Phishing Statistics for 2026: Attack Volume, Costs, and What Has Changed
Phishing is still the most common way attackers get into a business. According to IBM's 2026 Cost of a Data Breach Report, phishing was the most common initial attack vector for the fourth…
Table of Contents
Phishing is still the most common way attackers get into a business. According to IBM's 2026 Cost of a Data Breach Report, phishing was the most common initial attack vector for the fourth consecutive year, and the global average cost of a breach hit a record $4.99 million. The Verizon 2026 Data Breach Investigations Report found the human element in 62% of breaches, and the FBI's 2025 Internet Crime Report logged 191,561 phishing and spoofing complaints, more than any other crime type. This page collects the freshest phishing attack statistics available in 2026, sourced from primary research so you can cite them with confidence.
Key phishing statistics at a glance
Phishing is the number one initial attack vector for the fourth year running, per IBM's 2026 Cost of a Data Breach Report.
$4.99 million is the global average cost of a data breach in 2026, up 12% year over year and a record high (IBM, 2026). The US average is $11.5 million.
$5.29 million is the average cost of a breach that starts with voice or SMS phishing, the costliest initial vector IBM measured in 2026.
62% of breaches involved the human element, up from 60% a year earlier (Verizon 2026 DBIR).
16% of breaches used phishing as the initial access vector (Verizon 2026 DBIR).
191,561 phishing and spoofing complaints reached the FBI in 2025, the most of any crime category, with reported losses of $215.8 million (FBI IC3, 2025).
$3.05 billion was lost to business email compromise in 2025, up from $2.77 billion the year before (FBI IC3, 2025).
33.2% of untrained employees click on a simulated phishing email; after 12 months of training that falls to 4.2% (KnowBe4, 2026).
Vishing intrusions doubled and device code phishing attempts rose 15x in the first half of 2026 (CrowdStrike 2026 Threat Hunting Report).
One in four malicious breaches was AI-enabled in 2026, a 56% increase over the prior year (IBM, 2026).
AI-driven phishing is three times more effective than traditional campaigns (Microsoft Digital Defense Report 2025).
Mobile phishing click rates are 40% higher than email click rates (Verizon 2026 DBIR).
Phishing as the main cause of data breaches
The most-cited framing in this category is that phishing is the leading cause of data breaches. The 2026 data supports a more precise version of that claim.
IBM's 2026 Cost of a Data Breach Report ranks phishing as the most common initial attack vector for the fourth straight year, ahead of supply chain compromise. Voice and SMS phishing, the vishing and smishing variants, produced the single most expensive breaches of any traditional entry point at an average of $5.29 million, well above the $4.99 million global average.
The Verizon 2026 DBIR, which analyzed more than 31,000 security incidents and more than 22,000 confirmed breaches, puts phishing at 16% of initial access vectors, unchanged from the prior year. Social engineering as a whole accounted for 16% of breaches. Vulnerability exploitation overtook credential abuse as the leading initial vector at 31%, while credential abuse dropped to 13% as an entry point. That last figure is misleading on its own: when Verizon looked across every stage of a breach rather than just the entry point, credential abuse appeared in 39% of cases, and phishing is one of the main ways those credentials are harvested.
The broader human factor keeps growing. The human element, which includes phishing clicks, credential misuse, and errors, was present in 62% of breaches in the 2026 DBIR, up from 60% in the 2025 edition. Microsoft's Digital Defense Report 2025 found that 28% of the breaches it investigated began with phishing or social engineering.
Ransomware is the most common outcome. Verizon found ransomware present in 48% of all breaches in 2026, up from 44%, with a median ransom payment of $139,875. The 69% of victims who refused to pay is a positive trend, but the recovery bill does not disappear when the ransom does.
Phishing attack volume and reported losses in 2025 and 2026
Phishing volume statistics vary widely by vendor, so the most defensible numbers come from law enforcement and from telemetry providers that publish their methodology.
The FBI's Internet Crime Complaint Center received 1,008,597 complaints in 2025 with total reported losses of roughly $20.9 billion, a 26% increase in losses over 2024. Phishing and spoofing was the most reported crime type at 191,561 complaints, a slight decrease from 193,407 in 2024. Reported losses from phishing and spoofing, however, jumped from $70.0 million to $215.8 million in a single year, more than tripling.
Business email compromise, which almost always begins with a phishing or pretexting email, is where the money is. The FBI recorded 24,768 BEC complaints in 2025 with losses of $3.05 billion, up from 21,442 complaints and $2.77 billion in 2024. The FBI also began tracking AI-related complaints separately: 22,364 complaints referenced AI in 2025, with losses of $893.3 million.
Raw email volume tells a different story. The Zscaler ThreatLabz 2026 Phishing and Initial Access Report found that blocked phishing transactions declined roughly 20% year over year in both 2024 and 2025. That is not good news. Attackers are trading mass campaigns for targeted, higher-yield operations, which is why losses are climbing while volume falls. Zscaler observed that 95.2% of phishing activity is now delivered over encrypted TLS connections, so the padlock icon offers no protection.
Some sectors are seeing volume rise sharply. Phishing aimed at the services industry surged 65.5% in Zscaler's data, from 330.9 million to 547.7 million hits, with lures built around billing, renewals, support, onboarding, and document exchange.
KnowBe4's 2026 Phishing by Industry Benchmarking Report, based on 42 million simulations across 14.8 million users at 64,000 organizations, documented a 17.1% spike in phishing attacks since late 2025.
How many employees fall for phishing
The click rate is the statistic security leaders ask about most, and the 2026 benchmarks are consistent.
KnowBe4's 2026 report puts the global baseline phish-prone percentage at 33.2%. In other words, one in three untrained employees will fail a phishing test. After 90 days of training and simulated phishing, that drops to 20.1%. After one year, it falls to 4.2%, a 79% reduction.
Company size matters more than most people expect. Small businesses had a baseline phish-prone percentage of 24.7%, while large enterprises with more than 10,000 employees came in at 39.5%. The most susceptible industries were healthcare and pharmaceuticals at 42.7%, insurance at 38.1%, and retail and wholesale at 36.0%. North America's baseline was 34.5%, slightly above the global average.
Channel matters too. The Verizon 2026 DBIR found that the median successful click rate for mobile-centric vectors such as voice calls and text messages is 40% higher than for email. Attackers have noticed: vishing and smishing are where the fastest growth is.
Vishing, smishing, and device code phishing
The biggest shift in phishing attack statistics between 2025 and 2026 is the move away from the inbox.
The CrowdStrike 2026 Threat Hunting Report recorded a two-fold increase in vishing intrusions during the first half of 2026 compared with the second half of 2025. Device code phishing, which tricks a user into authorizing an attacker's device through a legitimate sign-in flow, grew 15x over the same period. In one intrusion CrowdStrike tracked, an attacker moved from account takeover to data theft in under five minutes.
Verizon flagged the same trend. Pretexting, which relies on a real-time conversation rather than a static email, reached 6% of initial access vectors in ransomware and extortion attacks in the 2026 DBIR. And IBM's finding that voice and SMS phishing breaches cost $5.29 million on average confirms that these attacks are not just more frequent but more damaging when they succeed.
Speed is the other variable. The CrowdStrike 2026 Global Threat Report measured the average eCrime breakout time, the gap between initial access and lateral movement, at 29 minutes in 2025, with the fastest observed case at 27 seconds. A phishing click that once bought defenders hours now buys them minutes.
AI-generated phishing statistics
Every major 2026 report quantifies AI in the phishing chain, and the numbers are no longer speculative.
IBM found that one in four malicious breaches in 2026 was AI-enabled, a 56% increase over the previous year. Those breaches cost roughly $6 million on average, about $1 million more than the global mean. Within AI-enabled incidents, deepfake and impersonation attacks made up 45%, AI-enabled malware 19%, and AI-generated phishing or other communications 17%.
Microsoft's Digital Defense Report 2025 reported that AI-driven phishing campaigns are three times more effective than traditional ones, and that AI-driven forgeries used for synthetic identities grew 195% globally. Microsoft also blocked 1.6 million bot-driven or fake account sign-ups every hour.
CrowdStrike's 2026 Global Threat Report found that AI-enabled adversaries increased their operations by 89% year over year. The Verizon 2026 DBIR observed the median threat actor using AI assistance across 15 different documented attack techniques.
AI is building the infrastructure as well as the lures. Zscaler identified 413,524 site instances generated by AI website builders, of which 37,447 (9.06%) were flagged as malicious phishing pages.
The FBI's first year of tracking AI-related complaints yielded 22,364 reports and $893.3 million in losses, a baseline that will almost certainly grow in the 2026 report.
Phishing by industry: healthcare, finance, and small business
Healthcare remains the most expensive sector to breach. IBM's 2026 report puts the average healthcare breach at $6.64 million, the highest of any industry for the 13th consecutive year, with financial services second at $6.29 million.
Verizon's 2026 DBIR healthcare snapshot analyzed 1,438 confirmed healthcare breaches. Social engineering accounted for 22% of them, with phishing the most common technique followed by pretexting. Phishing was the initial vector in 14% of healthcare breaches, and the human element was present in 54%. Combined with KnowBe4's finding that healthcare and pharmaceutical employees have the highest baseline phish-prone percentage at 42.7%, the sector faces a training gap as much as a technology gap. Providers evaluating managed IT services for healthcare should treat phishing resilience as a core requirement.
Small businesses are a paradox in the data. Their employees are less phish-prone at baseline (24.7% versus 39.5% at large enterprises), but they rarely have the detection and response capacity to contain a successful attack within CrowdStrike's 29-minute breakout window. That is the gap managed security services are designed to close.
Third-party and supply chain phishing
Phishing increasingly arrives through a trusted partner rather than a stranger. Verizon found that 48% of breaches in 2026 involved a third party in some capacity, a 60% increase from the previous year. Vendor email compromise, in which an attacker uses a supplier's real mailbox to phish its customers, is a growing share of that figure. Only 23% of third-party cloud environments in Verizon's dataset had fully remediated MFA gaps.
IBM ranked supply chain compromise as the second most common initial attack vector in 2026, directly behind phishing. The two often work together: a phishing email compromises the vendor, and the vendor's account phishes the target.
Emerging trends and what's new in 2026
For journalists and IT leaders tracking phishing statistics in 2026, these are the developments that separate this year's data from last year's:
Losses are rising while volume falls. Zscaler recorded a roughly 20% annual decline in phishing transactions for two years running, yet FBI-reported phishing losses tripled to $215.8 million and BEC losses climbed to $3.05 billion. Attackers are doing less spraying and more targeting.
Voice and device code attacks are the fastest-growing phishing channels. CrowdStrike's 2x rise in vishing and 15x rise in device code phishing in the first half of 2026, combined with Verizon's 40% higher mobile click rate and IBM's $5.29 million vishing breach cost, make a strong case that email-only phishing defenses are now incomplete.
AI is in a quarter of malicious breaches. IBM's one-in-four figure, up 56% in a year, turns AI-enabled phishing from a forecast into a line item. Deepfake impersonation, not AI-written email, is the largest AI-enabled category at 45%.
Shadow AI is creating new phishing surface. The Verizon 2026 DBIR found that 67% of users access unauthorized generative AI services on corporate devices, and 45% of employees are regular AI users whether sanctioned or not. Every unsanctioned AI login is another credential to phish.
Training still works, and the effect is measurable. KnowBe4's 79% reduction in phish-prone percentage after one year is the strongest counterweight in this dataset. IBM adds that organizations using security AI and automation extensively saved $1.93 million per breach compared with those using none, and shortened the breach lifecycle, which averaged 247 days in 2026.
Breach costs hit a record. The $4.99 million global average and $11.5 million US average in IBM's 2026 report are both all-time highs, up 12% and 13% respectively. For US organizations, the cost of a single phishing-initiated breach now exceeds the annual IT budget of many mid-market companies.
How managed IT services can help
Phishing defense in 2026 means email filtering, MFA that resists adversary-in-the-middle kits, monitoring for vishing and device code abuse, and continuous employee training. Few in-house IT teams can cover all of it. Looking for a managed security service provider that can help your organization reduce phishing risk and respond within the breakout window? manageditservices.ai connects businesses with vetted MSSPs and cybersecurity consultants across the United States. Find a provider near you to compare options and get a free assessment.
Related Articles
- Third-Party Data Breach Statistics for 2026Third-party data breaches now account for nearly half of all confirmed breaches worldwide. According to the 2026 Verizon Data Breach Investigations Report, 48% of breaches involved a third-party…
- Small Business Ransomware Statistics for 2026Ransomware has become the defining cyber threat for small businesses. According to the Verizon 2026 Data Breach Investigations Report, ransomware now appears in 48% of all breaches analyzed, up from…
- Small Business Cybersecurity Statistics for 2026Small businesses face an unprecedented wave of cyber threats in 2026. According to the Hiscox Cyber Readiness Report 2026, 56% of U.S.
- Shadow IT Statistics for 2026: What the Latest Data RevealsShadow IT, the use of technology, software, and cloud services without IT department approval, continues to grow as one of the most persistent security and compliance challenges facing…
Hadley McIntosh
Updated Sep 26, 2026 · 11 min read