Key Takeaways
- In Q4 2023, the Anti-Phishing Working Group (APWG) detected 5,020,947 phishing attacks worldwide, marking a 47% increase from Q3
- Verizon's 2024 Data Breach Investigations Report (DBIR) found that 36% of all data breaches involved phishing as the initial access vector
- Proofpoint's 2024 State of the Phish report indicated that 84% of organizations experienced at least one successful phishing attack in the past year
- The average global cost of a phishing attack in 2023 reached $4.91 million according to IBM's Cost of a Data Breach Report 2024
- FBI IC3 2023 reported total phishing losses exceeding $18.7 million from 298,878 complaints
- Verizon DBIR 2024 estimated phishing-related breaches cost an average of $4.45 million per incident
- 84% of millennials have experienced phishing attempts, per Proofpoint 2024 State of the Phish
- KnowBe4 2024 report found finance sector employees 25% more phished than average
- Verizon DBIR 2024 showed 22% of phishing victims were executives (whaling)
- Email spear-phishing involved in 65% of attacks per Verizon DBIR 2024
- APWG Q4 2023: 38% of phishing used brand impersonation of Microsoft
- Proofpoint 2024: 96% of phishing uses email as primary vector
- Only 19% of phishing emails detected by traditional filters per Proofpoint 2024
- KnowBe4 2024: Phishing simulation training reduced clicks by 55%
- Verizon DBIR 2024: MFA blocked 99.9% of account compromise post-phish
Phishing attacks are soaring in frequency, cost, and their success against people and companies worldwide.
Attack Vectors
Attack Vectors Interpretation
Defensive Measures
Defensive Measures Interpretation
Financial Losses
Financial Losses Interpretation
Incidence Rates
Incidence Rates Interpretation
Victim Profiles
Victim Profiles Interpretation
Sources & References
- Reference 1DOCSdocs.apwg.orgVisit source
- Reference 2VERIZONverizon.comVisit source
- Reference 3PROOFPOINTproofpoint.comVisit source
- Reference 4IC3ic3.govVisit source
- Reference 5KNOWBE4knowbe4.comVisit source
- Reference 6IBMibm.comVisit source
- Reference 7STATISTAstatista.comVisit source
- Reference 8TRANSPARENCYREPORTtransparencyreport.google.comVisit source
- Reference 9AKAaka.msVisit source
- Reference 10ENISAenisa.europa.euVisit source
- Reference 11PHISHLABSphishlabs.comVisit source
- Reference 12FTCftc.govVisit source
- Reference 13BLOGblog.cloudflare.comVisit source
- Reference 14BARRACUDAbarracuda.comVisit source
- Reference 15ZSCALERzscaler.comVisit source
- Reference 16CISCOcisco.comVisit source
- Reference 17SECURELISTsecurelist.comVisit source
- Reference 18DOCSdocs.broadcom.comVisit source
- Reference 19AKAMAIakamai.comVisit source
- Reference 20SOPHOSsophos.comVisit source
- Reference 21MIMECASTmimecast.comVisit source
- Reference 22ABNORMALSECURITYabnormalsecurity.comVisit source
- Reference 23HORNETSECURITYhornetsecurity.comVisit source
- Reference 24KEEPNETLABSkeepnetlabs.comVisit source
- Reference 25SLASHNEXTslashnext.comVisit source





