Key Takeaways
- In 2023, phishing attacks accounted for 36% of all data breaches reported globally according to the Verizon Data Breach Investigations Report
- The Anti-Phishing Working Group (APWG) reported over 5.3 million unique phishing sites detected in Q4 2023 alone, marking a 47% increase from the previous quarter
- Proofpoint's 2023 State of the Phish report indicated that 84% of organizations experienced at least one successful phishing attack
- Phishing caused $52.1 million in losses from business email compromise in 2023 per FBI IC3
- IBM 2023 Cost of Data Breach averaged $4.45 million per breach with phishing vector at $4.76 million
- Proofpoint 2023 report estimated global phishing losses exceeding $50 billion annually
- Mimecast 2023 reported BEC phishing losses at $2.4 billion in US alone for 2023, category: Financial Impact
- 55% of phishing victims are aged 30-49 per Proofpoint 2023 demographics study
- FBI IC3 2023 showed 42% of phishing complainants over age 60
- KnowBe4 2023 benchmarked finance employees 25% more likely to fall for phishing
- 82% of phishing uses email as primary vector per Proofpoint 2023
- APWG 2023 Q4 showed 28% phishing via SMS (smishing) rise
- Verizon DBIR 2023 spear-phishing 65% of social engineering attacks
- Proofpoint 2023 noted 300% rise in AI-generated phishing content
- APWG 2023 reported phishing-as-a-service kits doubled to 50+ on dark web
Phishing is a widespread threat causing immense and costly security breaches worldwide.
Attack Vectors
Attack Vectors Interpretation
Financial Impact
Financial Impact Interpretation
Financial Impact, source url: https://www.mimecast.com/content/state-of-email-security/
Financial Impact, source url: https://www.mimecast.com/content/state-of-email-security/ Interpretation
Prevalence and Frequency
Prevalence and Frequency Interpretation
Trends and Evolution
Trends and Evolution Interpretation
Victim Demographics
Victim Demographics Interpretation
Sources & References
- Reference 1VERIZONverizon.comVisit source
- Reference 2DOCSdocs.apwg.orgVisit source
- Reference 3PROOFPOINTproofpoint.comVisit source
- Reference 4IBMibm.comVisit source
- Reference 5IC3ic3.govVisit source
- Reference 6KNOWBE4knowbe4.comVisit source
- Reference 7AKAaka.msVisit source
- Reference 8TRANSPARENCYREPORTtransparencyreport.google.comVisit source
- Reference 9PHISHLABSphishlabs.comVisit source
- Reference 10BARRACUDAbarracuda.comVisit source
- Reference 11SECURELISTsecurelist.comVisit source
- Reference 12ZSCALERzscaler.comVisit source
- Reference 13COFENSEcofense.comVisit source
- Reference 14SOPHOSsophos.comVisit source
- Reference 15MIMECASTmimecast.comVisit source
- Reference 16ABNORMALSECURITYabnormalsecurity.comVisit source
- Reference 17AVANANavanan.comVisit source
- Reference 18IRONSCALESironscales.comVisit source
- Reference 19KEEPNETLABSkeepnetlabs.comVisit source
- Reference 20SLASHNEXTslashnext.comVisit source
- Reference 21BRANDEFENSEbrandefense.ioVisit source
- Reference 22NETCRAFTnetcraft.comVisit source
- Reference 23LOOKOUTlookout.comVisit source
- Reference 24TRENDMICROtrendmicro.comVisit source
- Reference 25MCAFEEmcafee.comVisit source
- Reference 26SYMANTEC-ENTERPRISE-BLOGSsymantec-enterprise-blogs.security.comVisit source
- Reference 27CROWDSTRIKEcrowdstrike.comVisit source
- Reference 28MANDIANTmandiant.comVisit source
- Reference 29UNIT42unit42.paloaltonetworks.comVisit source
- Reference 30APWGapwg.orgVisit source
- Reference 31PWCpwc.comVisit source
- Reference 32DELOITTEwww2.deloitte.comVisit source
- Reference 33GARTNERgartner.comVisit source






