Back to Cybersecurity

Phishing Statistics 2026: Sourced Numbers and What They Mean for Your Controls

Phishing statistics illustration: a phishing hook catching an email envelope, with stat badges for attack volume and breach share

Short answer: Phishing is still the most reported cybercrime and a steady breach entry point. The FBI logged 191,561 phishing and spoofing complaints in 2025, Verizon's 2026 DBIR puts phishing at 16% of breach entry points, and APWG counted over one million phishing attacks in Q2 2026. The fix is layered controls, not training alone.

Related guides:

Key takeaways

  • Volume stays high. APWG observed 1,069,681 phishing attacks in Q2 2026, up 10.1% from Q1, and phishing and spoofing was the most reported crime type to the FBI in 2025, with 191,561 complaints.
  • The money is in business email compromise. BEC generated about $3.05 billion in reported losses to the FBI in 2025, roughly 14 times the losses reported for phishing and spoofing itself.
  • Phishing is one door among several. Verizon's 2026 DBIR found phishing in 16% of breaches as the initial access vector, behind vulnerability exploitation at 31%. The human element still appeared in 62% of breaches.
  • Healthcare carries extra weight. HHS reports that 81% of large HIPAA breaches in 2024 came from hacking or IT incidents, and PHI in email was involved in 25% of all large breaches.
  • Scope note. These figures come from US (FBI, HHS), UK (government survey) and global (Verizon, APWG) sources, so treat them as directional for other countries. For wider context, see our data breach statistics and social engineering statistics.
  • Controls lag the threat. In the UK, 38% of businesses experienced phishing, but only 47% use two-factor authentication and 25% have a formal incident response plan.

How common is phishing in 2026?

Phishing is the most frequently reported cybercrime in the United States and attack volume rose through the first half of 2026.

According to the FBI's 2025 Internet Crime Report, the Internet Crime Complaint Center (IC3) received 1,008,597 complaints in 2025, up from 859,532 in 2024 according to the FBI's announcement of its 2024 report. Phishing and spoofing was the top crime type by complaint count, with 191,561 complaints. IC3 defines the category broadly: unsolicited email, text messages and phone calls that pretend to be a legitimate company to collect personal, financial or login details.

The Anti-Phishing Working Group (APWG) tracks phishing sites rather than victim complaints, and its numbers point the same way. The APWG Phishing Activity Trends Report for Q2 2026, published August 28, 2026, recorded:

  • 1,069,681 phishing attacks in Q2 2026, a 10.1% increase over Q1 2026 (971,181)
  • 425,808 attacks in June 2026 alone, the highest monthly total since April 2023
  • SaaS and webmail as the most targeted sector, at 29.1% of attacks
  • Smishing up 40% and vishing up 20% from Q1 to Q2 2026

The SaaS and webmail figure matters for any company that runs on cloud email and identity providers: attackers want the login that unlocks everything else.

How much money does phishing cost organizations?

Phishing itself produces modest reported losses per victim, but the business email compromise that often follows it is one of the costliest crimes the FBI tracks.

In the FBI's 2025 report, phishing and spoofing complaints carried $215,843,126 in reported losses. Business email compromise generated far fewer complaints (24,768) but $3,046,598,558 in losses. Total reported losses across all crime types reached $20.877 billion.

Divide those figures and the pattern is clear: the average BEC complaint represented roughly $123,000 in losses, while the average phishing and spoofing complaint represented about $1,100. The stolen mailbox password is cheap. The fraudulent wire instruction sent from that mailbox later is where you pay.

APWG data shows the size of those requests is rising. The average wire transfer requested in BEC attacks was $61,732 in Q2 2026, a 45% increase from $42,663 in Q1, and wire transfer BEC attempts rose 88% quarter over quarter.

What it means for controls: payment and vendor bank detail changes need documented out-of-band verification, such as a callback to a known number.

How often does phishing lead to a data breach?

Phishing was the initial access vector in 16% of breaches in Verizon's 2026 Data Breach Investigations Report, unchanged from the prior year.

The 2026 DBIR, published May 19, 2026, analyzed more than 22,000 breaches from incidents between November 1, 2024 and October 31, 2025. Its headline numbers for phishing and the human element:

DBIR 2026 finding Value
Phishing as initial access vector 16% of breaches
Vulnerability exploitation as initial access vector 31% of breaches (20% the prior year)
Credential abuse as initial access vector 13% of breaches (22% the prior year)
Human element present 62% of breaches (60% the prior year)
Ransomware present 48% of breaches (44% the prior year)
Third-party involvement 48% of breaches (30% the prior year)

Two points stand out. In the 2026 DBIR, vulnerability exploitation (31%) was a more common entry point than phishing (16%) or credential abuse (13%), so phishing defenses cannot crowd out patching. And the same report found the median click rate for mobile-centric vectors, such as voice and text messaging, is 40% higher than via email. With APWG's smishing and vishing growth, your threat model should cover phones too.

Are small businesses ready for phishing attacks?

Survey data suggests many smaller organizations face phishing regularly but have not adopted the controls that limit its impact.

The UK government's Cyber Security Breaches Survey 2025/2026, published April 30, 2026, is one of the few official surveys that breaks results down by business size:

  • 43% of businesses identified a breach or attack in the previous 12 months (42% of micro, 46% of small and 65% of medium businesses)
  • 38% of businesses experienced phishing, which remained "the most prevalent type of breach or attack by far"
  • 69% of organizations that had a breach or attack named phishing as the most disruptive
  • 47% of businesses use two-factor authentication
  • 25% of businesses have a formal incident response plan
  • 19% of businesses reported staff training and awareness raising activities, unchanged from the prior year

The gap between those last three numbers and the threat is exactly what customer security questionnaires probe.

What do healthcare phishing statistics show?

Healthcare phishing statistics show email remains a common route to large HIPAA breaches, and in the OCR settlements below, a successful phish led to findings about the organization's risk analysis.

The HHS Office for Civil Rights report to Congress on 2024 breaches found:

  • 663 breaches affecting 500 or more individuals, affecting approximately 242.9 million individuals in total (a handful of very large incidents can dominate a total like this, so it does not reflect a typical breach)
  • 534 of those (81%) were hacking or IT incidents, which OCR says involved malware, phishing and posting PHI to public websites
  • 164 large breaches (25%) involved PHI in email
  • 74,299 smaller breach reports affecting fewer than 500 individuals each

Verizon's 2026 DBIR healthcare snapshot counted 1,492 healthcare incidents, 1,438 with confirmed data disclosure. System Intrusion, Miscellaneous Errors and Social Engineering made up 81% of healthcare breaches, and Verizon summarizes the sector as facing financially motivated attackers "exploiting vulnerabilities, Phishing, and using stolen credentials."

OCR enforcement shows how phishing becomes a HIPAA finding:

  • In December 2023, OCR announced its first settlement of a phishing attack investigation: Lafourche Medical Group paid $480,000 after a phished email account exposed ePHI of about 34,862 individuals. OCR found no risk analysis and no procedures for reviewing information system activity. OCR's director said at the time that "phishing is the most common way that hackers gain access to health care systems."
  • In April 2025, PIH Health agreed to pay $600,000 after a phishing attack compromised 45 employee email accounts and affected 189,763 individuals. OCR's findings again included the lack of an accurate and thorough risk analysis, plus late breach notification.

For HealthTech vendors acting as business associates, the takeaway is that mailbox security is PHI security. If clinical or patient data ever passes through email, review our guide to HIPAA compliant email.

Which controls does each phishing statistic point to?

Each statistic maps to a specific control family, and most of those controls already appear in SOC 2, ISO 27001 and HIPAA.

Statistic Source What it means for your controls
191,561 phishing and spoofing complaints, the top crime type FBI IC3, 2025 Email filtering, SPF, DKIM and DMARC enforcement, and an easy report-phish button
$3.05 billion in BEC losses FBI IC3, 2025 Out-of-band verification for payments and vendor bank changes
1,069,681 phishing attacks, SaaS/webmail 29.1% of targets APWG, Q2 2026 Protect identity provider and email logins first, with conditional access
Smishing up 40%, vishing up 20% APWG, Q2 2026 Help desk identity verification and mobile phishing in training scenarios
Phishing is 16% of breach entry points Verizon DBIR, 2026 Layered email defenses, plus endpoint detection for when one gets through
Human element in 62% of breaches Verizon DBIR, 2026 Role-based awareness training with measured reporting rates
Third-party involvement in 48% of breaches Verizon DBIR, 2026 Vendor risk reviews that ask about MFA and email security
38% of UK businesses phished, 47% use 2FA UK CSBS, 2025/2026 Enforce MFA on all accounts, moving toward phishing-resistant methods
25% of UK businesses have a formal IR plan UK CSBS, 2025/2026 A written, tested playbook for compromised mailboxes
25% of large HIPAA breaches involved email HHS OCR, 2024 Encrypt PHI, limit PHI retained in mailboxes, monitor mailbox access

On MFA specifically, CISA's phishing-resistant MFA fact sheet says "phishing-resistant MFA is the gold standard for MFA" and that "the only widely available phishing-resistant authentication is FIDO/WebAuthn authentication." It also describes PKI-based MFA, such as smart cards like the U.S. government's PIV card, as a less widely available phishing-resistant option. CISA says SMS and voice codes, which are vulnerable to phishing and SIM swap attacks, should only be used as a last resort.

Here is how those controls are commonly mapped to the frameworks your customers ask about. Mappings are interpretations, so confirm them with your auditor:

Control area SOC 2 criteria commonly mapped ISO 27001:2022 Annex A HIPAA Security Rule
Awareness training CC1.4, CC2.2 A.6.3 164.308(a)(5)
Authentication and MFA CC6.1 A.8.5 164.312(d)
Email and malware protection CC6.8 A.8.7 164.308(a)(5)(ii)(B)
Incident response CC7.3, CC7.4 A.5.24 to A.5.26 164.308(a)(6)
Risk assessment CC3.2 Clause 6.1.2 164.308(a)(1)(ii)(A)

Training is one row of five, which is why a training platform alone will not satisfy an auditor.

How should you use phishing stats in your risk assessment?

Use external phishing statistics to justify the likelihood rating in your risk register, then back each control with your own internal evidence.

  1. Cite the source and year. A risk entry that says "phishing is the top IC3 complaint type (FBI, 2025)" is defensible. One that cites an unsourced percentage is not.
  2. Match the statistic to your exposure. HealthTech vendors should lean on HHS data, wire-heavy businesses on BEC figures.
  3. Pair each external number with an internal metric. Track phishing reports per month, simulation reporting rates, MFA coverage and mailbox compromise incidents.
  4. Refresh annually. APWG publishes quarterly and the DBIR, IC3 report, UK survey and HHS breach report annually, so stale numbers are easy to spot.
  5. Tie findings to an incident playbook. When a phish lands, your incident response plan should cover password resets, session revocation, mailbox rule review and breach assessment.

How SecureSlate helps

SecureSlate helps you prepare for the phishing questions auditors and customers ask. You can log phishing and business email compromise in your risk register with the source behind each likelihood rating, map your training, MFA, email security and incident response controls through the control library to SOC 2, ISO 27001 and HIPAA, and start from policy templates for acceptable use and incident response. Automated evidence collection can store evidence such as MFA settings, and vendor risk reviews help you track how third parties secure email and authentication.

Start your free SecureSlate trial

FAQ

What percentage of breaches start with phishing?

Verizon's 2026 Data Breach Investigations Report found phishing was the initial access vector in 16% of breaches, the same share as the prior year. Vulnerability exploitation (31%) and credential abuse (13%) were the other leading entry points.

Is phishing a HIPAA violation?

Being phished is not a violation by itself. OCR enforcement after phishing incidents has focused on missing risk analyses, weak activity review and late breach notification. Those are the gaps that turn a phishing incident into a settlement.

Does security awareness training stop phishing?

Training reduces risk but does not remove it. The human element appeared in 62% of breaches in the 2026 DBIR, which is why training should sit alongside phishing-resistant MFA, email authentication, payment verification and a tested incident response plan.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Keep reading

Oct 5, 2026 · Cybersecurity

Essential Eight Compliance Cost: What Drives Effort and Budget at ML1 to ML3

Oct 4, 2026 · Cybersecurity

Phishing-Resistant MFA: How to Roll Out Passkeys and Security Keys for Compliance

Oct 3, 2026 · Cybersecurity

NIST Phish Scale: How to Make Phishing Simulation Results Mean Something

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?