22 email security statistics that matter: 2026 edition
Email is still the number-one way attackers get in - and the same authentication that stops them is what earns your real mail a place in the inbox. These 22 sourced statistics show where email security actually breaks, and how the fix doubles as a deliverability control.
Every serious security incident has an origin story, and more often than not it begins in an inbox. A forged sender, a convincing link, a fake invoice from a "vendor" - email is where attackers first make contact, because it is the one channel that reaches everyone and trusts by default. In 2026, the numbers behind that opening move are stark.
The uncomfortable truth is that email security and email deliverability are the same problem viewed from two sides. The controls that stop a criminal from spoofing your domain - SPF, DKIM, and an enforced DMARC policy - are the exact signals mailbox providers use to decide whether your legitimate mail belongs in Primary or in spam. Neglect one and you weaken both.
Here are 22 sourced email security statistics for 2026 - covering phishing and BEC losses, breaches that start with email, DMARC and spoofing, malware delivery, employee behavior, and the cost of getting it wrong - with what each one means for how you protect and deliver your email.
Key takeaways
- US victims reported a record $16.6 billion in cybercrime losses in 2024, up 33% year over year.
- Business Email Compromise alone caused $2.77 billion in losses across 21,442 complaints in 2024.
- Phishing and pretexting by email account for 73% of social-engineering incidents, and phishing was the initial vector in 15% of breaches.
- Only 20% of the top 10 million domains had a DMARC record as of September 2024 - though enforced DMARC stops an estimated 90% of spoofing.
- Users click a phishing link in a median 21 seconds and submit their data 28 seconds after that.
- The global average cost of a data breach reached $4.88 million in 2024, a record high.
Phishing and BEC: the losses
1. US victims reported a record $16.6 billion in cybercrime losses in 2024
The FBI's Internet Crime Complaint Center logged a record $16.6 billion in reported cybercrime losses in 2024, up 33% from the prior year. Email-borne attacks - phishing, spoofing, and BEC - sit at the center of that total, which is why hardening the inbox is a financial decision, not just a technical one.
2. Business Email Compromise caused $2.77 billion in losses across 21,442 complaints
BEC remains the single most expensive email threat: in 2024 it drove $2.77 billion in losses across 21,442 complaints. These attacks rarely carry malware - they rely on a trusted-looking sender and a plausible request, which is exactly the gap that domain authentication closes.
3. Proofpoint detects about 66 million targeted BEC attacks every month
The scale is relentless. Proofpoint reports detecting roughly 66 million targeted BEC attacks per month. This is not a rare, sophisticated event aimed at a few enterprises - it is a constant, high-volume tide that every sending domain has to defend against.
4. Phishing and spoofing drew 193,407 FBI complaints as losses jumped 274%
Phishing and spoofing generated 193,407 complaints in 2024, with associated losses jumping 274% to $70 million. The complaint count is high and the loss-per-incident is climbing fast - attackers are getting more effective, not less.
5. Brand impersonation is used in more than 80% of spear-phishing attacks
Barracuda found brand impersonation appears in more than 80% of spear-phishing attacks. Attackers succeed by wearing a trusted name - often yours. A published, enforced DMARC policy is what stops criminals from forging your domain in the first place.
Check whether your domain is protected against spoofing →
Breaches that start with email
6. 68% of breaches involved a non-malicious human element
Verizon's 2024 DBIR found 68% of breaches involved a non-malicious human element such as social engineering or a simple error. Most breaches do not begin with a zero-day exploit - they begin with a person who was tricked, usually over email.
7. Phishing was the initial vector in 15% of data breaches in 2024
IBM's analysis found phishing was the initial access vector in 15% of data breaches, second only to stolen credentials - which are themselves frequently harvested through phishing emails. Email sits behind a large share of breaches even when it is not the label on the report.
8. Phishing and pretexting by email were 73% of social-engineering incidents
Within social engineering, the DBIR attributes 73% of incidents to phishing and pretexting delivered by email. When an organization is manipulated into a breach, email is overwhelmingly the medium the manipulation travels through.
DMARC and the spoofing gap
9. Only 20% of the top 10 million domains had a DMARC record
Valimail found that as of September 2024, only about 20% of the top 10 million domains published a DMARC record. Four in five major domains still leave the door open to exact-domain spoofing - a striking gap given how cheap the fix is.
10. Google and Yahoo's rules drove 500,000+ domains to publish DMARC
The 2024 sender requirements had a measurable effect: Valimail reports more than 500,000 additional top-10-million domains published DMARC by February 2024. When mailbox providers made authentication a condition of delivery, adoption jumped - proof that security and deliverability incentives pull in the same direction.
11. DMARC stops an estimated 90% of spoofing attacks
An enforced DMARC policy is one of the highest-leverage controls available: Valimail estimates it stops about 90% of spoofing attacks. The catch is enforcement - a record at p=none monitors but does not block. Sendaloft configures SPF, DKIM, and DMARC and moves the policy to enforcement so your domain is actually protected.
Run a free authentication and inbox placement test →
Malware and ransomware delivered by email
12. A malicious email bypassed secure gateways every 57 seconds
Cofense found a malicious email slipping past a secure email gateway every 57 seconds, a 104.5% year-over-year increase. Gateways catch a great deal, but the ones that get through arrive constantly - defense cannot stop at the perimeter filter.
13. Cofense found 1.5 million-plus malicious emails bypassing gateways in two years
Over a two-year window, Cofense identified more than 1.5 million malicious emails that bypassed secure email gateways. The volume that evades automated filtering is enormous, which is why authentication and user reporting have to backstop the gateway.
14. 69% of organizations suffered a successful ransomware infection in the past year
Proofpoint found 69% of organizations experienced a successful ransomware infection in the past year. Ransomware overwhelmingly enters through email - a malicious attachment or link - making the inbox the front line of ransomware defense.
15. Phishing made up 43.3% of email attacks and malicious URLs 30.5%
Across roughly 45 billion emails analyzed, Hornetsecurity found phishing accounted for 43.3% of email attacks and malicious URLs for 30.5%. Together, link-based and impersonation attacks dominate the threat mix - the payload is increasingly a click, not just an attachment.
16. HTML files are the most common malicious attachment at 37.1%
Hornetsecurity found HTML files are the most common malicious attachment at 37.1%, ahead of PDFs at 23.3%. Attackers favor HTML because it renders convincing fake login pages and evades signature-based scanning - a reminder that "it's just an HTML file" is not reassurance.
Employee click and report rates
17. Users click a phishing link in a median 21 seconds and submit data 28 seconds later
Verizon's DBIR clocked the speed of compromise: users click a phishing link in a median of 21 seconds and submit data 28 seconds after that. Under a minute separates a delivered phish from stolen credentials - too fast for human review to intervene, which is why prevention has to happen before the message lands.
18. In simulations, only 20% reported the phish without clicking
Phishing simulations paint a sobering picture: only 20% of users reported the phish without clicking, and just 11% reported it after clicking. The overwhelming majority neither report nor resist - security teams cannot rely on human vigilance alone.
19. 71% of working adults admitted taking a risky action
Proofpoint found 71% of working adults admitted to a risky action such as reusing passwords or clicking unknown links. Risky behavior is the norm, not the exception, which is why technical controls that stop the malicious mail from arriving matter far more than awareness slogans.
20. Credential phishing volume rose 67% year over year
Cofense measured credential phishing volume rising 67% year over year. Attackers are concentrating on stealing logins - the same stolen credentials that top the breach-vector charts - and email is their delivery mechanism of choice.
The cost of email attacks
21. The global average cost of a data breach reached $4.88 million in 2024
IBM's 2024 report put the global average breach cost at $4.88 million, up about 10% year over year and a record high. Given that phishing and stolen credentials lead the vector list, email hardening is one of the most direct levers on this number.
22. Breaches taking 200+ days to contain cost nearly $5.5 million
IBM also found breaches that take more than 200 days to identify and contain cost nearly $5.5 million on average. The slower an email-driven intrusion is caught, the more it costs - and stopping the initial phish is far cheaper than the months-long cleanup that follows.
What this means: the email security playbook
Authenticate your domain, then enforce it. DMARC at an enforcing policy stops roughly 90% of spoofing, yet only about 20% of top domains even publish a record and most that do sit at p=none. A monitoring-only policy earns no protection. Get SPF, DKIM, and DMARC aligned and move DMARC to p=quarantine or p=reject so attackers cannot forge your domain in the brand-impersonation attacks that drive most spear-phishing.
Treat authentication as a deliverability control, not just a security one. The same DNS records that block spoofing are what Gmail and Yahoo use to decide whether your real mail reaches Primary. When Google and Yahoo made authentication mandatory, 500,000+ domains added DMARC almost overnight - because security and inbox placement are enforced by the same gatekeepers. Fixing one fixes the other.
Assume the malicious mail will get through. A phish bypasses secure gateways every 57 seconds, and Cofense counted 1.5 million-plus that slipped past in two years. Gateways are necessary but not sufficient. Layer authentication, monitoring, and fast user reporting so the messages that evade the filter still hit a wall - and so your own domain is not the one being impersonated.
Do not rely on employees to catch it. Users click in a median 21 seconds and submit data 28 seconds later, only 20% report a phish without clicking, and 71% admit to risky behavior. Human vigilance is real but too slow and too rare to be the primary control. The highest-leverage move is preventing the malicious and spoofed mail from arriving at all.
Count the cost, then close the cheapest gap first. The average breach now costs $4.88 million, and slow-to-contain incidents near $5.5 million - with phishing and stolen credentials leading the way in. Authentication is close to free by comparison. Before you scale sending, test your domain's authentication and inbox placement so you close the spoofing gap while it is still just a DNS change.