Key Takeaways
- In the second half of 2023, the Anti-Phishing Working Group (APWG) detected over 2.7 million phishing attacks worldwide, marking a 48% increase from the first half
- Verizon's 2024 Data Breach Investigations Report (DBIR) found that phishing was involved in 24% of all data breaches analyzed across 30,458 incidents
- Proofpoint's 2024 State of the Phish report revealed that 84% of organizations experienced at least one successful phishing attack in the past year, based on survey of 7,500+ organizations
- In 2023, phishing scams caused $12.5 billion in global losses according to the FBI IC3, with over 300,000 complaints filed
- IBM's 2024 Cost of Data Breach Report states average cost of phishing-initiated breach is $4.88 million, 10% higher than other vectors
- Proofpoint 2024 reports average financial loss per successful phishing attack at $4.9 million for enterprises
- In 2023, 36% of phishing victims were aged 30-39 according to Proofpoint survey of 7,500 orgs
- Verizon DBIR 2024 shows 25% of victims in finance sector, highest targeted industry
- FBI IC3 2023 reports 55% of phishing complainants were male, average age 41
- Email phishing accounted for 91% of attacks per Verizon DBIR 2024
- Proofpoint 2024 reports SMS phishing (smishing) up 328% in 2023
- APWG Q1 2024: 35% of phishing used HTTPS for legitimacy
- Proofpoint training reduced phish-prone users by 90% within 90 days per 2024 report
- KnowBe4 2024 benchmarking shows top 10% orgs have 5% phish-prone rate via training
- Verizon DBIR 2024: MFA blocked 99.9% of account compromise attempts when enabled
Phishing attacks surged dramatically in 2023, causing billions in global losses annually.
Attack Vectors
Attack Vectors Interpretation
Financial Impact
Financial Impact Interpretation
Prevalence and Trends
Prevalence and Trends Interpretation
Prevention and Response
Prevention and Response Interpretation
Victim Demographics
Victim Demographics Interpretation
Sources & References
- Reference 1DOCSdocs.apwg.orgVisit source
- Reference 2VERIZONverizon.comVisit source
- Reference 3PROOFPOINTproofpoint.comVisit source
- Reference 4IBMibm.comVisit source
- Reference 5AKAaka.msVisit source
- Reference 6TRANSPARENCYREPORTtransparencyreport.google.comVisit source
- Reference 7IC3ic3.govVisit source
- Reference 8PHISHLABSphishlabs.comVisit source
- Reference 9SECURELISTsecurelist.comVisit source
- Reference 10SOPHOSsophos.comVisit source
- Reference 11KNOWBE4knowbe4.comVisit source
- Reference 12BARRACUDAbarracuda.comVisit source
- Reference 13ZSCALERzscaler.comVisit source
- Reference 14BLOGblog.talosintelligence.comVisit source
- Reference 15ABNORMALSECURITYabnormalsecurity.comVisit source
- Reference 16MIMECASTmimecast.comVisit source
- Reference 17TRENDMICROtrendmicro.comVisit source
- Reference 18FORTINETfortinet.comVisit source
- Reference 19RESEARCHresearch.checkpoint.comVisit source
- Reference 20CROWDSTRIKEcrowdstrike.comVisit source
- Reference 21DARKTRACEdarktrace.comVisit source
- Reference 22RAPID7rapid7.comVisit source
- Reference 23UNIT42unit42.paloaltonetworks.comVisit source
- Reference 24MANDIANTmandiant.comVisit source
- Reference 25RECORDEDFUTURErecordedfuture.comVisit source
- Reference 26SLASHNEXTslashnext.comVisit source
- Reference 27NETCRAFTnetcraft.comVisit source
- Reference 28THREATRESEARCHthreatresearch.ext.hp.comVisit source
- Reference 29LOOKOUTlookout.comVisit source
- Reference 30APWGapwg.orgVisit source
- Reference 31FTCftc.govVisit source
- Reference 32PONEMONponemon.orgVisit source
- Reference 33KASPERSKYkaspersky.comVisit source
- Reference 34CISCOcisco.comVisit source






