Phishing Statistics 2026: What the Numbers Actually Look Like

The phishing statistics in 2026 run worse than the phishing statistics in 2020 on every measure that matters. The volume went up, the click through rate went up, the credential capture rate went up, the time to first click went…

Dark cinematic editorial image for Phishing Statistics 2026: What the Numbers Actually Look Like - abstract cyan digital composition, hacker aesthetic, no text no logos

5 MIN READ

The phishing numbers have been running in the wrong direction for six straight years, and the awareness training that was supposed to fix them has not fixed them. APWG reported 4.7 million phishing attacks in 2025, up from 1.1 million in 2020. The economics on the attacker side work, and they work for a $50 kit.

The Verizon Data Breach Investigations Report put phishing at the initial access vector in roughly 1 in 3 breach cases in 2025, up from 1 in 4 in 2020. The average click through rate on a phishing email sat at 18 percent in 2026, up from 14 percent in 2020. The average time to first click has dropped to 60 seconds. The industry has been spending on awareness training and secure email gateways. The numbers have not moved, because the attacker side of the equation is moving faster than the defender side.

What the attacks actually look like in 2026

Credential phishing remains the dominant shape at roughly 2 in 3 of total volume, and the typical lure is a fake Microsoft 365 or Okta login page served from a lookalike domain. Roughly 22 percent click the lure. Malware delivery at around 1 in 5 of volume has shifted hardest to HTML smuggling and OneNote attachments, since the secure email gateways have learned to flag the old Excel macro pattern. The open rate on the malware campaigns sits at about 12 percent. Business email compromise at 1 in 10 of total volume carries the lowest click rate (around 4 percent), but the average loss per successful attack sat at $125K per the FBI IC3 2025 report, which makes the segment disproportionately expensive. QR code phishing at 1 in 20 of total volume runs as the fastest growing slice, with a 28 percent scan rate that surprises everyone the first time they see the number. The phishing crews have been layering new shapes on top of the same economics, and each new shape takes the defender side a year to catch up to.

Why the typical company has not solved it

Three patterns, and they compound. Training fatigue sits at the top. The same awareness training has been running in most companies for ten years. The user who has seen the simulated phishing email 30 times has stopped reading the banner, and the banner that lives in the email footer has been tuned out entirely. The training wears off faster than the curriculum gets updated. Tooling arms race follows. The secure email gateway catches known bad senders at a 99 percent rate. The phisher registers a new domain, the gateway does not have a reputation for the new domain, and the email lands. The gateway gets updated, the bypass gets updated, and the cycle has been running since the first Proofpoint and Mimecast deployments. Attacker economics closes the list. The phisher pays $50 for a phishing kit from a Telegram channel, sends 100,000 emails, captures 100 credentials, monetises the credentials at $50 each on an initial access marketplace, and walks away with a 100x return. The MFA bypass kits (Muraena, Evilginx, EvilnoVNC) have been raising the floor on the credential capture side, since the kit captures the session token as well as the credential and the session token works regardless of the MFA setting on the account. The company that tries to solve phishing with training alone, or tooling alone, has been losing this fight for years.

What actually works in 2026

Phishing resistant authentication has changed the math. FIDO2 security keys (YubiKey, Feitian), passkeys in the Apple, Google, and Microsoft identity layers, and Windows Hello on managed Windows fleets all share one property: the credential never leaves the device, the fake login page never receives anything it can replay, and the phisher who tricked the user tricked nothing usable. Microsoft, Google, and Okta have been rolling out phishing resistant auth as the default for new tenants since 2025. Conditional access runs as the next layer. Azure AD Conditional Access, Okta Identity Engine, and the Google Workspace equivalent block the impossible travel sign in, force MFA on the new device, and revoke the active session when the risk score crosses the threshold. The credential that was phished on Monday cannot be used from a residential proxy in Lagos on Tuesday. Identity monitoring closes the trio. Microsoft Defender for Identity, CrowdStrike Falcon Identity Threat Detection, and the Splunk User Behavior Analytics equivalent watch for the post compromise signals (the impossible travel, the inbox rule changes, the OAuth grant abuse) and surface the attack in time to contain it. The company with the phishing resistant auth, the conditional access, and the identity monitoring in place ends up with a phishing email that still arrives and still gets clicked, while the breach still does not happen.

Stack of envelopes fanned out on a steel office desk, half opened, the topmost letter folded into a recognizable fake login page, a single red phishing report button on the desk lamp
Phishing in 2026: 4 attack types, 3 reasons companies have not solved it, 3 things that actually work.

The bottom line

Phishing resistant authentication, conditional access, identity monitoring. The user who can be tricked without a credential to give is the user who cannot be breached, and the company that ships all three in 2026 is the one that has finally broken the six year trend.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading