← Blog
Deliverability

22 email security statistics that matter: 2026 edition

Email is still the number-one way attackers get in - and the same authentication that stops them is what earns your real mail a place in the inbox. These 22 sourced statistics show where email security actually breaks, and how the fix doubles as a deliverability control.

11 min readPublished July 11, 2026Sendaloft Research

Every serious security incident has an origin story, and more often than not it begins in an inbox. A forged sender, a convincing link, a fake invoice from a "vendor" - email is where attackers first make contact, because it is the one channel that reaches everyone and trusts by default. In 2026, the numbers behind that opening move are stark.

The uncomfortable truth is that email security and email deliverability are the same problem viewed from two sides. The controls that stop a criminal from spoofing your domain - SPF, DKIM, and an enforced DMARC policy - are the exact signals mailbox providers use to decide whether your legitimate mail belongs in Primary or in spam. Neglect one and you weaken both.

Here are 22 sourced email security statistics for 2026 - covering phishing and BEC losses, breaches that start with email, DMARC and spoofing, malware delivery, employee behavior, and the cost of getting it wrong - with what each one means for how you protect and deliver your email.

Key takeaways

Phishing and BEC: the losses

1. US victims reported a record $16.6 billion in cybercrime losses in 2024

The FBI's Internet Crime Complaint Center logged a record $16.6 billion in reported cybercrime losses in 2024, up 33% from the prior year. Email-borne attacks - phishing, spoofing, and BEC - sit at the center of that total, which is why hardening the inbox is a financial decision, not just a technical one.

2. Business Email Compromise caused $2.77 billion in losses across 21,442 complaints

BEC remains the single most expensive email threat: in 2024 it drove $2.77 billion in losses across 21,442 complaints. These attacks rarely carry malware - they rely on a trusted-looking sender and a plausible request, which is exactly the gap that domain authentication closes.

3. Proofpoint detects about 66 million targeted BEC attacks every month

The scale is relentless. Proofpoint reports detecting roughly 66 million targeted BEC attacks per month. This is not a rare, sophisticated event aimed at a few enterprises - it is a constant, high-volume tide that every sending domain has to defend against.

4. Phishing and spoofing drew 193,407 FBI complaints as losses jumped 274%

Phishing and spoofing generated 193,407 complaints in 2024, with associated losses jumping 274% to $70 million. The complaint count is high and the loss-per-incident is climbing fast - attackers are getting more effective, not less.

5. Brand impersonation is used in more than 80% of spear-phishing attacks

Barracuda found brand impersonation appears in more than 80% of spear-phishing attacks. Attackers succeed by wearing a trusted name - often yours. A published, enforced DMARC policy is what stops criminals from forging your domain in the first place.

Check whether your domain is protected against spoofing →

Breaches that start with email

6. 68% of breaches involved a non-malicious human element

Verizon's 2024 DBIR found 68% of breaches involved a non-malicious human element such as social engineering or a simple error. Most breaches do not begin with a zero-day exploit - they begin with a person who was tricked, usually over email.

7. Phishing was the initial vector in 15% of data breaches in 2024

IBM's analysis found phishing was the initial access vector in 15% of data breaches, second only to stolen credentials - which are themselves frequently harvested through phishing emails. Email sits behind a large share of breaches even when it is not the label on the report.

8. Phishing and pretexting by email were 73% of social-engineering incidents

Within social engineering, the DBIR attributes 73% of incidents to phishing and pretexting delivered by email. When an organization is manipulated into a breach, email is overwhelmingly the medium the manipulation travels through.

DMARC and the spoofing gap

9. Only 20% of the top 10 million domains had a DMARC record

Valimail found that as of September 2024, only about 20% of the top 10 million domains published a DMARC record. Four in five major domains still leave the door open to exact-domain spoofing - a striking gap given how cheap the fix is.

10. Google and Yahoo's rules drove 500,000+ domains to publish DMARC

The 2024 sender requirements had a measurable effect: Valimail reports more than 500,000 additional top-10-million domains published DMARC by February 2024. When mailbox providers made authentication a condition of delivery, adoption jumped - proof that security and deliverability incentives pull in the same direction.

11. DMARC stops an estimated 90% of spoofing attacks

An enforced DMARC policy is one of the highest-leverage controls available: Valimail estimates it stops about 90% of spoofing attacks. The catch is enforcement - a record at p=none monitors but does not block. Sendaloft configures SPF, DKIM, and DMARC and moves the policy to enforcement so your domain is actually protected.

Run a free authentication and inbox placement test →

Malware and ransomware delivered by email

12. A malicious email bypassed secure gateways every 57 seconds

Cofense found a malicious email slipping past a secure email gateway every 57 seconds, a 104.5% year-over-year increase. Gateways catch a great deal, but the ones that get through arrive constantly - defense cannot stop at the perimeter filter.

13. Cofense found 1.5 million-plus malicious emails bypassing gateways in two years

Over a two-year window, Cofense identified more than 1.5 million malicious emails that bypassed secure email gateways. The volume that evades automated filtering is enormous, which is why authentication and user reporting have to backstop the gateway.

14. 69% of organizations suffered a successful ransomware infection in the past year

Proofpoint found 69% of organizations experienced a successful ransomware infection in the past year. Ransomware overwhelmingly enters through email - a malicious attachment or link - making the inbox the front line of ransomware defense.

15. Phishing made up 43.3% of email attacks and malicious URLs 30.5%

Across roughly 45 billion emails analyzed, Hornetsecurity found phishing accounted for 43.3% of email attacks and malicious URLs for 30.5%. Together, link-based and impersonation attacks dominate the threat mix - the payload is increasingly a click, not just an attachment.

16. HTML files are the most common malicious attachment at 37.1%

Hornetsecurity found HTML files are the most common malicious attachment at 37.1%, ahead of PDFs at 23.3%. Attackers favor HTML because it renders convincing fake login pages and evades signature-based scanning - a reminder that "it's just an HTML file" is not reassurance.

Employee click and report rates

17. Users click a phishing link in a median 21 seconds and submit data 28 seconds later

Verizon's DBIR clocked the speed of compromise: users click a phishing link in a median of 21 seconds and submit data 28 seconds after that. Under a minute separates a delivered phish from stolen credentials - too fast for human review to intervene, which is why prevention has to happen before the message lands.

18. In simulations, only 20% reported the phish without clicking

Phishing simulations paint a sobering picture: only 20% of users reported the phish without clicking, and just 11% reported it after clicking. The overwhelming majority neither report nor resist - security teams cannot rely on human vigilance alone.

19. 71% of working adults admitted taking a risky action

Proofpoint found 71% of working adults admitted to a risky action such as reusing passwords or clicking unknown links. Risky behavior is the norm, not the exception, which is why technical controls that stop the malicious mail from arriving matter far more than awareness slogans.

20. Credential phishing volume rose 67% year over year

Cofense measured credential phishing volume rising 67% year over year. Attackers are concentrating on stealing logins - the same stolen credentials that top the breach-vector charts - and email is their delivery mechanism of choice.

The cost of email attacks

21. The global average cost of a data breach reached $4.88 million in 2024

IBM's 2024 report put the global average breach cost at $4.88 million, up about 10% year over year and a record high. Given that phishing and stolen credentials lead the vector list, email hardening is one of the most direct levers on this number.

22. Breaches taking 200+ days to contain cost nearly $5.5 million

IBM also found breaches that take more than 200 days to identify and contain cost nearly $5.5 million on average. The slower an email-driven intrusion is caught, the more it costs - and stopping the initial phish is far cheaper than the months-long cleanup that follows.

What this means: the email security playbook

Authenticate your domain, then enforce it. DMARC at an enforcing policy stops roughly 90% of spoofing, yet only about 20% of top domains even publish a record and most that do sit at p=none. A monitoring-only policy earns no protection. Get SPF, DKIM, and DMARC aligned and move DMARC to p=quarantine or p=reject so attackers cannot forge your domain in the brand-impersonation attacks that drive most spear-phishing.

Treat authentication as a deliverability control, not just a security one. The same DNS records that block spoofing are what Gmail and Yahoo use to decide whether your real mail reaches Primary. When Google and Yahoo made authentication mandatory, 500,000+ domains added DMARC almost overnight - because security and inbox placement are enforced by the same gatekeepers. Fixing one fixes the other.

Assume the malicious mail will get through. A phish bypasses secure gateways every 57 seconds, and Cofense counted 1.5 million-plus that slipped past in two years. Gateways are necessary but not sufficient. Layer authentication, monitoring, and fast user reporting so the messages that evade the filter still hit a wall - and so your own domain is not the one being impersonated.

Do not rely on employees to catch it. Users click in a median 21 seconds and submit data 28 seconds later, only 20% report a phish without clicking, and 71% admit to risky behavior. Human vigilance is real but too slow and too rare to be the primary control. The highest-leverage move is preventing the malicious and spoofed mail from arriving at all.

Count the cost, then close the cheapest gap first. The average breach now costs $4.88 million, and slow-to-contain incidents near $5.5 million - with phishing and stolen credentials leading the way in. Authentication is close to free by comparison. Before you scale sending, test your domain's authentication and inbox placement so you close the spoofing gap while it is still just a DNS change.

FAQ

Questions, answered.

What share of cyberattacks and breaches start with email?+
Email is the dominant entry point. Verizon's DBIR found phishing and pretexting by email make up 73% of social-engineering incidents, and phishing was the initial access vector in 15% of all data breaches in 2024 - second only to stolen credentials, which are themselves often harvested by email. Proofpoint reports US cybercrime losses hit a record $16.6 billion in 2024, much of it driven by email-borne attacks.
What is Business Email Compromise (BEC) and how costly is it?+
Business Email Compromise is a fraud where an attacker impersonates a trusted sender - an executive, vendor, or partner - to trick someone into wiring money or handing over data. In 2024 the FBI logged 21,442 BEC complaints totaling $2.77 billion in losses, and Proofpoint detects roughly 66 million targeted BEC attacks every month. Brand impersonation appears in more than 80% of spear-phishing attacks, which is exactly what DMARC enforcement is designed to block.
Does DMARC actually stop email spoofing?+
Yes - DMARC at an enforcing policy stops an estimated 90% of spoofing attacks by rejecting mail that fails authentication alignment for your domain. Adoption is still the gap: only about 20% of the top 10 million domains had a DMARC record as of September 2024, though Google and Yahoo's 2024 sender rules pushed more than 500,000 additional top-domain publishers to add one. A DMARC record only protects you at p=quarantine or p=reject, not at p=none.
How fast do people fall for phishing emails?+
Alarmingly fast. Verizon's DBIR found users click a phishing link in a median of 21 seconds and submit data 28 seconds after that - under a minute from open to compromise. In phishing simulations, only 20% of users reported the phish without clicking, and just 11% reported it after clicking. Proofpoint found 71% of working adults admitted to a risky action like reusing passwords or clicking unknown links.
How much does an email-driven data breach cost?+
IBM's 2024 report put the global average cost of a data breach at $4.88 million, up about 10% year over year and a record high. Breaches that take more than 200 days to identify and contain cost nearly $5.5 million on average. Because phishing and stolen credentials are the leading initial vectors, hardening email is one of the most direct ways to lower breach risk and cost.
How does email authentication improve both security and deliverability?+
SPF, DKIM, and DMARC do double duty. On the security side, enforced DMARC blocks about 90% of spoofing and shuts down the brand impersonation used in most spear-phishing. On the deliverability side, mailbox providers reward authenticated, aligned senders with inbox placement and penalize domains that fail authentication. The same DNS configuration that stops attackers from forging your domain is what convinces Gmail and Yahoo to trust your real mail - security and deliverability are the same project.