Key Takeaways
- In 2023, phishing attacks accounted for 36% of all data breaches involving email hacking, with over 300,000 reported incidents worldwide
- Email hacking via phishing succeeded in 22% of attempts in Q4 2022, affecting 1.2 million user accounts globally
- 85% of organizations experienced at least one email-based hacking attempt in 2023, per global survey of 500 IT leaders
- 82% of email hacks used social engineering tactics in 2023 Verizon analysis
- Credential stuffing attacks on email accounts succeeded 18% of the time in 2023 tests
- 65% of email hacks exploited weak or reused passwords in 2023 breaches
- Average cost of email hacking breach was $4.45 million in 2023 globally
- BEC email hacks caused $2.4 billion losses to US victims alone in 2023
- 51% of email hacked organizations faced regulatory fines averaging $5 million in 2023
- SMEs represented 43% of email hack victims but bore 60% of total costs in 2023
- 29% of email hacking targets were individuals aged 25-44 in 2023 consumer reports
- Finance industry accounted for 24% of all email hacks in 2023 Verizon DBIR
- 76% of phishing simulation click rates higher in sales/marketing depts 2023
- Multi-factor authentication blocked 99.9% of email account takeover attempts in 2023
- Email filtering solutions stopped 97% of phishing emails before user interaction 2023
Email hacking remains a widespread and costly global threat with rising attack rates.
Demographics
Demographics Interpretation
Impacts
Impacts Interpretation
Methods
Methods Interpretation
Prevalence
Prevalence Interpretation
Prevention
Prevention Interpretation
Sources & References
- Reference 1VERIZONverizon.comVisit source
- Reference 2APWGapwg.orgVisit source
- Reference 3PROOFPOINTproofpoint.comVisit source
- Reference 4IC3ic3.govVisit source
- Reference 5MIMECASTmimecast.comVisit source
- Reference 6IBMibm.comVisit source
- Reference 7CISCOcisco.comVisit source
- Reference 8SECURELISTsecurelist.comVisit source
- Reference 9ZDNETzdnet.comVisit source
- Reference 10PONEMONponemon.orgVisit source
- Reference 11FIREEYEfireeye.comVisit source
- Reference 12FBIfbi.govVisit source
- Reference 13GARTNERgartner.comVisit source
- Reference 14HHShhs.govVisit source
- Reference 15ENISAenisa.europa.euVisit source
- Reference 16SOPHOSsophos.comVisit source
- Reference 17FINRAfinra.orgVisit source
- Reference 18KASPERSKYkaspersky.comVisit source
- Reference 19HAVEIBEENPWNEDhaveibeenpwned.comVisit source
- Reference 20GROUP-IBgroup-ib.comVisit source
- Reference 21MICROSOFTmicrosoft.comVisit source
- Reference 22CLOUDFLAREcloudflare.comVisit source
- Reference 23CROWDSTRIKEcrowdstrike.comVisit source
- Reference 24FTCftc.govVisit source
- Reference 25VALIMAILvalimail.comVisit source
- Reference 26ZERODAYINITIATIVEzerodayinitiative.comVisit source
- Reference 27IMPERVAimperva.comVisit source
- Reference 28SANSsans.orgVisit source
- Reference 29SECsec.govVisit source
- Reference 30SALESFORCEsalesforce.comVisit source
- Reference 31CHAINALYSISchainalysis.comVisit source
- Reference 32JAVELINSTRATEGYjavelinstrategy.comVisit source
- Reference 33EDELMANedelman.comVisit source
- Reference 34BAKERLAWbakerlaw.comVisit source
- Reference 35MARSHmarsh.comVisit source
- Reference 36BOARDCYBERSECURITYboardcybersecurity.comVisit source
- Reference 37MCKINSEYmckinsey.comVisit source
- Reference 38NISTnist.govVisit source
- Reference 39FSISACfsisac.comVisit source
- Reference 40CISAcisa.govVisit source
- Reference 41KNOWBE4knowbe4.comVisit source
- Reference 42URBAN-INSTITUTEurban-institute.orgVisit source
- Reference 43CISCOciscoVisit source
- Reference 44EDUCASEeducase.eduVisit source
- Reference 45SBAsba.govVisit source
- Reference 46CYBERcyber.gov.auVisit source
- Reference 47AARPaarp.orgVisit source
- Reference 48ISACAisaca.orgVisit source
- Reference 49LASTPASSlastpass.comVisit source
- Reference 50EXABEAMexabeam.comVisit source
- Reference 51QUALYSqualys.comVisit source
- Reference 52ZSCALERzscaler.comVisit source
- Reference 53RECORDEDFUTURErecordedfuture.comVisit source
- Reference 54OKTAokta.comVisit source
- Reference 55BARRACUDAbarracuda.comVisit source
- Reference 56IDCidc.comVisit source






