Managed ITServices
Statistics

Phishing Statistics 2025: The Year in Review (Updated 2026)

Phishing remained the single most reported cybercrime in the United States throughout 2025, and the numbers paint a sobering picture.

Phishing remained the single most reported cybercrime in the United States throughout 2025, and the numbers paint a sobering picture. While organizations poured billions into security tooling, threat actors adapted faster, weaponizing artificial intelligence, exploiting third-party trust chains, and refining social engineering tactics that bypass even modern email gateways. This article compiles the most important phishing statistics from 2025, drawn from primary research by the FBI, APWG, Verizon, and Microsoft, and closes with early 2026 data that shows the threat is still accelerating.

Key Phishing Statistics From 2025

Phishing Statistics 2025: The Year in Review (Updated 2026) infographic

The Financial Toll of Phishing in 2025

Every phishing email carries a price tag, whether it results in a ransomware deployment, a fraudulent wire transfer, or simply the operational cost of investigating and remediating the incident. The raw complaint numbers only tell part of the story. When the FBI released its 2025 Internet Crime Report in early 2026, the headline figure was $20.9 billion in total losses, but the phishing-adjacent categories deserve a closer look. Phishing and spoofing complaints generated $215.8 million in direct reported losses. BEC, which almost always begins with a phishing email or compromised inbox, added another $3.05 billion. Together, these two categories represented over 21% of all cybercrime complaints and more than half of total dollar losses when combined with investment fraud that often originates from phished credentials.

For small and mid-sized businesses, the per-incident cost is disproportionately painful. APWG data from Q1 2025 showed the average BEC wire transfer request sitting at $42,236, while Q4 saw that figure climb to over $50,000. Gift card scams, a hallmark of BEC campaigns targeting smaller organizations, accounted for 51% of all BEC attack volume in the first quarter. These are not nation-state-level heists. They are everyday attacks hitting everyday businesses.

How AI Changed the Phishing Landscape

If 2024 was the year security vendors warned about AI-powered phishing, 2025 was the year the data confirmed their fears. Microsoft's Digital Defense Report documented that AI-crafted phishing emails achieved click rates more than four times higher than their manually written counterparts. The grammatical errors and awkward phrasing that once served as reliable red flags have largely disappeared from modern phishing campaigns.

The Verizon 2026 DBIR noted that the median threat actor leveraged AI across 15 documented techniques, not to invent novel attack methods, but to scale and polish existing ones. Deepfakes added another dimension: Gartner research from 2025 found that between 35% and 62% of surveyed organizations had experienced at least one deepfake-related incident, with 41% involving audio deepfakes paired with social engineering.

Meanwhile, only 10% of security leaders said they were prioritizing deepfake-specific training for employees. That gap between the pace of attacker innovation and the pace of defender adaptation defined much of the 2025 phishing landscape. Traditional email security tools, already struggling, saw their limitations exposed further: one report found a 104.5% increase in malicious emails bypassing secure email gateways compared to the prior year. The old playbook of blocking known-bad domains and scanning for malware attachments simply cannot keep up when attackers use generative AI to craft unique, contextually relevant messages at scale.

Third-Party Risk and the Supply Chain Problem

One of the most striking findings from the Verizon 2026 DBIR was that 48% of breaches involved a third party, a 60% increase year over year. This means attackers are no longer just phishing your employees. They are phishing your vendors, your SaaS providers, and your managed service partners, then using those compromised relationships to reach you.

The APWG identified a BEC group called Scripted Sparrow as the most active business email compromise organization globally in Q4 2025, sending up to 6 million emails per month using spoofed reply chains. Their technique was deceptively simple: fabricate an email thread that appeared to show a company executive approving an expense, then insert a fraudulent payment request into the conversation.

Credential abuse appeared in 39% of breaches across the full intrusion chain, and 44.2% of employees who received a vendor email compromise message engaged with it. That engagement rate highlights a fundamental challenge: when a phishing email arrives from a trusted partner's real email address, traditional "look for suspicious senders" training falls short.

The Emerging Channels: Quishing, Smishing, and Voice Phishing

Email remained the dominant phishing vector in 2025, but attackers increasingly diversified. QR code phishing, often called "quishing," gained significant traction. The APWG noted that criminals exploited free QR code generators and URL shorteners to funnel victims toward phishing sites, with retail and wholesale sectors showing particular vulnerability.

Smishing, or SMS-based phishing, grew 30% to 40% quarter over quarter by Q4 2025. Phone-centric phishing simulations tracked by Verizon showed a roughly 2% median click rate, about 40% higher than email-based simulations. The difference matters because SMS messages carry an inherent sense of urgency and are harder to inspect on a small screen.

In the UK, the Cyber Security Breaches Survey 2025/26 reported that 38% of businesses experienced a phishing attack in the preceding 12 months, with 69% of affected firms calling phishing the most disruptive attack type they faced. The UK's National Cyber Security Centre removed over 1.2 million phishing campaigns during the same period.

What Changed in 2026

Early 2026 data suggests the trends from 2025 are intensifying rather than leveling off. Microsoft Defender reported a 146% increase in QR code phishing between January and March 2026, confirming that quishing is moving from novelty to mainstream attack vector.

The Verizon 2026 DBIR, published in mid-2026 with data spanning the prior year, reinforced that vulnerability exploitation surpassed credential abuse as the top initial access method at 31% of breaches, but phishing remains the primary way attackers harvest the credentials that fuel lateral movement. Only 26% of known exploited vulnerabilities were remediated in 2025, down from 38% the year before, suggesting that patching discipline is eroding even as phishing volumes hold steady.

Organizations are also contending with a remediation gap on the human side. The Verizon report found that 84% of security leaders still rely on training completion rates as their primary metric for phishing resilience, while only 73% prioritize phishing reporting rates, a far more meaningful indicator of whether employees can actually recognize and escalate threats.

How Managed IT Services Can Help

The statistics above share a common thread: phishing succeeds because it targets the intersection of human behavior, technology gaps, and organizational complexity. For small and mid-sized businesses without dedicated security operations centers, closing those gaps internally is rarely realistic.

A managed IT services provider can layer the defenses that phishing statistics consistently show are missing. That starts with advanced email filtering that goes beyond basic secure email gateways, which saw a 104.5% increase in bypass rates during 2025. It extends to ongoing security awareness training that measures reporting behavior rather than just course completion, endpoint detection that catches credential theft in progress, and incident response planning that accounts for BEC, quishing, and voice phishing scenarios.

Third-party risk management, the area where 2025 saw a 60% year-over-year spike in breach involvement, is another area where managed services deliver outsized value. Continuous monitoring of vendor access, enforced multi-factor authentication, and regular access reviews are operational disciplines that require consistent staffing and attention.

Perhaps most importantly, a managed IT partner brings the kind of 24/7 vigilance that phishing demands. Attackers do not operate on business hours, and a BEC wire transfer request sent at 6 PM on a Friday is designed to exploit exactly the moment when internal oversight is thinnest. Having a dedicated team that monitors, detects, and responds around the clock turns what would otherwise be a catastrophic breach into a contained and recoverable event.

The phishing statistics from 2025 make one thing clear: the threat is not slowing down, and the attackers are getting better. The question for every business is whether their defenses are keeping pace.

Need Help With Your Security Strategy?

Get a free assessment from our team of cybersecurity experts.

Related Articles

HM

Hadley McIntosh

Updated Sep 27, 2026 · 8 min read