every month (Barracuda)
The FBI recorded over 22,000 AI-related cybercrime complaints and nearly $900 million in AI-related losses in 2025 (FBI IC3)
The Financial Impact of Email Phishing
The cost of phishing continues to climb across every metric. The IBM 2026 Cost of a Data Breach Report puts the global average breach cost at $4.99 million, a 12% increase over the prior year and a new record. When AI-enabled techniques are involved, that figure jumps to $6 million per incident, with one in four malicious breaches now falling into this category. Financial services organizations face the steepest costs at $6.3 million per breach, followed by the energy sector at $5.2 million.
The FBI IC3 2025 Annual Report paints an equally stark picture. Total cybercrime losses reached $20.9 billion (a 26% year-over-year increase), and email-based fraud played a central role. BEC alone accounted for $3.04 billion, with average per-complaint losses exceeding $122,000. Phishing-specific losses tripled from $70 million in 2024 to $215.8 million in 2025, the sharpest increase in the report's history. Government impersonation scams conducted via email added another $797.9 million, bringing total email-origin fraud above $4 billion.
Account takeover losses further compound the problem. The FBI recorded 4,700 ATO complaints with $359.7 million in losses, and ransomware (frequently delivered via phishing) saw a 159% increase in reported losses to $32.3 million, with 63 new ransomware variants identified. Across all categories, the FBI now receives over 3,000 cybercrime complaints per day.
Organizations that deploy AI and automation in their security operations, however, are cutting their breach costs by roughly $2 million compared to those that rely on traditional tools, according to IBM. Over 50% of organizations have now deployed AI agents specifically for threat detection and containment, though only 18% apply them to vulnerability management.
Phishing Attack Volume and Delivery Methods
The sheer volume of phishing attempts continues to grow. The APWG Q1 2026 report logged 971,181 attacks, up from 853,244 in Q4 2025. The telecommunications sector saw the most dramatic targeting shift, jumping from 5.9% of all attacks in Q3 2025 to 33% by Q1 2026, a development linked to SIM-swapping and account-takeover schemes.
Barracuda found that phishing represents 48% of all malicious email activity, with one in three emails received by businesses classified as malicious or unwanted spam. HTML attachments are the most weaponized file format (over 10% are malicious), and QR code phishing has surged; 70% of malicious PDFs and 56% of malicious Microsoft 365 documents now embed QR codes that redirect victims to credential-harvesting sites.
Vishing and smishing (voice and SMS phishing) rose 15% from Q4 2025 to Q1 2026, per the APWG, and the Verizon DBIR found that mobile-targeted social engineering achieves a 40% higher click rate than desktop email phishing, making mobile devices an increasingly attractive target for attackers. URL phishing frequency targeting the telecom sector increased 75% since Q4 2025, reflecting attackers' growing focus on mobile carrier ecosystems.
Approximately one in every 200 URLs encountered in business email is malicious, per Barracuda. While that may sound low, at the scale of enterprise email traffic (where a mid-sized company processes tens of thousands of emails daily), it translates to dozens of potential phishing links reaching employee inboxes each week.
AI-Powered Phishing and the Automation of Attacks
Artificial intelligence has fundamentally changed the phishing threat landscape. IBM reports a 56% increase in AI-enabled breaches year over year, with 62% of AI-driven attacks targeting critical infrastructure sectors. The 2025 FBI IC3 report introduced AI-related cybercrime tracking for the first time, recording over 22,000 complaints and nearly $900 million in AI-related losses, of which $47.2 million was directly tied to email-based AI attacks spanning BEC, phishing, and impersonation.
Abnormal AI found that 21.6% of phishing attacks now use redirect chains to obscure malicious destinations, and 61% of business email compromise is vendor-related, meaning attackers compromise a trusted supplier's email account to target their customers downstream. The Verizon DBIR identified 15 distinct attack techniques now being augmented by generative AI, while shadow AI usage among employees surged from 15% to 45% within a single year, creating new insider risk vectors.
Business Email Compromise and Account Takeover
BEC remains the costliest form of email-based crime. The FBI IC3 recorded $3.04 billion in BEC losses for 2025, with 86% of those losses transmitted through wire transfers or ACH payments. Average wire transfer demands in Q1 2026 dropped 15% to $42,663 (down from $50,297 in Q4 2025), per the APWG, though this may reflect a shift toward higher-volume, lower-value attacks.
Account takeover (ATO) is closely linked to phishing success. Barracuda reports that 34% of companies experience at least one ATO incident monthly, with 25% of compromised accounts showing suspicious inbox rule changes (such as auto-forwarding or auto-deletion) designed to hide the attacker's activity. Abnormal AI found that billing account update requests carry a 26.5% compromise rate, making them the single highest-risk BEC vector.
The rise of phishing-as-a-service has also industrialized these attacks. Barracuda found that 90% of high-volume phishing campaigns now leverage PhaaS kits, with the number of active kits doubling in 2025. The most common PhaaS techniques include MFA bypass (48%), URL obfuscation (48%), and CAPTCHA abuse (43%).
Emerging Trends and What's New in 2026
Several developments stand out in the first half of 2026:
QR code phishing goes mainstream. Quishing has moved from a niche tactic to a dominant delivery method. With 70% of malicious PDFs and 56% of malicious Office documents now containing embedded QR codes, attackers are bypassing traditional URL scanning by shifting the click to a mobile device, where security controls are typically weaker.
AI-generated phishing becomes harder to detect. AI-crafted emails now closely mimic the writing style, tone, and formatting of legitimate business communications. The FBI IC3 recorded over 22,000 AI-related cybercrime complaints in its first year of tracking this category, with nearly $900 million in associated losses. Generative AI is also powering deepfake voice and video impersonations used in callback phishing and BEC schemes.
Telecom becomes the top target. The telecommunications sector surged from under 6% of phishing attacks in mid-2025 to 33% of all attacks by Q1 2026, per the APWG. This shift is driven by SIM-swapping campaigns and account takeover attempts targeting mobile subscribers.
Phishing-as-a-service matures. PhaaS has evolved into a full ecosystem with subscription pricing, customer support, and turnkey kits offering real-time MFA bypass and credential relay. The number of active PhaaS kits doubled in 2025, and they now power 90% of high-volume campaigns.
Shadow AI creates new exposure. Employee use of unauthorized AI tools surged from 15% to 45% in a single year, per the Verizon DBIR, making it the third most common non-malicious data leakage activity. These unmonitored tools create new pathways for sensitive data exposure that attackers are beginning to exploit through targeted phishing of AI platform credentials.
How Managed IT Services Can Help
With phishing attacks growing more sophisticated and more frequent, most small and mid-sized businesses lack the in-house expertise to keep pace with evolving threats. A managed IT services provider can deploy layered email security (including AI-powered filtering and DMARC enforcement), continuous phishing awareness training, and 24/7 monitoring to catch threats before they reach employee inboxes. To learn how proactive managed IT support can protect your organization, visit manageditservices.ai.
Related Articles
- Third-Party Data Breach Statistics for 2026Third-party data breaches now account for nearly half of all confirmed breaches worldwide. According to the 2026 Verizon Data Breach Investigations Report, 48% of breaches involved a third-party…
- Small Business Ransomware Statistics for 2026Ransomware has become the defining cyber threat for small businesses. According to the Verizon 2026 Data Breach Investigations Report, ransomware now appears in 48% of all breaches analyzed, up from…
- Small Business Cybersecurity Statistics for 2026Small businesses face an unprecedented wave of cyber threats in 2026. According to the Hiscox Cyber Readiness Report 2026, 56% of U.S.
- Shadow IT Statistics for 2026: What the Latest Data RevealsShadow IT, the use of technology, software, and cloud services without IT department approval, continues to grow as one of the most persistent security and compliance challenges facing…
Hadley McIntosh
Updated Sep 29, 2026 · 7 min read