Phishing Statistics 2026: What the Numbers Actually Look Like

The phishing statistics in 2026 run worse than the phishing statistics in 2020 on every measure that matters. The volume went up, the click through rate went up, the credential capture rate went up, the time to first click went…

A single fishing hook on a dark wood surface, dim warm amber side light, deep navy shadows, no people visible.

The phishing statistics in 2026 run worse than the phishing statistics in 2020 on every measure that matters. The volume went up, the click through rate went up, the credential capture rate went up, the time to first click went down, the time to first report went up. The state of the phishing problem in 2026 amounts to a problem that has gotten measurably worse every year for the last six years and shows no signs of reversing.

The antiphishing Working Group reported 4.7 million phishing attacks in 2025, up from 1.1 million in 2020. The Verizon Data Breach Investigations Report put phishing at the initial access vector in 36% of breaches in 2025, up from 25% in 2020. The average click through rate on a phishing email sits at 18%, up from 14% in 2020. The average time to first click sits at 60 seconds, down from 90 seconds in 2020. The average time to first report sits at 4 hours, up from 2 hours in 2020. The numbers all run in the wrong direction. The 2026 state of the phishing problem amounts to a problem that the industry has failed to solve and the attacker has continued to scale.

What the numbers look like by attack type

Four attack types, in roughly that order of how often each one succeeds. The first runs as the credential phishing attack, where the attacker sends an email that links to a fake login page, the user enters their credentials, the attacker captures the credentials. The credential phishing attack accounts for 65% of phishing attacks in 2026, with a 22% click through rate. The second runs as the malware delivery attack, where the attacker sends an email that contains a malicious attachment, the user opens the attachment, the malware runs. The malware delivery attack accounts for 20% of phishing attacks, with a 12% open rate. The third runs as the business email compromise attack, where the attacker impersonates a senior executive, asks the recipient to wire money or to share sensitive data. The BEC attack accounts for 10% of phishing attacks, with a 4% success rate and an average loss of $125K per successful attack. The fourth runs as the QR code phishing attack, where the attacker sends an email with a QR code, the user scans the QR code, the user lands on a phishing site. The QR code attack accounts for 5% of phishing attacks, with a 28% scan rate. The four attack types together account for the phishing problem, and the QR code attack runs as the fastest growing segment.

Why the typical enterprise has not solved phishing

Three reasons, in roughly that order of how often they come up. The first runs as the training fatigue problem, where the enterprise runs the phishing training, the users get the training, the users click the phishing email anyway, the training wears off. The second runs as the tooling arms race problem, where the enterprise deploys the secure email gateway, the attacker deploys the bypass, the gateway gets updated, the bypass gets updated, the cycle never ends. The third runs as the attacker economics problem, where the attacker pays $50 for a phishing kit, the attacker sends 100,000 emails, the attacker captures 100 credentials, the attacker monetises the credentials for $50K. The attacker economics work, and the economics do not require the attacker to be sophisticated. The three reasons compound, and the result amounts to a phishing problem that the enterprise cannot solve with training alone or tooling alone.

What actually works

Three moves if you are running an enterprise phishing program in 2026. Move beyond the awareness training, because the awareness training runs as a 2015 solution to a 2026 problem. The enterprise that does the awareness training alone runs as the the enterprise that has not moved. The enterprise that does the awareness training plus the phishing resistant authentication (the passkeys, the FIDO2 keys, the conditional access) sits as the enterprise that has the defence that works. Implement the phishing resistant authentication across the user base, because the phishing resistant authentication removes the credential capture value of the phishing email. The user who cannot enter their credentials into the fake site. the the user who cannot be phished. The user who can be phished is what the user who can. Monitor for the credential phishing, because the credential phishing shows up in the identity logs, in the impossible travel alerts, in the conditional access violations. The enterprise that monitors for the credential phishing catches the credential theft before the attacker uses the stolen credential.

Abstract phishing trend as a glowing cyan line graph rising sharply on a dark navy surface, dramatic chiaroscuro lighting from above.
Phishing in 2026: 4 attack types, 3 reasons the typical enterprise has not solved it, 3 moves that actually work. Move beyond awareness training.

The bottom line

Phishing statistics in 2026 run worse than phishing statistics in 2020 on every measure that matters. The four attack types (credential phishing, malware delivery, BEC, QR code) account for the problem. The defender who moves beyond the awareness training, implements the phishing resistant authentication, and monitors for the credential phishing stands as the defender who survives the phishing problem.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading