Key Takeaways
- In 2023, phishing attacks accounted for 36% of all data breaches according to the Verizon Data Breach Investigations Report
- Globally, there were over 300,000 unique phishing sites detected in Q4 2022 by APWG
- Phishing emails comprised 54% of all malicious emails in 2023 per Proofpoint's State of the Phish report
- Email was the top phishing vector at 78% in 2023 Verizon DBIR
- 57% of phishing used malicious links in 2023 per Proofpoint
- Attachments in phishing emails rose to 14% with macros in 2023 KnowBe4
- Phishing losses totaled $12.5 billion globally in 2023 per FBI and IC3 aggregate
- Average BEC phishing wire transfer $120,000 in 2023 FBI
- Phishing caused $4.2 billion in ransomware payouts indirectly 2023 Sophos
- 84% of CISOs reported phishing as top risk in 2023 Gartner survey
- Millennials clicked 30% more phishing links than Boomers 2023 Proofpoint
- Finance sector targeted in 32% phishing attacks 2023 Verizon DBIR
- 95% of phishing preventable with training per 2023 NIST
- MFA blocked 99.9% phishing credential theft 2023 Microsoft
- AI email filters caught 97% phishing 2023 Google Workspace
Phishing is a widespread and costly threat that successfully breaches organizations daily.
Attack Vectors and Techniques
Attack Vectors and Techniques Interpretation
Financial and Operational Impact
Financial and Operational Impact Interpretation
Mitigation and Detection
Mitigation and Detection Interpretation
Prevalence and Trends
Prevalence and Trends Interpretation
Victim Demographics
Victim Demographics Interpretation
Sources & References
- Reference 1VERIZONverizon.comVisit source
- Reference 2DOCSdocs.apwg.orgVisit source
- Reference 3PROOFPOINTproofpoint.comVisit source
- Reference 4IC3ic3.govVisit source
- Reference 5BLOGblog.googleVisit source
- Reference 6GETSAFEONLINEgetsafeonline.orgVisit source
- Reference 7BLOGblog.talosintelligence.comVisit source
- Reference 8SECURELISTsecurelist.comVisit source
- Reference 9PONEMONponemon.orgVisit source
- Reference 10ENISAenisa.europa.euVisit source
- Reference 11MIMECASTmimecast.comVisit source
- Reference 12ZSCALERzscaler.comVisit source
- Reference 13IBMibm.comVisit source
- Reference 14MICROSOFTmicrosoft.comVisit source
- Reference 15UNIT42unit42.paloaltonetworks.comVisit source
- Reference 16KNOWBE4knowbe4.comVisit source
- Reference 17RESEARCHresearch.checkpoint.comVisit source
- Reference 18BARRACUDAbarracuda.comVisit source
- Reference 19ABNORMALSECURITYabnormalsecurity.comVisit source
- Reference 20US-CERTus-cert.govVisit source
- Reference 21F5f5.comVisit source
- Reference 22PHISHLABSphishlabs.comVisit source
- Reference 23GROUP-IBgroup-ib.comVisit source
- Reference 24SOPHOSsophos.comVisit source
- Reference 25VADESECUREvadesecure.comVisit source
- Reference 26ICANNicann.orgVisit source
- Reference 27DARKTRACEdarktrace.comVisit source
- Reference 28TWILIOtwilio.comVisit source
- Reference 29AKAMAIakamai.comVisit source
- Reference 30NILSONREPORTnilsonreport.comVisit source
- Reference 31JAVELINSTRATEGYjavelinstrategy.comVisit source
- Reference 32CYENCEcyence.comVisit source
- Reference 33GARTNERgartner.comVisit source
- Reference 34FFIECffiec.govVisit source
- Reference 35BAKERLAWbakerlaw.comVisit source
- Reference 36FTCftc.govVisit source
- Reference 37DELOITTEwww2.deloitte.comVisit source
- Reference 38PAPERSpapers.ssrn.comVisit source
- Reference 39WORLDBANKworldbank.orgVisit source
- Reference 40COMPLIANCEWEEKcomplianceweek.comVisit source
- Reference 41PSYCHOLOGYTODAYpsychologytoday.comVisit source
- Reference 42HIMSShimss.orgVisit source
- Reference 43SANSsans.orgVisit source
- Reference 44NRFnrf.comVisit source
- Reference 45AMERICANBARamericanbar.orgVisit source
- Reference 46UPGUARDupguard.comVisit source
- Reference 47SHRMshrm.orgVisit source
- Reference 48EDUCAUSEeducause.eduVisit source
- Reference 49DRAGOSdragos.comVisit source
- Reference 50ABAaba.comVisit source
- Reference 51NVLPUBSnvlpubs.nist.govVisit source
- Reference 52WORKSPACEworkspace.google.comVisit source
- Reference 53BLOGblog.virustotal.comVisit source
- Reference 54FORRESTERforrester.comVisit source
- Reference 55SPLUNKsplunk.comVisit source
- Reference 56BLOGblog.avast.comVisit source
- Reference 57DUOduo.comVisit source
- Reference 58GLASSWALLglasswall.comVisit source
- Reference 59MANDIANTmandiant.comVisit source
- Reference 60VEEAMveeam.comVisit source
- Reference 61BLOGblog.cloudflare.comVisit source
- Reference 62IMMERSIVELABSimmersivelabs.comVisit source
- Reference 63G2g2.comVisit source






