100 Mind-Blowing Phishing Facts

Hacking programs, spammers and malicious phishing take 30% of the Internet traffic.

Most Internet traffic isn’t from real humans. About 51% of Internet traffic is non-human. Over 30% is from hacking programs, spammers, and phishing. Be careful with your computer security!

57 per cent of organisations see weekly or daily phishing attempts. (GreatHorn)

Phishing was the leading infection vector, identified in 41% of incidents, making it the most common initial attack vector. (IBM)

26 per cent of phishing attacks exploited public-facing applications. (IBM)

$17,700 is lost every minute due to a phishing attack. (CSO Online)

The use of stolen cards is the most common type of threat, followed by ransomware and phishing. (Verizon)

Phishing is the most expensive initial attack vector, costing $4.9 million in 2023 (IBM).

In Europe, U.K. companies are the most likely to be targeted by phishing attacks, followed by Spain (Slash Next)

In the first month of the pandemic, Google blocked 18 million daily malware and phishing emails related to the coronavirus. (Google)

47 per cent of employees cited distraction as the reason for falling for a phishing scam while working from home. (Tessian)

55% of phishing sites used target brand identities in URLs for hacking (F5 Labs): The 2020 report from F5 Labs on phishing and hacking found a massive increase in the number of phishing attacks in 2020. There were 15% more phishing attacks in 2020 compared to 2019. 55% of all phishing attacks also target brand names and identities of other companies in their URL, domain name, or path to trick customers.

In 2020 hackers sold over 500,000 Zoom passwords on the dark web (Forbes): Criminals will often take advantage of events happening in the world, the concerns of their targets, and the vulnerability of society to make money. This was particularly evident in 2020 when countless hackers started sending COVID-themed phishing emails to attempt to hack personal and business accounts. Forbes reported in April 2020 that hackers stole and sold over 500,000 passwords for the popular video-conferencing tool, Zoom, which ended up on the dark web. The information included personal user names too.

More than 85% of breaches in 2021 involved a human element (Verizon): The Verizon Data Breach Investigations report for 2021 found around 85% of breaches involved a human element, and 61% involved using an employee’s credentials stolen from the business. In 2021, the majority of attacks came from social engineering, phishing, and Denial of Service attacks, according to Verizon. Particularly, Phishing became one of the most significant threats during the pandemic.

In 2021 the most common initial attack vector was compromised credentials (IBM): IBM reported the most common initial attack vendor to be compromised credentials in hacking cases. In other words, this is when people lose their username or password. Compromised credentials accounted for around 20% of attacks, while phishing was responsible for 17%, and cloud misconfiguration led to around 15% of hacks. Though business email compromise was responsible for only 4% of hacking incidents in this report, it also had the highest average cost at around $5.1 million per attack. The second most expensive initial attack vector was phishing, at around $4.56 million.

A SlashNext report called The State of Phishing 2023 reveals a 1,265% increase in phishing emails since ChatGPT launched, “signalling a new era of cybercrime fueled by generative AI.”

Scroll to Top