Back to Learning Hub

Quick Guide: Phishing Statistics

Last updated: 2026-08-133 min read

What the headline phishing numbers mean, how to read a benchmark without fooling yourself, and which of your own metrics actually predict risk.

Why do attackers keep using phishing? Because it works, and because it is cheap. Even with strong technical controls, one person having a busy day can hand over everything an attacker needs.

Deep dive: for the full dataset, read Phishing Statistics 2026: 40 Numbers Every Security Team Needs to Know.

This page is the short version — the handful of numbers worth remembering, and, more usefully, how to read them without misleading yourself.


The reality

  • Phishing is the primary entry point. Over 90% of successful cyberattacks begin with a phishing email. Attackers rarely break in; they get invited in.
  • Email still dominates. SMS, voice and QR-based attacks are all growing, but email remains the workhorse because it is cheap to send and trivial to automate.
  • Human error is ordinary, not negligent. Most breaches involving people are not malicious insiders. They are competent employees making one fast decision on a bad day, which is why the fix is habit-building rather than blame.

The good news

The same data shows training moves the numbers. Teams running regular simulations can reduce click rates by up to 70% within a year, and a genuine reporting culture turns detection from days into minutes.


How to read a benchmark without fooling yourself

This is where most teams go wrong, and no statistic protects you from it.

A click rate only means something next to its difficulty. A 3% click rate on an obvious lure is worse than 18% on a realistic one. Comparing your number to an industry average is meaningless unless the simulations were comparably hard, which is never stated. Compare against your own baseline instead.

Low clicks plus low reports is a bad result. It usually means people ignored the message rather than recognised it. The combination you want is falling clicks and rising reports — that shows recognition, not apathy.

Time to report beats both. A real campaign hitting 200 inboxes is a race. Whether the first report arrives in four minutes or four hours decides if security contains it or cleans up after it. It is the metric most closely tied to actual outcomes, and the one most often ignored.

Averages hide the people who matter. A tolerable organisational click rate can conceal a small group clicking every single campaign. Repeat clickers carry a disproportionate share of the risk, and targeted help for a handful of people beats retraining everyone.

Beware numbers with no methodology. Vendor statistics rarely disclose sample, sector, or lure difficulty. Treat a figure without its method as directional, never as a target.

For sector context where the methodology is stated, see the click rate and reporting rate benchmarks.


The takeaway

Phishing is a human problem with measurable outcomes, which is unusual and useful — most security risk is far harder to quantify. Track your own click rate, report rate and time to report over time, and the trend will tell you more than any industry average. On what that improvement is worth financially, see the security awareness training ROI benchmarks.


Related Learning

Ready to stop phishing attacks?

Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.