phishing statisticshuman riskhuman factor

    August 6, 2026 · 6 min read · By Fensivo Team

    Phishing statistics 2026: the numbers behind human risk

    Leer en español

    If you are looking for phishing and human-risk statistics to back a report or a decision, here are the 2026 figures you can cite on their own, each with its primary source and edition. We only kept numbers we verified against the original source, not figures that travel from slide to slide with no owner. The five that matter most come first, in the table; the rest is grouped by theme, so you can take only the one you need.

    #StatisticSource
    1Close to 90 percent of breaches involve a human factorCisco's 90-5-5 framework (2025)
    2More than 90 percent of successful cyberattacks begin with a phishing emailCISA
    34.4 million dollars: global average cost of a data breach in 2025IBM, Cost of a Data Breach 2025
    422 seconds: handoff time from initial access to the actor running the attack in 2025Mandiant, M-Trends 2026
    56.74 billion dollars: security awareness training market in 2026Mordor Intelligence

    A note on method before the figures: we deliberately left out several numbers you will see cited elsewhere because we could not trace them to an open, stable primary source. We would rather give you a shorter, verifiable list than a longer, fragile one. Every figure below carries its source in the same line.

    The human factor is still the primary vector

    1. Close to 90 percent of breaches involve a human factor. Cisco's 90-5-5 framework estimates that close to 90 percent of breaches involve a human factor. It is the anchor figure for the whole category, and it is worth reading carefully: it does not say people are careless, it says most incidents run through a human decision that an attacker knew how to trigger. That is why we speak of the human factor: it names a risk surface without blaming the person.

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment

    2. The rest splits between tools and resources. The 90-5-5 breakdown from Cisco splits the rest this way: 5 percent missing or misconfigured tools, and the remaining 5 percent limited resources such as time or staffing. The useful takeaway is not to assign blame, it is that investing in that 10 percent of technology and resources is exactly what holds up the 90 percent that is human.

    3. Completing training does not by itself predict that behavior changes. Two peer-reviewed studies from the IEEE Symposium on Security and Privacy (Ho et al., 2025; Lain et al., 2022) found that having completed training does not by itself predict a lower likelihood of falling for a real attack. It is not a headline number, it is the finding that explains why measuring completed courses is not the same as measuring risk, and why the only proof someone learned is testing them again.

    Phishing by email is the entry point

    4. More than 90 percent of successful cyberattacks begin with a phishing email. This is the figure from CISA, the United States cybersecurity agency, and it is why email is still the first front to cover, ahead of any newer channel.

    5. AI-driven phishing is now three times more effective than traditional campaigns. The Microsoft Digital Defense Report 2025 reports it. The uncomfortable conclusion is that email is not fading: it became cheaper to produce and harder to detect. In its targeted form, business email compromise (BEC), the messages that impersonate an executive or a supplier to divert a payment, is the most expensive face of this same vector. That is why adaptive phishing simulations target email before any other channel.

    What a breach costs

    6. 4.4 million dollars is the global average cost of a data breach in 2025. According to IBM's Cost of a Data Breach 2025, that was the worldwide average. It is the figure that translates human risk into the language of the finance office.

    7. That cost fell 9 percent from the prior year. The same IBM report attributes the drop to faster identification and containment. The message is not that breaches cost less because they matter less, it is that companies that detect and contain sooner pay less: reaction speed has a measurable price.

    How fast the attacker moves

    8. 22 seconds is how long the handoff now takes between initial access and the actor running the attack. Mandiant's M-Trends 2026 (Google Cloud) documents that this time went from more than 8 hours in 2022 to 22 seconds in 2025. In practice: once a credential leaks or someone falls for an email, the window to react stopped being measured in hours.

    The size of the category

    The market that answers this problem, human risk management (HRM), has a size and a growth rate you can also cite.

    9. 6.74 billion dollars is the size of the security awareness training market in 2026. Mordor Intelligence values it at 6.74 billion, up from 5.77 billion in 2025.

    10. It is projected to reach 14.66 billion dollars by 2031. The same source, Mordor Intelligence, maps that five-year trajectory.

    11. The category grows at a compound annual rate near 16.82 percent. It is one of the faster rates in security, and it explains why more and more vendors are competing for the budget that goes to people.

    12. Small and midsize businesses are the fastest-growing segment. Mordor attributes this to cloud delivery lowering cost and deployment barriers. That is the 25-to-500-employee range, where the human factor weighs as much as in a large enterprise but the security budget is a fraction of it.

    Read together, the twelve figures tell a single story: the problem is human and arrives by email, it costs millions, it plays out in seconds, and training on its own does not solve it. What changes the outcome is not stacking up data, it is acting on it and validating that behavior actually changed.

    At Fensivo we work on exactly this cycle: we continuously monitor more than 680 public breach databases and the dark web to cut from months to hours the time a leaked credential stays useful to an attacker, we send per-person personalized email phishing simulations, and when someone falls we deliver microlearning within minutes. What sets the cycle apart is the retest: weeks later we run the same type of attack with a different template, to validate that behavior changed and not just that an email was remembered. It is built for companies of 25 to 500 employees, where the human factor weighs as much as in a large corporation. You can see how it all fits together in our use cases.

    How many of the figures you use today to justify your security budget could you trace back to a primary source, and how many do you repeat only because you saw them on someone else's slide?

    Sources and references

    Cisco, "The 90-5-5 Concept: Your Key to Solving Human Risk in Cybersecurity", May 27, 2025. https://blogs.cisco.com/security/the-90-5-5-concept-your-key-to-solving-human-risk-in-cybersecurity

    CISA, "4 Things You Can Do To Keep Yourself Cyber Safe". https://www.cisa.gov/news-events/news/4-things-you-can-do-keep-yourself-cyber-safe

    Microsoft, "Microsoft Digital Defense Report 2025". https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2025

    IBM, "Cost of a Data Breach Report 2025". https://www.ibm.com/reports/data-breach

    Mandiant (Google Cloud), "M-Trends 2026 Report". https://cloud.google.com/security/resources/m-trends

    Mordor Intelligence, "Security Awareness Training Market Size & Share Analysis (2026-2031)". https://www.mordorintelligence.com/industry-reports/security-awareness-training-market

    Ho, G. et al., "Understanding the Efficacy of Phishing Training in Practice", 2025 IEEE Symposium on Security and Privacy. https://ieeexplore.ieee.org/document/11023357

    Lain, D., Kostiainen, K. and Čapkun, S., "Phishing in Organizations: Findings from a Large-Scale and Long-Term Study", 2022 IEEE Symposium on Security and Privacy. https://ieeexplore.ieee.org/document/9833766

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment