Phishing Scam Statistics for 2026
Phishing scams remain the single most reported form of cybercrime in the United States, and the financial damage they cause is accelerating at an alarming pace.
Table of Contents
Phishing scams remain the single most reported form of cybercrime in the United States, and the financial damage they cause is accelerating at an alarming pace. The FBI's Internet Crime Complaint Center (IC3) 2025 Annual Report logged over one million cybercrime complaints for the first time, with phishing and spoofing topping the list yet again. Meanwhile, the Anti-Phishing Working Group (APWG) tracked nearly one million attacks in the first quarter of 2026 alone, confirming that the threat is not slowing down.
For businesses that rely on email, cloud applications, and remote workforces, understanding the latest phishing scam statistics is no longer optional. The data below draws from government reports, industry research, and cybersecurity vendors to paint a clear picture of where phishing stands today and where it is headed.
Key Phishing Scam Statistics at a Glance
The FBI IC3 received 191,561 phishing and spoofing complaints in 2025, making it the most reported cybercrime category for the fifth consecutive year.
Reported phishing losses reached $215.8 million in 2025, a 208% increase from $70 million in 2024, according to the FBI IC3 2025 report.
Business email compromise (BEC) caused $3.05 billion in losses from 24,768 complaints in 2025, with an average loss of $122,000 per incident.
The APWG observed 971,181 phishing attacks in Q1 2026, a 13.8% increase from Q4 2025.
Approximately 3.8 million phishing attacks were recorded globally across all of 2025, according to the APWG.
Microsoft detected and blocked 8.3 billion email phishing threats in Q1 2026 alone.
Phishing-initiated data breaches cost an average of $4.8 million per incident, above the $4.44 million global average, according to IBM's 2025 Cost of a Data Breach Report.
73% of U.S. adults have experienced some form of online scam or cyberattack in their lifetime, per Pew Research Center.
AI-linked phishing complaints totaled 803 incidents with $10.3 million in losses in 2025, averaging $12,807 per complaint, roughly 11 times the overall phishing average.
The median time for a user to click a phishing link is just 21 seconds, with another 28 seconds to enter data, according to the Verizon 2026 DBIR.
The Financial Toll of Phishing Scams
The cost of phishing is growing far faster than the volume of attacks. While the FBI IC3 saw a slight dip in phishing complaint counts from 193,407 in 2024 to 191,561 in 2025, the reported dollar losses surged from $70 million to $215.8 million. That represents a staggering 208% year-over-year increase in financial damage, even as complaint numbers held steady.
Business email compromise remains the most financially devastating form of phishing. BEC attacks generated $3.05 billion in losses during 2025, up from $2.77 billion the previous year. The average BEC victim lost over $122,000, and 86% of stolen funds were moved through wire transfers or ACH payments. In one notable case, the FBI's Recovery Asset Team froze $955,060 from a single real-estate BEC scheme.
Government impersonation scams, which often begin with a phishing email or text message, doubled in losses from $405.6 million in 2024 to $797.9 million in 2025. More than half of those losses fell on Americans aged 60 and older, a group that filed 48,064 phishing complaints with $77 million in total losses.
On the enterprise side, IBM's 2025 Cost of a Data Breach Report found that breaches originating from phishing cost organizations an average of $4.8 million, and took 254 days to identify and contain. In the United States, the average data breach cost reached a record $10.22 million, with healthcare organizations paying $7.42 million per incident.
How Phishing Attacks Are Evolving
Phishing is no longer limited to poorly written emails from unknown senders. Attackers are diversifying their methods and leveraging new technologies to bypass traditional defenses.
The APWG's Q1 2026 report showed a dramatic shift in sector targeting. Telecom companies were hit with 33% of all phishing attacks in Q1 2026, surging from just 5.9% in Q3 2025. SaaS and webmail providers, long the primary targets, saw their share decline to roughly 18%.
QR code phishing (quishing) is expanding rapidly. Microsoft reported that QR-based phishing detections jumped from 7.6 million in January 2026 to 18.7 million by March 2026, a 146% increase in a single quarter. Meanwhile, smishing (SMS-based phishing) grew 30-40% quarter over quarter throughout 2025, according to APWG data.
The CrowdStrike 2026 Global Threat Report highlighted that 82% of threat detections in 2025 were malware-free, up from 51% in 2020. Attackers increasingly rely on stolen credentials, social engineering, and living-off-the-land techniques rather than deploying traditional malware payloads. The average eCrime breakout time dropped to just 29 minutes, giving security teams very little time to respond once an attacker gains initial access.
Mobile phishing is proving especially effective. The Verizon 2026 Data Breach Investigations Report found that voice and SMS-based phishing campaigns achieve click rates 40% higher than email-based attacks.
Who Is Being Targeted
Phishing attacks affect every demographic, but some groups face disproportionate risk. Pew Research Center found that 21% of U.S. adults have lost money to online scams. Among adults aged 18-29, the rate climbs to 26%, while those 65 and older report losses at 15%. Lower-income households are also hit harder, with 26% reporting financial losses compared to 15% of upper-income households.
On the business side, technology companies absorbed 23% of all interactive intrusion attempts in 2025, according to the CrowdStrike 2026 Global Threat Report. The Verizon 2026 DBIR found that human error plays a role in 62% of all data breaches, with phishing accounting for 16% of initial access vectors and pretexting (voice or chat-based social engineering) contributing another 6%.
Small and mid-sized businesses are especially vulnerable. They often lack dedicated security operations centers and rely on employees to be the first line of defense. With the median phishing click happening in just 21 seconds, there is almost no time for a user to recognize and avoid a well-crafted attack.
The AI Factor in Phishing
Artificial intelligence is transforming phishing on both sides of the battle. The FBI IC3 tracked 22,364 AI-related cybercrime complaints in 2025 with $893 million in combined losses. Within phishing specifically, 803 complaints carried an AI nexus, generating $10.3 million in losses at an average of $12,807 per complaint.
Research cited by Microsoft found that AI-automated phishing emails achieve a 54% click-through rate, compared to just 12% for standard phishing emails. That is a 4.5 times multiplier in effectiveness. IBM research showed that generative AI reduced the time to craft a convincing phishing email from roughly 16 hours to about 5 minutes, a 200-fold productivity gain for attackers.
Deepfakes are adding another layer of danger. Gartner's 2025 survey found that 35% of organizations had already experienced a deepfake-related incident, with 41% involving audio deepfakes paired with social engineering. Fake CAPTCHA lure incidents surged 563% year over year, according to CrowdStrike, as attackers use seemingly legitimate verification prompts to trick users into downloading malware.
On the defensive side, organizations using AI-powered security tools saved an average of $1.9 million per breach compared to those without, per the IBM report. However, shadow AI usage within organizations adds roughly $670,000 to the average breach cost, highlighting the double-edged nature of the technology.
Emerging Trends and What's New in 2026
Several developments in the first half of 2026 stand out:
Scale keeps climbing. Microsoft blocked 8.3 billion phishing emails in Q1 2026 and detected 10.7 million BEC attempts in the same period. The APWG recorded nearly one million attacks in Q1 alone, putting 2026 on pace to surpass the 3.8 million attacks seen in all of 2025.
QR code phishing is surging. The 146% quarterly growth in QR detections reported by Microsoft suggests that attackers view QR codes as an effective way to bypass email security filters, which have historically struggled to scan image-based payloads.
AI-enabled attacks are accelerating. CrowdStrike reported an 89% year-over-year increase in AI-enabled adversary operations. As large language models become more accessible, the barrier to launching convincing, personalized phishing campaigns continues to drop.
Credential theft outpaces malware. With 82% of detections being malware-free and valid account abuse accounting for 35% of cloud-based incidents, the phishing kill chain is shifting toward identity compromise rather than payload delivery. Organizations that focus solely on endpoint antivirus are missing the majority of modern threats.
Phishing training alone is not enough. Gartner found that while 84% of organizations track training completion as their top security awareness metric, only 73% measure phishing reporting rates. Employees trained within 30 days of onboarding are four times more likely to report suspicious emails, according to Verizon, but training must be paired with technical controls to be effective.
How Managed IT Services Can Help
Phishing scams exploit the gap between human judgment and technical defenses. For small and mid-sized businesses without large security teams, closing that gap requires a combination of technology, monitoring, and expertise that is difficult to build in-house.
Managed IT services provide a layered approach to phishing defense. This includes advanced email filtering that catches threats before they reach employee inboxes, endpoint detection and response to stop credential theft in real time, and 24/7 monitoring that reduces the window attackers have to move laterally after a successful phish.
With the average BEC incident costing over $122,000 and phishing breach costs averaging $4.8 million, the return on professional security management is measurable. Managed service providers also handle ongoing security awareness training, simulated phishing campaigns, and incident response planning, so businesses do not have to choose between protecting their people and running their operations.
As phishing scams become more sophisticated and AI-driven, the organizations best positioned to avoid becoming a statistic are those that pair informed employees with professional, proactive security management.
Related Articles
- Third-Party Data Breach Statistics for 2026Third-party data breaches now account for nearly half of all confirmed breaches worldwide. According to the 2026 Verizon Data Breach Investigations Report, 48% of breaches involved a third-party…
- Small Business Ransomware Statistics for 2026Ransomware has become the defining cyber threat for small businesses. According to the Verizon 2026 Data Breach Investigations Report, ransomware now appears in 48% of all breaches analyzed, up from…
- Small Business Cybersecurity Statistics for 2026Small businesses face an unprecedented wave of cyber threats in 2026. According to the Hiscox Cyber Readiness Report 2026, 56% of U.S.
- Shadow IT Statistics for 2026: What the Latest Data RevealsShadow IT, the use of technology, software, and cloud services without IT department approval, continues to grow as one of the most persistent security and compliance challenges facing…
Hadley McIntosh
Updated Sep 27, 2026 · 8 min read