Key Takeaways
- In 2023, phishing attacks accounted for 36% of all data breaches analyzed in the Verizon Data Breach Investigations Report, with over 16,000 incidents reviewed globally.
- The Anti-Phishing Working Group reported 1,077,501 unique phishing sites detected in Q4 2023, a 47% increase from Q4 2022.
- Proofpoint's 2024 State of the Phish report found that 84% of organizations experienced at least one successful phishing attack in the past year.
- The average global cost of a data breach involving phishing was $4.88 million in 2023 per IBM's Cost of a Data Breach Report.
- FBI IC3 2023: BEC phishing scams caused $2.9 billion in losses from 21,000+ complaints.
- Proofpoint 2024: Successful phishing cost organizations $14.8 million on average annually.
- 25-44 year olds were the most targeted demographic in phishing attacks, comprising 42% of victims per FTC 2023 data.
- Proofpoint 2024: Finance employees clicked 1.5x more phishing links than average.
- KnowBe4 2023: Healthcare sector had highest phish-prone percentage at 37.5%.
- 91% of phishing attacks used malicious links, per Proofpoint 2024 analysis of 10 billion emails.
- Spear-phishing made up 65% of targeted attacks, Verizon DBIR 2023.
- Business Email Compromise (BEC) used domain spoofing in 98% cases, FBI IC3 2023.
- 84% of organizations with phishing training reduced click rates by 50%, KnowBe4 2023 benchmarks.
- Multi-factor authentication (MFA) blocked 99.9% of account compromise post-phishing, Microsoft 2023.
- AI-based email filters detected 97% of phishing, Proofpoint 2024.
Phishing attacks have become a massive and costly problem for everyone worldwide.
Attack Methods and Techniques
Attack Methods and Techniques Interpretation
Financial Impact
Financial Impact Interpretation
Prevalence and Incidence
Prevalence and Incidence Interpretation
Prevention and Detection
Prevention and Detection Interpretation
Victim Demographics
Victim Demographics Interpretation
Sources & References
- Reference 1VERIZONverizon.comVisit source
- Reference 2DOCSdocs.apwg.orgVisit source
- Reference 3PROOFPOINTproofpoint.comVisit source
- Reference 4BLOGblog.googleVisit source
- Reference 5AKAaka.msVisit source
- Reference 6IC3ic3.govVisit source
- Reference 7KNOWBE4knowbe4.comVisit source
- Reference 8IBMibm.comVisit source
- Reference 9EGRESSegress.comVisit source
- Reference 10COFENSEcofense.comVisit source
- Reference 11ABNORMALSECURITYabnormalsecurity.comVisit source
- Reference 12ZSCALERzscaler.comVisit source
- Reference 13KEEPERSECURITYkeepersecurity.comVisit source
- Reference 14SLASHNEXTslashnext.comVisit source
- Reference 15BARRACUDAbarracuda.comVisit source
- Reference 16FORTINETfortinet.comVisit source
- Reference 17MIMECASTmimecast.comVisit source
- Reference 18CISCOcisco.comVisit source
- Reference 19RESEARCHresearch.checkpoint.comVisit source
- Reference 20RAPID7rapid7.comVisit source
- Reference 21SOPHOSsophos.comVisit source
- Reference 22TRENDMICROtrendmicro.comVisit source
- Reference 23SECURELISTsecurelist.comVisit source
- Reference 24MCAFEEmcafee.comVisit source
- Reference 25SYMANTEC-ENTERPRISE-BLOGSsymantec-enterprise-blogs.security.comVisit source
- Reference 26DARKTRACEdarktrace.comVisit source
- Reference 27FORCEPOINTforcepoint.comVisit source
- Reference 28UNIT42unit42.paloaltonetworks.comVisit source
- Reference 29CROWDSTRIKEcrowdstrike.comVisit source
- Reference 30REPORTFRAUDreportfraud.ftc.govVisit source
- Reference 31APWGapwg.orgVisit source
- Reference 32ERICOMericom.comVisit source
- Reference 33MANDIANTmandiant.comVisit source
- Reference 34CYBERARKcyberark.comVisit source
- Reference 35TERRANOVASECURITYterranovasecurity.comVisit source
- Reference 36SANSsans.orgVisit source
- Reference 37SPLUNKsplunk.comVisit source






