Contents:
“You’ve been gifted a voucher!”.
“Your account will be closed unless you act now”.
“Late payment demand. Invoice # 207”.
Phishing scams come in many shapes and sizes. And, in 2026, they remain, by far, the most common attack vector targeting both individuals and organizations.
To help you understand the scale of the threat, I’ve compiled this list of the most recent phishing statistics from around the world. I’ve gathered data on phishing published by independent industry bodies, law enforcement agencies, cybersecurity vendors and academia to give as full and broad a picture as possible.
Here’s our rundown of the most significant phishing statistics in 2026.
What is phishing?
Before I dig into 2026 phishing statistics, it’s valuable to have a working definition. Here’s a definition:
Phishing is a malicious technique based on deception, used to steal sensitive information from users. The attackers pretend to be a trustworthy entity to trick the victims into revealing their confidential data.
There are several kinds of phishing, including email phishing, smishing (SMS phishing), vishing (voice phishing) and QR code phishing, among others.
Phishing statistics for 2026
I’ve only included phishing statistics and data that has been published in 2026 or very late in 2025 in certain cases. This will give you the most up to date insights into phishing today.
Phishing in 2026: scale of the issue
In this section, I look at the big picture of the scale of phishing.
Phishing is the most common type of cybercrime in 2026
Phishing is by far and away the most common kind of cybercrime in 2026. Every year, the UK government conducts a survey with businesses and charities. This year’s study found that phishing affects 38% of all businesses and 25% of all charities. This equates to 69% of businesses that experienced a breach or attack.
Similarly, the FBI’s Internet Crime Complaint Center’s most recent statistics (from 2025) show they received almost 192,000 complaints about phishing last year, making it by far the most prevalent kind of reported cybercrime. The next most common issue was extortion, at 89,000 complaints.
Phishing rates may be increasing
The data on phishing rates in 2026 is equivocal. Different authorities may be gathering data in different ways and on different timescales, so the picture is a little unclear.
The UK government survey mentioned above found a slight decrease in phishing rates this year, from 42% last year, to 38% in 2026.
However, the Anti-Phishing Working Group (APWG), which collates data from many international partners, found that phishing attacks rose by 13.8% in early 2026 – from a total of 853,244 in Q4 2025 to 971,181 in Q1 2026.
The APWG’s data also shows an increase in unique phishing email campaigns at the start of the year:

Phishing still below the rates of the mid 2010s
While there may be a slight upward trend in phishing this year, it’s important to put things in context.
An academic study published in late November last year analyzed reports of phishing incidents between 2009 and 2024. Data from three separate databases showed a massive rise from about 2012 which peaked in 2016, before sharply dropping by 2019.
This isn’t to trivialize the issue. But there is often a narrative that this kind of crime is endlessly rising. The reality is somewhat different.
Data on types of phishing in 2026
There are several kinds of phishing which use different vectors of attack. Data from 2026 shows some interesting trends.
Email remains the dominant phishing method
Email remains the attackers’ preferred method. Verizon reports that phishing represents 80% of all email-based attacks in 2026. And ENISA (the EU’s cybersecurity agency) reported that email phishing was the dominant intrusion vector, accounting for approximately 60% of all cases (N.B. this report was from October 2025).
Vast numbers of phishing emails get sent daily. Microsoft Threat Intelligence detected around 8.3 billion email-based phishing threats in the first quarter of 2026 alone.
But email isn’t the only risk
Other phishing techniques are still important. Microsoft’s data shows:
- There were 10.7 million business email compromises attacks in Q1 2026
- QR code phishing increased from 7.6 million in January 2026 to 18.7 million in March
- CAPTCHA-gated phishing volumes reached 11.9 million in March 2026
- Business email compromise (BEC) attacks also reached 10.7 million in Q1
Although email is the main attack vector, these alternative phishing techniques may be more effective. Verizon estimates that phone-based phishing has a success rate of 2% compared to 1.4% with email.
Varying payload methods
Microsoft also records the different kinds of payload methods used by phishing criminals. This shows there’s quite a diverse range:

The bottom line: what does phishing cost?
The costs of phishing are tricky to ascertain. Again, this is because different organisations measure things differently. Do you count the direct impact on the individual victim’s work? Or do you also include the cost of time spent investigating, business disruption, or even penalties for failing to protect customer data?
According to the UK government’s survey, the median perceived cost of phishing was £400 (US $542). However, about 5% of businesses reported costs mounting up to £15,000 ($20,300).
Meanwhile, the FBI reported total losses from phishing in 2025 mounted to almost $216 million.
These figures, however, are dwarfed by those of IBM. In their 2026 Cost of a Data Breach report, they estimate that individual phishing incidents cost businesses US $5.29 million, on average.
IBM explains that the costs of detection, escalation and lost business account for a large part of this figure. That may explain the disparity with the FBI and UK government’s data, which just focus on the direct cost.
AI and phishing – an emerging problem
Like any tool, AI can be used for both good and for ill. And criminals are certainly turning to it for support.
According to Hoxhunt, a security training provider, there was a 14x increase in AI-generated phishing emails that bypassed email security filters at the start of 2026. Their report also discovered that:
- 43% of AI phishing emails use malicious links
- 11% of them use malicious attachments
- 19% of AI phishing emails promote fraudulent offers and rewards
Meanwhile, Verizon looked at how AI is being used in different forms of attack in 2026. They found that:
- Phishing is the main way the tech is being used (44% of the total).
- Exploitation of vulnerabilities comes next (32%).
- The rest goes to credential abuse (21%).
Statistics on phishing victims in 2026
So, who’s being targeted by phishing this year? The data provides some valuable insights.
A third of people are phish-prone
KnowBe4, a training company, produces an annual analysis of phishing simulations. Their data shows that in 2026, 33.2% of workers are ‘phish prone’. This means an individual is more likely to open a phishing email and become a victim.
Business size and risk level
KnowBe4’s data also shows that employees at larger companies are more likely to be phishing-prone.

Sectors most likely to be targeted
In 2026, the APWG’s data suggests that the telecom industry is most likely to be targeted by phishing:

Attacks by region
Phishing is a global phenomenon. However, it affects different regions in different ways. According to Verizon’s data, initial access vectors where breaches are successful range quite considerably.

This data shows that phishing is more likely to be successful in the EMEA and LAC region than in North America or APAC. Overall, phishing is least successful in the North America region.
Demographics of phishing victims
The FBI provides some interesting insights into the age groups of phishing victims in the United States. For their 2025 figures, people in the 60+ group are most likely to be victims:

Individual characteristics and phishing
A fascinating academic study was published in 2026 which analyzed data from many other studies into the individual characteristics of phishing victims. Some insights include:
- People are more likely to fall for phishing when they have a high workload or face time pressures
- A high email volume is associated with increased likelihood of becoming a phishing victim
- People who are extraverted and people who are impulsive are more likely to fall for phishing scams
- Phishing emails with an urgency cue, an authority cue or a scarcity cue are more likely to be successful
Some good news: criminals arrested
Few crime agencies provide detailed data about arrests for phishing specifically. However, there have been some important news stories this year:
- In February, Interpol announced the arrest of 651 criminals involved in phishing and other scams across Africa
- Also in February, 201 individuals involved in cyber scams and phishing were arrested across the MENA region
- In April, the FBI and Indonesian police dismantled a global phishing operation, took down the off-the-shelf W3LL toolkit and arrested its alleged developer
Stay ahead of phishing in 2026
As these 2026 phishing statistics show, this form of cyber crime remains extremely widespread. And with the emergence of AI and new phishing categories, it’s constantly evolving.
But, with a combination of tools and training, organizations can stay on top of the threat. See how Heimdal’s email security products can help you guard against BECs, CEO fraud, impersonation and other forms of phishing.
If you liked this article, follow us on LinkedIn, Reddit, X, Facebook, and Youtube.