Facts About Phishing: 20+ Statistics That Define 2026

Sourced phishing statistics for 2026: 971,181 attacks in one quarter, 21 seconds to click, USD 4.88 million breaches, and AI writing most of the bait.

MadhurendraBy Madhurendra
Reviewed by Madhurendra
September 20, 2023
5 min read
Updated August 10, 2026
facts about phishing

Phishing keeps breaking its own records. The APWG counted 971,181 phishing attacks in Q1 2026, the median employee clicks a phishing link 21 seconds after opening it (Verizon DBIR 2025), and a phishing-initiated breach costs an average of USD 4.88 million (IBM Cost of a Data Breach). Here are the numbers that matter this year, each with its source.

How many phishing attacks happen?

Attack volume is still climbing. These are the most recent counts from the APWG, the industry body that has tracked reported phishing since 2003.

  • 971,181 phishing attacks were recorded in Q1 2026, up 13.8% from 853,244 in Q4 2025 (APWG, Q1 2026 report).

  • Q2 2025 hit 1,130,393 attacks, the largest quarter since Q2 2023 (APWG).

  • 2024 closed with more than 4.8 million attacks, an all-time annual record and roughly 20% more than 2023 (APWG).

How fast do employees fall for phishing?

The human window is brutally short. Speed, not sophistication, is what makes phishing work.

  • The median time to click a phishing link is 21 seconds after opening the email, and the median time to report one is 28 minutes (Verizon DBIR 2025). Attackers get a long head start.

  • The average click rate on real phishing emails is 3.4% (Proofpoint State of the Phish). Small percentage, huge exposure: at 1,000 employees that’s 34 people per campaign.

  • Organisations take 207 days on average to identify a breach (IBM Cost of a Data Breach), so one click in January is often still undiscovered in July.

What does a phishing attack cost?

  • A breach that starts with phishing costs an average of USD 4.88 million (IBM Cost of a Data Breach, 2024 edition), keeping phishing among the most expensive initial attack vectors.

  • The 2025 edition puts malicious insider breaches at USD 4.92 million and third-party or supply chain compromise at USD 4.91 million, with phishing close behind (IBM Cost of a Data Breach).

  • One bright spot: the number of wire-transfer business email compromise attacks fell in Q1 2026 (APWG), though the attacks that succeed keep getting costlier.

AI phishing statistics: the 2026 story

The biggest change since our last update isn’t volume, it’s authorship. Machines now write a large share of the bait, and it shows in both quality and scale.

  • 1 in 6 breaches now involve attackers using AI, and of those, 37% used it for phishing and 35% for deepfake impersonation (IBM Cost of a Data Breach, 2025).

  • AI-supported campaigns account for more than 80% of observed social engineering activity worldwide (ENISA Threat Landscape 2025).

  • In December 2025, Hoxhunt recorded a 14x surge in AI-generated phishing emails in a single month, briefly pushing the AI share of inbox phishing past 56%. It has settled at roughly 40% in early 2026.

  • AI-written lures kill the classic advice. Typo-spotting stopped working when the attacker stopped making typos.

Where does phishing happen most?

  • On social media, impersonation makes up 43.8% of all threats and scams another 27.1%, and volume rose on every platform in Q1 2026 (APWG).

  • The most-targeted sectors in Q1 2026 were Telecom and SaaS/Webmail (APWG).

  • QR code phishing (quishing) grew about 400% between 2023 and 2025 as attackers moved the malicious link somewhere email filters can’t read.

What these numbers mean for your team

Three practical conclusions fall out of the data. First, filters alone can’t win when a click happens in 21 seconds, so train the pause: our guide to security awareness training covers how. Second, reporting speed is the metric that matters most, and regular phishing awareness emails to employees keep the reporting habit alive between trainings. Third, test against what attackers actually send. Our phishing email template library mirrors the lures in these statistics, including QR and AI-generated variants, and covers every major type of phishing attack.

Where these numbers come from

Every statistic on this page links to its source. The primary references: the APWG quarterly Phishing Activity Trends Reports, the Verizon DBIR, IBM Cost of a Data Breach (2024 and 2025 editions), the ENISA Threat Landscape 2025, Proofpoint State of the Phish, and Hoxhunt threat detection data. We update this page when new editions land. Last update: August 2026.

FAQs

How common are phishing attacks in 2026?

Very. The APWG recorded 971,181 attacks in Q1 2026 alone, a 13.8% jump in one quarter, and 2024 set the all-time annual record with over 4.8 million. Phishing remains the most reported category of cybercrime.

What percentage of employees click on phishing emails?

About 3.4% of recipients click on real phishing emails on average, per Proofpoint’s State of the Phish research. Untrained organisations often start much higher in simulations, and the median click happens just 21 seconds after the email is opened. See our click rate benchmarks by industry to compare your own results.

How much does a phishing attack cost a company?

IBM’s Cost of a Data Breach research puts a phishing-initiated breach at USD 4.88 million on average. The figure includes detection, response, downtime, and lost business, which is why prevention and fast reporting are cheaper than any cleanup.

Is AI making phishing worse?

Yes, measurably. ENISA attributes over 80% of observed social engineering activity to AI-supported campaigns, IBM found 1 in 6 breaches involve attacker AI, and Hoxhunt measured a 14x monthly surge in AI-generated phishing in December 2025. The practical effect: fluent, typo-free lures at scale.

Ready to reduce your human risk?

PhishGrid helps you run phishing simulations and build a culture of security awareness across your organisation, for free.

Start Free