Skip to main content
HomeTopicsPhishing

Phishing

Email security statistics, phishing attack trends, user awareness metrics, and defense effectiveness data.

Showing 361-380 of 389 results

The most common third-party platforms used for phishing were: • sendgrid.com • salesforce.com • amazonaws.com • sendlayer.com • mailgun.com • marketo.com.

KnowBe43/20/2025

20% of phishing emails between September 15, 2024 and February 14, 2025 relied solely on social engineering.

KnowBe43/20/2025
Social engineering

In 2024, there was a 47% increase in phishing emails evading detection by Microsoft’s native security and secure email gateways.

KnowBe43/20/2025
EvasionMicrosoft

Most polymorphic phishing emails are sent from compromised accounts (52%), followed by phishing domains (25%), and webmail (20%).

KnowBe43/20/2025
Polymorphic

25.9% of phishing emails between September 15, 2024 and February 14, 2025 contained attachments.

KnowBe43/20/2025

There was a 17.3% increase in phishing emails between September 15, 2024 and February 14, 2025 compared to the previous six months.

KnowBe43/20/2025

Cybercriminals created nearly 1 million new phishing sites each month in 2024. This represents a 700% increase since 2020.

Menlo Security3/19/2025

Nearly 51% of browser-based phishing attempts involved some form of brand impersonation in 2024.

Menlo Security3/19/2025
Brand impersonationBrowser-based phishing

75% of phishing links are hosted on good, trusted websites.

Menlo Security3/19/2025

Four of the top five hosting providers used by bad actors to host phishing attacks were based in the U.S. in 2024.

Menlo Security3/19/2025
US

There is up to six days as the average window of exposure before legacy security tools begin blocking pages from zero-hour phishing attacks.

Menlo Security3/19/2025
Zero-hour phishing

Cybercriminals created nearly 1 million new phishing sites each month in 2024. This represents a 700% increase since 2020.

Menlo Security3/19/2025

There has been a 140% increase in browser-based phishing attacks in 2024 compared to 2023.

Menlo Security3/19/2025
Browser-based phishing

Phishing attacks hosted on subdomain providers increased by 51% in 2024, representing 24% of all phishing attacks.

Menlo Security3/19/2025

Solara Medical Supplies' $9.76 million settlement was due to a phishing-related breach affecting 114,000 patient records.

Paubox 3/13/2025
Data breachHealthcare

For medium sized organisations, the average Phish Prone Percentage PPP after one year of sustained training dropped to 5.2%.

KnowBe43/1/2025
EducationTraining

After 90 days of training and simulated phishing tests, the Phish Prone Percentages (PPPs) for the education sector reduced to 19%, 19.4%, and 18% respectively for small, medium, and large organisations.

KnowBe43/1/2025
EducationTraining

The median time for users to fall for phishing emails is less than 60 seconds.

KnowBe43/1/2025

More than 20% of users identified and reported phishing per engagement, including 11% of the users who did click the email.

KnowBe43/1/2025

For education institutions with 250-999 employees, the baseline Phish Prone Perecentage (PPP) was 31.2%.

KnowBe43/1/2025
Education