Phishing Statistics and Trends for 2026
Phishing attack volume barely moved this year. That is not good news. Losses per attack climbed, business email compromise crossed $3 billion, and AI handed average criminals the writing skill they never had. The click rate only improved at companies that train their people.
In 2026, phishing is still the most reported cybercrime. The FBI logged 191,561 phishing complaints, Verizon ties roughly 60% of breaches to a human element, and AI-written phishing now outperforms human attackers.
Here is the uncomfortable part. Most companies read a phishing statistic, feel a jolt, and change nothing. Phishing is not a technology problem you can filter your way out of. It is a people problem, which is why security awareness training moves the outcome more than any tool you can buy.
Then a wire goes out to an account nobody verified, and someone finds out the number was about them. So look at the 2026 phishing statistics with a decision in mind, not a shrug. According to the FBI's Internet Crime Complaint Center, Americans filed 191,561 phishing complaints in 2025, more than any other category of online crime. This post pulls the numbers that matter for a 2026 defense, sourced to the primary reports, and tells you what each one should change about how you operate.
Phishing Statistics 2026 at a Glance
Phishing remained the top reported cybercrime in 2026. The FBI counted 191,561 phishing complaints, the APWG tracked 853,244 attacks in a single quarter, and Microsoft blocked roughly 8.3 billion email threats in Q1 alone.
Here are the headline numbers, each tied to the report it came from. Bookmark this section. It is the part people quote.
- 191,561 phishing complaints in the US in 2025, the most-reported cybercrime of the year, per the FBI IC3.
- 853,244 phishing attacks in a single quarter, tracked by the APWG in Q4 2025.
- About 295,691 unique phishing sites in December 2025 alone, also from the APWG.
- Roughly 8.3 billion email phishing threats blocked in one quarter, per Microsoft in Q1 2026.
- About 60% of breaches involve a human element, according to the Verizon DBIR.
- A median of about 21 seconds for an employee to click a phishing link, per Microsoft.
- Around 33% of untrained employees take the bait, based on KnowBe4 benchmarks.

Notice what is missing from that list. A giant year-over-year jump in attack volume. It is not there. The APWG's fourth-quarter data actually shows attacks dipping about 4% from the prior quarter. Attackers didn't stop. They got better at fewer, sharper attempts. That is the trend under the trend.
How Much Is Phishing Costing Businesses?
Phishing losses are climbing far faster than phishing volume. The FBI reported that phishing complaints stayed flat year over year while reported dollar losses jumped 208%, and business email compromise alone drove more than $3 billion in losses.
Flat volume. Triple the damage. Read that twice.
The FBI's 2025 report put total losses from internet crime at $20.9 billion across more than a million complaints, the first time the count crossed seven figures. Business email compromise, the polite name for tricking someone into wiring money to a criminal, accounted for roughly $3.05 billion of that. Average loss per BEC complaint ran north of $122,000. For a 60-person manufacturer, that is not an IT line item. That is payroll for a quarter.
Why does the money move so cleanly? Because BEC doesn't break anything. No malware, no alarm, no locked screen. An email asks accounting to update a vendor's bank details, accounting complies, and the fraud looks exactly like normal Tuesday work. About 86% of BEC funds leave by wire or ACH, which means the attack lands inside the financial workflow you already trust. That is the whole problem. It hides in the routine.
Phishing Is Still the Front Door to Breaches
Phishing remains one of the top ways attackers get in. Verizon's 2025 Data Breach Investigations Report attributes about 60% of breaches to a human element, whether that is a click, a reused password, or a misdirected payment.
Filters catch a lot. They don't catch a person.
Verizon analyzed more than 12,000 confirmed breaches for its 2025 report, the largest set it has ever run. Stolen credentials showed up as the most common way in, used in 22% of breaches. Phishing sits right alongside it, because phishing is how most of those credentials get stolen in the first place. One feeds the other.
The operator takeaway is blunt. You can buy the best email gateway on the market and still lose to a login page that looks close enough to your Microsoft 365 sign-in. The attacker doesn't need to beat your firewall. They need one distracted person late on a Friday afternoon. And with a median time-to-click of about 21 seconds, they usually get an answer before anyone thinks to ask a second question. This is why how social engineering actually works on employees matters more than any single product decision.
AI Rewrote the Phishing Playbook
AI is the biggest phishing trend of 2026. Generative tools now write cleaner, more convincing lures than most human attackers could, and security researchers report AI-written phishing landing at markedly higher click rates than traditional attempts.
Remember the old tell? Broken grammar, weird spacing, a greeting that used your email prefix instead of your name. Gone. AI erased the typos that used to save people.
Hoxhunt's 2026 trends research found AI-generated phishing outperforming human-written phishing in head-to-head tests, a reversal from just two years ago when the machine-written stuff was easy to spot. And the economics are the scary part. AI drops the cost of writing and translating a convincing lure close to zero. When a campaign costs almost nothing to run, the 60-person company that used to be too small to bother with becomes worth the attacker's time.
Three shifts are worth watching this year.
- Deepfake voice. A cloned voice on the phone asking for an urgent transfer, and the finance team hears the CEO, not a script.
- QR codes in emails and PDFs that jump the attack from a monitored laptop to an unmonitored phone. Microsoft logged QR phishing climbing 146% in a single quarter.
- Text messages. Smishing keeps growing 30 to 40% quarter over quarter, per APWG, because a phone screen hides the sketchy link better than a desktop does.
None of these are science fiction. They are line items in this year's incident reports. The tools got cheaper and the targets got wider. That is the actual headline of 2026, and no email filter closes it.
Which Channels Are Attackers Using Now?
Email is still the main phishing channel, but text and voice are the fastest-growing ones. The APWG reports smishing volumes rising 30 to 40% each quarter, while Microsoft tracked QR-code phishing jumping 146% in Q1 2026.
Phishing stopped being an inbox-only problem. Here is where the pressure is landing.
- Email is still the volume leader, with roughly 8.3 billion threats blocked in a single quarter, mostly fake login pages, invoice fraud, and BEC (Microsoft).
- Smishing, or SMS phishing, shows up as fake toll fees, delivery notices, and MFA prompts, and it is growing 30 to 40% per quarter (APWG).
- Vishing, or voice phishing, uses cloned-voice calls demanding urgent action, and it is the fastest-rising vector right now.
- Quishing, or QR-code phishing, moves the victim onto a personal phone, and it jumped 146% in Q1 2026 (Microsoft).

The pattern connecting all four? Attackers keep moving the fight to the device you monitor least. Your email gateway doesn't see the text message. Your SIEM doesn't hear the phone call. Your endpoint agent doesn't ride along when someone scans a QR code with their personal phone. Every one of these channels routes around the tool you spent money on and lands on a human instead. Which is the whole reason the human is where the defense has to be.
How Exposed Is a Small or Mid-Sized Business?
Small and mid-sized businesses are now prime phishing targets, not afterthoughts. Guardz reported SMB cyberattacks nearly doubling in 2025, driven largely by AI that made small companies cheap enough to attack at scale.
There is an old assumption worth killing. That criminals only chase the Fortune 500. It was never fully true, and AI finished it off.
When writing a convincing lure cost real time and skill, attackers picked big payouts. Now that a model writes a flawless campaign in seconds, the calculus flips. A 50-employee food processor in the Inland Empire is suddenly worth targeting, because the cost of trying is close to zero and the defenses are usually thinner than an enterprise's. Guardz found attacks on small businesses nearly doubled in 2025. That is not a rounding error. That is a category shift.
Manufacturing feels this in a specific way. Verizon's data consistently ranks manufacturing among the most-hit sectors, and the reason is operational, not technical. A plant that stops is a plant bleeding money by the hour, so the pressure to pay or to comply with an urgent request is higher than in most offices. Attackers know that. They engineer urgency because urgency is where verification dies. For a closer look at protecting a production floor, this is where cybersecurity built for manufacturers earns its keep.
Which Industries Get Phished the Most?
Hospitality and education are the most phishing-prone industries in 2026, with baseline click rates above 50%, while finance and technology run the lowest at roughly 4 to 9%. The gap comes down to training and regulatory pressure, not luck.
Same phishing email, wildly different outcomes depending on who receives it. KnowBe4's benchmarking puts the untrained baseline around 33% of employees clicking, but that average hides a huge spread.
- Hospitality and education click the most, above 50%, driven by high turnover, constant external email, and thin training budgets.
- Healthcare, insurance, and retail sit elevated, roughly 35 to 43%, with large mixed workforces of clinical and administrative staff.
- Manufacturing and professional services land in the middle, improving where training exists and exposed where it does not.
- Finance and technology click the least, about 4 to 9%, thanks to heavy regulation and funded security teams that run frequent simulations.
Look at what separates the top from the bottom of that list. It isn't the industry. It's the training. Finance doesn't click less because bankers are smarter. They click less because regulators and funded programs force regular practice on them. The industries at the top of the click-rate charts are the ones where nobody made training a habit. That is a fixable position, no matter your vertical.
Does Security Awareness Training Actually Work?
Yes, and the data is unusually clear. KnowBe4 found that ongoing training drops the share of employees who fall for phishing from about 33% to roughly 4% over 12 months, an 86% reduction in click rates.
Most security spending buys probability, not proof. This is one of the few line items where the before-and-after is measurable.
KnowBe4's 2026 benchmarking tracked organizations through a year of simulated phishing and training. The baseline phish-prone rate started near 33%. After 90 days it dropped meaningfully. After 12 months of consistent practice it landed around 4.1%, and the company's separate reporting pegged the overall reduction at about 86%.
- Before any training, about 1 in 3 employees takes the bait.
- After 90 days of simulations, that share drops meaningfully.
- After 12 months of ongoing practice, it falls to roughly 1 in 24.

One caveat, and it is the one that trips people up. The word doing the work above is ongoing. A single annual training video does close to nothing. The reductions come from monthly simulations paired with immediate feedback the moment someone clicks, because that is when the lesson sticks. Set-it-and-forget-it training is theater. The programs that move the number are the ones that keep showing up. If you want the budgeting side of this, we broke down what training actually costs in a separate piece.
What the 2026 Numbers Should Change About Your Defense
Three takeaways, and then a next step.
First, stop reading flat attack volume as calm. Losses per attack are up sharply while the count holds steady, which means each attempt is more targeted and more expensive when it lands. Second, AI is the multiplier this year, not a future worry. It made cheap attacks convincing and small companies worth targeting. Third, training is the one lever with a proven, measurable payoff, dropping click rates by roughly 86% when it runs continuously.
Bias disclosed, because it is only fair. We sell managed security, so of course we think this matters. But the math isn't ours. It's the FBI's, Verizon's, and KnowBe4's, and it points the same direction from three independent angles. If you are a California business sizing up your exposure, start by measuring your own baseline click rate, then decide whether ongoing managed cybersecurity is worth it against a $122,000 average BEC loss. When you want a second set of eyes on that math, talk to our team.