If you've been following cybersecurity news lately, you may have caught a headline that sounds almost encouraging: global phishing attack volume dropped 20% in 2024. And then dropped another 20% in 2025. On the surface, that sounds like progress — like defenders are finally winning the war against one of the internet's oldest and most persistent threats.
But here's the uncomfortable truth: the risk is not going down. In fact, it's accelerating.
Although global phishing volume dropped about 20% in 2024, this was not a victory for defenders. Attackers simply got more strategic, focusing on fewer but higher-value targets in departments like HR, finance, and payroll to maximise payouts.
Fewer attacks. Bigger damage. That's the new calculus facing every organisation connected to the internet.
This post breaks down exactly what's happening in the phishing threat landscape, why the raw numbers are misleading, and — most importantly — what you can do about it right now.
The 20% Drop: What It Really Means
At first glance, the data from Zscaler seems reassuring.
After the record high, phishing volume dropped 20% in 2024, and another 20% in 2025.
But security experts are quick to pump the brakes on any celebration.
Zscaler's senior director of threat intelligence told Dark Reading that the trend doesn't necessarily have to do with AI, or even phishing for that matter. Instead, threat actors are becoming more selective.
The analogy to ransomware is instructive: early ransomware operators cast wide nets hoping to catch anyone, including home users willing to pay small ransoms. Today, ransomware gangs target large enterprises for millions. Phishing has followed the exact same evolutionary path.
The financial data confirms the strategic pivot is working.
The FBI reported having received the same number of phishing complaints in 2024 and 2025, yet the total losses to victims tripled, from $70 million to $215 million. In 2023 — a year in which it received 50% more complaints — losses only added up to $18 million.
Read that again. Fewer complaints. Twelve times the losses. The attackers are winning, even as the volume falls.
The Financial Toll: A Multi-Billion Dollar Crisis
The headline numbers are staggering.
Phishing attacks had an estimated financial impact of $3.5 billion in 2024.
But when you zoom out further, the picture becomes even grimmer.
Global phishing losses total $25 billion annually, with $17,700 lost every minute.
Business Email Compromise (BEC) — a direct descendant of phishing — is one of the primary drivers of those losses.
BEC generated $3.046 billion in losses from just 24,768 FBI complaints in 2025, averaging $122,999 per complaint, making it the second-costliest cybercrime category.
The average cost of a single phishing-related breach is also climbing fast.
According to IBM's Cost of a Data Breach report, phishing-related breaches now average $4.88 million per incident.
And when AI-augmented attacks enter the picture, the losses jump even higher:
average per-incident losses from AI-augmented BEC now exceed $4.1 million, compared to $1.3 million for traditional phishing.
What makes this especially alarming is how long attacks go undetected.
On average, phishing attacks take 254 days to detect and contain — the third longest of all attack vectors, behind only supply chain attacks and malicious insiders.
Nearly nine months of undetected access can cause catastrophic, irreversible damage to any organisation.
How Phishing Has Evolved: Quality Over Quantity
The modern phishing attack looks almost nothing like the misspelled emails from "Nigerian princes" that defined the early era of internet fraud. Today's campaigns are surgical, multi-channel, and increasingly powered by artificial intelligence.
AI Is Supercharging Every Attack
82.6% of detected phishing emails now show signs of AI generation.
That number alone should reshape how every security team thinks about their email defences.
Generative AI has reduced phishing email creation from 16 hours to approximately 5 minutes, enabling attackers to operate at unprecedented volume per IBM X-Force 2026.
What once required a dedicated criminal team and significant investment can now be launched by a single actor for almost nothing.
The cost reduction of over 95% means phishing campaigns that previously required dedicated criminal teams costing $50,000+ per operation can now be run for under $5.
The result is attacks that are flawless in grammar, perfectly contextualised, and terrifyingly convincing.
AI-generated phishing eliminates the grammatical errors, generic messaging, and manual limitations that legacy email filters and awareness training relied on to catch fraud.
The Rise of Quishing, Vishing, and Multi-Channel Attacks
Phishing is no longer just an email problem. Attackers have diversified across every communication channel imaginable.
- Quishing (QR code phishing):
QR code phishing attacks increased 400% between 2023 and 2025.
QR codes embed malicious URLs in images, bypassing traditional text-based email filters entirely — the malicious link exists only in an image.
- Vishing (voice phishing):
Deepfake vishing attacks surged by 1,633% in Q1 2025 versus Q4 2024.
AI voice cloning lets scammers mimic real people's voices from just a few seconds of audio, producing highly convincing calls that even tech-savvy users might trust.
- Smishing (SMS phishing):
Roughly 70% of all mobile phishing attacks happen through smishing.
Phishing has expanded beyond email, with 19% of breaches now attributed to smishing and vishing, highlighting the diversification of channels used for impersonation and deception.
AiTM Attacks: MFA Is No Longer Enough
Perhaps the most technically alarming development in the phishing landscape is the explosion of Adversary-in-the-Middle (AiTM) attacks.
Adversary-in-the-middle attacks, which bypass multi-factor authentication by intercepting session cookies in real time, surged 146% in 2024.
These attacks render standard MFA protections effectively useless.
These Attacker-in-the-Middle attacks are powered by criminal Phishing-as-a-Service kits such as Tycoon, NakedPages, Sneaky2FA, and various Evilginx variations.
Security teams that have relied on MFA as their primary defence need to urgently reassess their posture.
The Deepfake Dimension: When Seeing Isn't Believing
Deepfake technology has taken social engineering to an entirely new level of danger. In 2024, a now-infamous case saw a finance employee transfer millions after attending a video call where
the attack involved a sophisticated, multi-person video conference featuring deepfaked, AI-generated likenesses of the company's CFO and other senior executives.
In 2024, businesses lost an average of nearly $500,000 per deepfake-related incident.
And the trajectory is steep:
a forecast from the Deloitte Center for Financial Services projects that fraud losses facilitated by generative AI will climb from $12.3 billion in 2023 to $40 billion by 2027, a compound annual growth rate of 32%.
The human impact is just as troubling as the financial.
32% of leaders lack confidence in their employees' ability to detect or respond to deepfakes effectively, while over 50% of business leaders admit their teams have never received training on identifying or mitigating deepfake attacks.
Industries Under the Crosshairs
While no sector is immune, the data reveals clear patterns in who attackers are targeting most aggressively.
Certain industries experienced major swings in 2025, with services sector phishing attacks rising 66% and government attacks rising 50%.
In 2024, manufacturing was the most targeted industry, accounting for about 21.8% of phishing attacks, closely followed by the services sector at 20.7% and education at 17.9%.
In the financial sector, between 59% and 66% of ransomware and extortion cases begin with phishing campaigns, while pretexting and BEC account for 24–25% of financial attacks.
Looking ahead,
2026 is expected to see a 14x increase in AI-generated phishing attacks, and phishing is projected to account for more than 42% of all global breaches.
Practical Tips: What You Can Do Right Now
The evolving threat landscape is sobering, but not hopeless. Here are actionable steps every individual and organisation can implement immediately.
1. Upgrade to Phishing-Resistant MFA
Standard MFA can be bypassed by AiTM attacks. Move to phishing-resistant authentication methods such as FIDO2 hardware keys or passkeys.
Microsoft's own implementation, which embedded phishing-resistant MFA into every stage of the employee lifecycle, resulted in 92% of employee productivity accounts being protected by phishing-resistant authentication.
2. Run Continuous, Simulation-Based Security Training
Annual compliance-tick-box training is no longer sufficient.
Research shows that phishing awareness training reduces data breaches significantly when implemented as a continuous, simulation-based programme rather than a perfunctory annual compliance exercise. Organisations that run monthly phishing simulations see employee click rates drop from an industry baseline of ~30% to below 5% within 12 months.
3. Establish a Multi-Channel Verification Protocol
Never authorise financial transactions or sensitive data transfers based on a single communication — even a video call.
Always verify through a second channel, especially for financial or sensitive tasks, and use authentication tools and train staff to detect anomalies.
4. Deploy AI-Powered Email Threat Detection
Email security gateways implementing advanced threat protection, sandboxing, and URL rewriting reduce inbox penetration of malicious messages — these systems detonate attachments in isolated environments, rewrite URLs to redirect through security scanners, and compare messages against known phishing campaigns.
5. Train Employees to Spot Deepfake Red Flags
Signs of deepfake video calls include unnatural blinking, lip-sync mismatches, and voice distortions.
Combine this with mandatory out-of-band verification protocols for any unusual executive requests.
6. Build a Zero-Trust Security Architecture
Identity platforms are expected to serve as amplifiers for attackers, who will continue targeting cloud platforms, SaaS tools, and identity providers — a single compromised identity can grant access to various collaboration tools and internal applications.
A Zero Trust model, which assumes no user or device is automatically trusted, limits the blast radius of any successful phishing attack.
7. Have an Incident Response Plan Ready
Employees should not attempt to resolve a phishing incident independently. Report it to your IT support or security team immediately, and follow your organisation's incident response plan.
Speed of response is critical — every hour of delay compounds the damage.
The Road Ahead: Vigilance Is Non-Negotiable
The 20% drop in phishing volume is not a victory lap — it's a strategic pivot by cybercriminals who have learned that precision beats volume.
Phishing does not follow isolated cycles but rather a sustained pattern of growth and continuous adaptation, with artificial intelligence, phishing-as-a-service models, and diversification into deepfakes, smishing, and vishing all increasing campaign sophistication.
According to the U.S. Cybersecurity and Infrastructure Security Agency, more than 90% of successful cyberattacks begin with a phishing attack, making it one of the most pervasive, effective, and costly forms of cybercrime.
That figure has not budged despite years of defensive innovation, because attackers innovate just as fast — often faster.
The organisations that will weather this threat successfully are those that treat phishing as an ever-present, constantly evolving adversary — not a problem to be solved once and forgotten.
Is Your Organisation Truly Protected?
If reading this has made you question whether your current defences are keeping pace with the modern phishing threat, that instinct is worth acting on. The data is clear: fewer attacks are causing dramatically more damage, and AI has made it easier than ever for attackers to craft convincing, multi-channel campaigns that bypass traditional security tools.
Now is the time to audit your phishing defences, upgrade to phishing-resistant MFA, invest in continuous employee security training, and develop a robust incident response plan. Don't wait for a $4.88 million data breach to find the gaps in your security posture — find them first. Speak to a cybersecurity specialist today and take the guesswork out of your organisation's resilience against the evolving phishing threat landscape.



