
Phishing remains one of the most common cyber threats facing businesses and consumers. Attackers now combine email, social media, messaging apps, QR codes, and artificial intelligence to steal credentials, financial information, and corporate data. Organizations use phishing statistics to improve employee training, while security teams rely on them to strengthen email security and incident response programs. Explore the latest figures below to understand how phishing continues to evolve across the US and worldwide.
Editor’s Choice
- The FBI received more than 1 million internet crime complaints in 2025, with phishing/spoofing remaining one of the most frequently reported cybercrime categories.
- Americans reported nearly $21 billion in internet crime losses during 2025, marking another record year for cyber-enabled fraud.
- APWG recorded 971,181 phishing attacks during Q1 2026, a 13.8% increase from Q4 2025.
- APWG observed 1,003,924 phishing attacks in Q1 2025, making it one of the highest quarterly totals recorded since late 2023.
- Credential abuse accounted for 22% of confirmed data breaches analyzed in the latest global breach investigations.
- In 2025, phishing/spoofing generated $77 million in reported victim losses submitted to the FBI, compared with about $20 million in 2024.
- Telecom and SaaS/webmail organizations became the most targeted sectors in APWG’s Q1 2026 phishing analysis.
Recent Developments
- APWG reported phishing activity increased 13.8% quarter over quarter between Q4 2025 and Q1 2026.
- Social media phishing campaigns expanded across every major platform during Q1 2026, with impersonation representing 43.8% of observed threats.
- Scam campaigns represented 27.1% of all social platform threats tracked during early 2026.
- QR code phishing remained a major tactic, with millions of phishing emails delivering malicious QR codes instead of clickable links throughout 2025.
- Wire transfer BEC attacks declined during Q1 2026 after increasing sharply throughout 2025.
- The FBI added a dedicated section on AI-related cybercrime to its latest Internet Crime Report, reflecting the rapid growth of AI-assisted scams.
- AI-related complaints generated nearly $893 million in reported losses during 2025.
- Cyber-enabled fraud complaints exceeded 453,000 during 2025, highlighting continued growth in online financial crime.
- The FBI’s IC3 now processes roughly 3,000 cybercrime complaints every day.
Phishing Attack Volume
- APWG recorded 971,181 phishing attacks during the first quarter of 2026.
- Q1 2026 phishing activity increased from 853,244 attacks reported during Q4 2025.
- APWG detected 1,003,924 phishing attacks during Q1 2025.
- Phishing remained among the top three internet crimes reported to the FBI in both 2024 and 2025.
- The FBI received 1,008,597 total cybercrime complaints during 2025, up from 859,532 in 2024.
- More than 1 million complaints submitted during 2025 demonstrate that phishing and related fraud continue affecting consumers at scale.
- APWG data shows phishing activity has remained near record highs across consecutive quarters since 2023.
- Financial institutions and online payment providers together represented 30.9% of phishing targets during Q1 2025.
- Telecom providers became one of the largest phishing targets entering 2026.

Phishing Trends Over Time
- APWG surpassed 1 million phishing attacks in a single quarter during Q1 2025.
- Quarterly phishing activity remained above 850,000 incidents through late 2025 before climbing again in 2026.
- Phishing/spoofing has consistently ranked among the most reported cybercrimes in successive FBI annual reports.
- Reported phishing/spoofing financial losses rose from about $3.4 million (2023) to $20.2 million (2024) and $77 million (2025).
- Internet crime losses climbed from over $16 billion in 2024 to nearly $21 billion in 2025.
- Organizations increasingly face phishing campaigns that combine AI-generated content with traditional social engineering.
- Credential abuse continues to rank among the leading initial access methods in confirmed breaches worldwide.
- Criminals increasingly combine phishing with credential theft, business email compromise, and identity fraud instead of relying on standalone phishing emails.
- Security researchers continue reporting sustained phishing growth despite stronger email authentication technologies.
Email Phishing Statistics
- Email remains the primary delivery channel for phishing campaigns worldwide.
- APWG reported that SaaS/webmail providers ranked among the most targeted sectors in Q1 2026.
- During Q3 2025, 74% of observed BEC attacks originated from free webmail accounts.
- Among free webmail providers used in BEC attacks, 66% utilized Gmail accounts.
- Microsoft webmail services accounted for 16% of free webmail accounts used in BEC campaigns during Q3 2025.
- Credential abuse represented 22% of confirmed breaches, reflecting the continued effectiveness of phishing emails designed to steal login credentials.
- Business email compromise continued generating hundreds of millions of dollars in reported annual losses.
- Email phishing increasingly incorporates AI-generated writing, making fraudulent messages more convincing and grammatically accurate.
- Organizations continue adopting DMARC, SPF, and MFA because email remains the largest phishing attack surface.
Social Media Phishing Statistics
- Impersonation attacks accounted for 43.8% of social platform phishing threats in Q1 2026.
- Social media scams represented 27.1% of observed threats across monitored platforms in early 2026.
- The combined share of impersonation and scams represents 70.9% of the core social media threat landscape.
- LinkedIn phishing messages account for 47% of all social media phishing attempts.
- Phishing threats on Tumblr grew by 200%, while Twitch saw a 149% increase in Q1 2026.
- Malicious threats on TikTok and LinkedIn experienced growth rates of 133% and 130%, respectively.
- Global phishing attacks rose 13.8% to reach 971,181 total incidents during Q1 2026.
- AI-driven phishing campaigns have boosted successful click-through rates to 54% across platforms.

SMS and Smishing Statistics
- SMS-based fraud detections grew by 30–40% quarter-over-quarter throughout 2025.
- Telecom sector attacks surged from 5.9% in Q3 2025 to 33% by Q1 2026.
- URL phishing frequency within the telecom industry increased by 75% since Q4 2025.
- Phone-based phishing simulations yield a median click rate 40% higher than traditional email.
- Social media and SMS phishing accounted for 17.3% of overall attacks in late 2025.
- Smishing makes up over two-thirds of all observed mobile-based phishing threats.
- SMS and voice simulations report a ~2% median click rate compared to ~1.4% for email.
- Phishing attacks across all vectors rose 13.8% to reach 971,181 incidents in Q1 2026.
QR Code Phishing Statistics
- Credential theft is the primary objective in QR code attacks, representing 89.3% of all detected incidents.
- The volume of QR code phishing attacks experienced a massive 400% increase between the years 2023 and 2025.
- Malicious actors focus heavily on mobile platforms, with 68% of phishing attacks explicitly targeting mobile users.
- Fake QR stickers placed over real ones caused $2.3 million in damages and a 15% decrease in legitimate scans.
- During the first quarter of 2025, analysts observed over 1 million phishing attacks with a notable spike in QR-code lures.
- Approximately 12% of all detected phishing attacks globally contained a malicious QR code in 2025.
- Corporate leaders are highly targeted, with executives being 40 times more likely to face QR code attacks than average employees.
- The energy sector is disproportionately affected, receiving 29% of all malware-infested quishing emails.
- Proper security training can drastically reduce risk, improving QR phishing detection rates by 87% within three months.
- In 2025, about 56% of quishing emails were designed to mimic Microsoft 2FA resets to steal corporate credentials.
Credential Theft Statistics
- Credential abuse accounted for 22% of confirmed data breaches analyzed in the latest global breach investigations.
- Analysis of infostealer malware showed that only 49% of users’ passwords were unique across different services, increasing credential reuse risk.
- Credential stuffing represented a median of 19% of daily authentication attempts across analyzed organizations.
- Enterprise organizations experienced credential stuffing rates reaching 25% of authentication attempts on a typical day.
- Small businesses still experienced credential stuffing activity equal to 12% of authentication attempts.
- Researchers observed single-day credential stuffing peaks reaching 44% of all authentication attempts.
- 46% of compromised devices containing corporate credentials were unmanaged endpoints that stored both personal and business logins.
- 54% of ransomware victims analyzed had internet domains appearing in credential dumps, indicating stolen credentials often support later attacks.
- Credential theft continues serving as one of the primary outcomes of phishing campaigns targeting employees and consumers alike.

Business Email Compromise Statistics
- APWG observed a 25% decline in wire transfer BEC attacks during Q1 2026 compared with Q4 2025.
- The average wire transfer requested in BEC attacks fell to $42,663 during Q1 2026, down 15% from the previous quarter.
- During Q1 2025, wire transfer BEC attacks had increased 33% compared with the previous quarter before moderating in 2026.
- 74% of BEC attacks observed in Q3 2025 originated from free webmail accounts.
- Gmail accounted for 66% of the free webmail accounts used in BEC campaigns during Q3 2025.
- Microsoft-hosted webmail services represented 16% of free email accounts used in observed BEC attacks.
- Domain registrars NameSilo and NameCheap remained the registrars most frequently associated with BEC-related domains during Q1 2026.
- BEC remains one of the most financially damaging forms of phishing despite fluctuations in quarterly attack volume.
- Attackers increasingly combine compromised email accounts with AI-generated messages to make executive impersonation more convincing.
Financial Losses from Phishing
- Americans reported nearly $21 billion in internet crime losses during 2025, the highest annual total on record.
- The FBI received more than 1 million cybercrime complaints during 2025, reflecting continued growth in phishing-related fraud.
- Reported phishing and spoofing losses increased to approximately $77 million in 2025, compared with about $20 million in 2024.
- AI-related cybercrime generated nearly $893 million in reported victim losses during 2025.
- Business email compromise remains highly damaging, producing over $3 billion in losses across 24,768 complaints during 2025.
- Wire transfer fraud remains a leading financial objective in enterprise phishing campaigns, averaging $42,236 per attack.
- Credential theft drives 80% of phishing campaigns, frequently leading to additional financial crimes like account takeover and ransomware.
- Organizations continue increasing cybersecurity budgets because phishing remains a costly initial vector, averaging $4.88 million per breach.
- The financial impact of phishing extends beyond direct theft, with delayed containment over 200 days adding $1.2 million in damages.
Phishing Targets by Industry
- Social media platforms are the most targeted category, accounting for 37.6% of all phishing activity shown in the data.
- SaaS and webmail services rank second with a 21% share, highlighting their appeal to attackers seeking login credentials.
- Financial institutions represent 9.8% of phishing targets, placing the banking sector among the most frequently impersonated industries.
- Payment platforms account for 7.2% of attacks, reflecting the continued focus on services linked to financial transactions.
- E-commerce and retail businesses make up 5.4% of phishing activity, often involving fake stores, order alerts, or account notices.
- Logistics and shipping companies account for 5%, showing how delivery notifications remain a common phishing lure.
- Telecom providers represent 2% of phishing targets, despite holding valuable customer and account information.
- Cryptocurrency platforms also account for 2%, indicating a smaller but financially attractive target category.
- Other industries collectively make up 10% of phishing activity, showing that attacks extend beyond the leading sectors.

Phishing by Region
- North America recorded 12,371 security incidents, including 8,426 confirmed data breaches, in the latest regional breach analysis.
- In North America, credential abuse accounted for 20% of initial access vectors, while phishing represented 12%.
- Europe, the Middle East, and Africa (EMEA) recorded 8,245 incidents with 6,060 confirmed data disclosures.
- In EMEA, phishing represented 28% of initial access vectors, exceeding credential abuse at 6%.
- Asia-Pacific recorded 5,229 incidents with 2,855 confirmed data disclosures.
- In APAC, 15% of breaches involved phishing as the initial access vector, while 25% involved credential abuse.
- Latin America recorded 813 incidents and 718 confirmed breaches, with phishing accounting for 20% of initial access vectors.
- Financial motivation dominated breach activity across every major geographic region analyzed.
- Human interaction remained a key factor in successful phishing attacks across all global regions, highlighting the continued need for user awareness training.
Attack Delivery Methods
- Over 90% of cyberattacks are initiated through a phishing delivery method.
- 3.4 billion phishing emails are sent globally every single day.
- 43.8% of social platform threats in early 2026 involved account impersonation.
- Scam campaigns represented 27.1% of all social media threats during the same period.
- QR code phishing (quishing) attacks expanded by 400% between 2023 and 2025.
- 68% of all quishing attacks specifically targeted mobile device users.
- Multi-channel phishing campaigns now account for 41% of all attacks.
- SMS-based fraud detections grew by 30% to 40% quarter-over-quarter throughout 2025.
- Nearly 40% of phishing campaigns now utilize platforms beyond traditional email.
- 89.3% of detected QR code attacks were specifically designed for credential theft.
Most Targeted Brands
- Microsoft remained the most impersonated brand in phishing campaigns during Q1 2026, accounting for 22% of all observed brand phishing attempts.
- Apple ranked second with 11% of all brand impersonation attacks recorded during Q1 2026.
- Google accounted for 9% of phishing brand impersonation campaigns during the same period.
- Amazon represented 7% of observed phishing impersonation attacks worldwide.
- LinkedIn ranked fifth with 6% of brand phishing attempts, reflecting continued attacks targeting professional identities.
- The top four brands together accounted for nearly 50% of all recorded brand phishing campaigns in Q1 2026.
- The technology sector remained the most impersonated industry because attackers seek access to enterprise cloud accounts and email platforms.
- Social networking platforms ranked behind technology brands as major phishing impersonation targets.
- Banking brands continued attracting phishing campaigns because compromised accounts provide direct financial rewards.

AI-Generated Phishing Statistics
- The IC3 received 22,364 AI-related complaints during 2025.
- AI-enabled cybercrime generated nearly $893 million in reported victim losses during 2025.
- Generative AI-assisted phishing emails boast a 54% click rate, up from 12% for traditional campaigns.
- There has been a 1,265% increase in malicious phishing emails since the launch of mainstream AI chatbots.
- Over 82.6% of all newly generated phishing emails currently contain AI-generated elements.
- AI tools have accelerated phishing creation by 192 times, reducing crafting time from 16 hours to 5 minutes.
- Approximately 60% of recipients fall victim to AI-generated phishing due to perfect grammar and personalization.
- AI-powered voice and deepfake employment fraud alone accounted for $13 million in losses in 2025.
- The average cost of a phishing-initiated data breach reached $4.8 million in 2025.
- Attackers using AI-generated QR code phishing (quishing) increased their attack volume by 400% through 2025.
Phishing Detection and Prevention Statistics
- Global DMARC adoption reached 52.1% by 2026, yet over half of these domains remain in monitoring mode without active spoofing protection.
- Phishing-resistant Multi-factor authentication (MFA) successfully blocks more than 99% of identity-based attacks even when attackers possess valid credentials.
- Compromised and stolen credentials served as the initial access vector in 22% of all confirmed data breaches in 2025.
- AI-driven phishing attacks are 3 to 4.5 times more effective than traditional methods, accelerating the need for AI-powered email security.
- Malicious QR code phishing (quishing) incidents surged by 400% between 2023 and 2025, forcing security teams to inspect embedded images.
- Organizations face 8.3 billion phishing threats annually, making zero-trust access a mandatory standard for preventing credential compromise.
- Threat intelligence platforms and identity security systems now block an average of 7,000 automated password and phishing attacks per second.
- Companies combining technical controls with mature employee education report a remarkably low 4.93% average failure rate on phishing simulations.
- The average time to identify and contain a phishing-initiated data breach is 254 days, highlighting the essential need for continuous monitoring.
Anti-Phishing Training Adoption Insights
- 52% of organizations conduct anti-phishing training, showing that only a slight majority actively educate employees about phishing threats.
- The remaining 48% of organizations do not provide anti-phishing training, leaving a significant share of employees potentially unprepared.
- The narrow 4 percentage point gap highlights that anti-phishing awareness programs are still not widely adopted across organizations.
- Expanding employee cybersecurity training could help organizations reduce phishing-related risks, credential theft, and security incidents.

Frequently Asked Questions (FAQs)
APWG recorded 971,181 phishing attacks in Q1 2026, up 13.8% from 853,244 attacks in Q4 2025.
The FBI reported $215.8 million in phishing/spoofing losses in 2025, compared with $70.0 million in 2024.
Credential abuse accounted for 22% of confirmed data breaches in the latest global breach investigations.
Microsoft ranked No. 1, accounting for 22% of all observed brand phishing impersonation attacks in Q1 2026.
Phishing attacks increased by 13.8% quarter over quarter, rising from 853,244 in Q4 2025 to 971,181 in Q1 2026.
Conclusion
Phishing continues to evolve rapidly, with attackers leveraging artificial intelligence, QR codes, mobile messaging, social media, and trusted brands to improve the success of their campaigns. At the same time, record complaint volumes and financial losses show that phishing remains one of the most persistent cybersecurity threats for both individuals and organizations.
The data also highlights a clear path forward. Organizations that combine multi-factor authentication, advanced email protection, continuous threat monitoring, and ongoing employee awareness training consistently reduce phishing risk. As attackers adopt more sophisticated tactics, proactive security strategies and user education will remain the most effective defenses against credential theft, financial fraud, and business disruption.