Phishing Statistics by Attack Stage
Phishing statistics become misleading when every number is treated as a count of successful attacks. A detected website, a delivered message, a submitted complaint, a stolen credential, and a confirmed breach describe different stages. One campaign can generate many observations across those stages without producing a one-to-one relationship between them.
For a security team, the practical question is where the evidence sits in that sequence. Site observations can describe attacker infrastructure detected by a source. Complaint data can describe reported experiences. Confirmed disclosure data concerns a narrower outcome. Those measures should not be combined into a conversion funnel unless the underlying events are linked.
APWG’s second-quarter 2026 report and the FBI’s 2025 complaint data illustrate the distinction. They provide useful observations, but they do not reveal how many recipients moved from a message to a click, a compromised account, and a breach.
Key Statistics and Data
The findings below use different units and periods. Their scope should remain visible whenever they are quoted.
- April site observations: APWG reports 325,934 phishing sites for April 2026.
- May site observations: The report gives 317,940 for May 2026.
- June site observations: The report gives 425,808 for June 2026.
- Brand targeting: APWG reports 941 brands targeted during the quarter. A brand count is not a count of victims or compromised companies.
- Complaint reporting: The FBI’s 2025 IC3 report records 191,561 phishing/spoofing complaints, a separate complaint-based measure for a different period.
Understand What a Phishing Site Count Represents
APWG’s observed phishing sites are based on its report’s URL-oriented measurement. The monthly figures describe observed sites, not messages sent, inboxes reached, people deceived, or accounts compromised.
| Month | Reported Phishing Sites | Counting Unit |
|---|---|---|
| April 2026 | 325,934 | Sites under APWG’s stated method |
| May 2026 | 317,940 | Same monthly measure |
| June 2026 | 425,808 | Same monthly measure |
The report contains a small reconciliation issue: the three monthly figures sum to 1,069,682, while the stated quarterly total is 1,069,681. This article uses the monthly observations and does not rely on the conflicting aggregate or calculate growth from it.
That discrepancy does not justify silently correcting the source. A reader should be able to distinguish the publisher’s reported figures from arithmetic performed by an editor. Keeping the monthly values intact and explaining the conflict preserves that distinction.
The 941-brand figure supplies another dimension: the number of brands targeted within the report’s scope. It does not establish that each brand’s own systems were breached. Brand impersonation and compromise of the impersonated organization are different events.
Use site observations to discuss observed infrastructure and coverage, with the method attached. Do not translate the count into a number of employees exposed or a probability that a message will succeed. Those questions require additional evidence at later stages.
Place Each Measure at the Correct Attack Stage
A stage map helps explain why apparently similar phishing totals differ. It also identifies which internal evidence a team needs to assess its own controls.
| Stage | Example Measure | What It Can Establish |
|---|---|---|
| Infrastructure observed | Detected phishing sites or URLs | Observations within a source’s detection method |
| Message delivered | Messages reaching a defined mail population | Delivery within the monitored environment |
| User interaction | Recorded interaction with a message or destination | The defined interaction, subject to collection limits |
| Credential or session compromise | Verified unauthorized access evidence | Compromise of the investigated identity or session |
| Confirmed disclosure | Evidence of unauthorized data disclosure | A breach under the source’s definition |
| Complaint submitted | Report filed with a reporting system | A submitted complaint, not necessarily a unique attack |
The rows are conceptual stages, not a measured funnel built from the cited reports. A site count from one source and a complaint count from another do not supply the numerator and denominator for an attack-success rate.
The distinction between confirmed breaches and exposed records matters at the later stages. A compromised account does not automatically establish disclosure of a known number of records. That determination requires evidence about what was accessed and what the applicable source counts.
Phishing statistics are more useful when they identify the stage explicitly. A chart labeled “attacks” may appear simple, but it obscures whether the team is discussing infrastructure, interaction, compromise, or impact.
Read Complaint Data as Reported Experience
The FBI’s reported complaints and losses include 191,561 phishing/spoofing complaints in the 2025 report. This is a category in a complaint system, not a count of every phishing message or every successful compromise.
The period differs from APWG’s second-quarter 2026 observations. The counting unit differs as well. Dividing one figure by the other would not produce a meaningful conversion rate, even if both concerned the same calendar period, because the reports do not link the underlying events.
Complaint data can still help explain the scale of reported concern under a defined category. It can also support careful comparison within the report when the definitions permit it. The key is to avoid expanding the claim beyond the reporting system’s scope.
For internal reporting, distinguish employee reports from confirmed incidents. A rise in employee reporting can reflect greater awareness or easier reporting rather than a proportional increase in successful attacks. Record the disposition of reports so the organization can understand both reporting activity and investigated outcomes.
The team should also preserve duplicate handling rules. Several employees may report the same campaign, and one employee may submit several related messages. Decide whether an internal metric counts submissions, unique messages, campaigns, or investigated events, then keep that unit consistent.
Connect the Stages to Controls
Different controls act at different points in the sequence. A control intended to reduce message delivery should be evaluated on relevant delivery evidence. A control intended to limit account misuse needs access and session evidence. A control intended to reduce disclosure needs data-access and containment evidence.
Verizon’s incident and breach counts provide broader event context, but they do not establish the effectiveness of a specific control in your environment. The required test should follow the action the control is supposed to prevent, detect, or contain.
For an identity-related review, define the account types, authentication paths, and downstream applications involved. Include employee changes and exception handling. Employee access changes can affect whether old entitlements or sessions remain relevant after a role change or departure, so central account status should not be the only evidence reviewed.
For an investigation workflow, define who receives a report, who evaluates it, and what triggers escalation. A reporting button is useful only if the resulting queue has an owner and a process. Measure whether reports are reviewed and acted upon under the organization’s intended operating model.
These are editorial control-review recommendations, not claims that a particular product guarantees protection. The value comes from matching the control, the evidence, and the stage of the event.
Build an Internal Measurement Plan
A useful measurement plan starts with a small number of questions. Are relevant messages being detected? Are employees able to report suspicious activity? Can the team distinguish an interaction from a compromise? Can it determine whether protected information was accessed?
For each question, record the data source, counting unit, scope, and owner. Document how duplicates are handled and which observations are excluded. This makes the resulting dashboard easier to interpret when tools or collection methods change.
| Internal Question | Measurement Design Requirement |
|---|---|
| How much suspicious activity is reported? | Define whether the unit is a submission, message, or campaign |
| How quickly is it investigated? | Define the start, end, exclusions, and responsible queue |
| How many cases involve compromise? | Require a consistent evidence threshold and case disposition |
| What information was affected? | Separate confirmed access or disclosure from unresolved exposure |
| Did the control improvement work? | Compare the intended behavior under consistent test conditions |
Avoid choosing a metric solely because the tool exports it easily. A large volume of blocked messages may be useful operational evidence, but it does not by itself describe the residual risk to a critical business process. A low click count may omit other interaction paths or collection limits.
The wider sector and company-size comparisons can frame external context. Your internal measurement plan should remain grounded in the systems, identities, and services the organization operates.
Interpret Trends Without Losing the Denominator
A change in a reported count can reflect a change in activity, visibility, coverage, classification, or reporting behavior. Before describing improvement or deterioration, establish which of those changed during the comparison period.
If a new source adds more monitored mailboxes, the count may rise even when the rate within the original population stays similar. If the team changes duplicate handling, a campaign count may fall without a corresponding change in message volume. If a reporting process becomes easier, employee submissions may increase while investigation quality improves.
Keep those changes in the reporting record. A short note beside the chart can prevent a misleading executive interpretation. Where the populations cannot be reconciled, show the periods separately rather than forcing a continuous trend line.
The same rule applies to external phishing statistics. Edition changes, revised definitions, and source inconsistencies need to be considered before calculating growth. An attractive chart is not worth a comparison that the underlying data cannot support.
Use the Evidence to Improve a Specific Stage
The strongest use of phishing statistics is to locate the evidence and then choose an action appropriate to that stage. APWG’s monthly site observations concern infrastructure detected under its method. IC3’s figure concerns submitted phishing/spoofing complaints. Confirmed breaches require their own evidence.
Choose one stage where your organization lacks clarity. It may be report triage, investigation disposition, downstream access, or confirmation of affected information. Assign an owner and define the evidence that would demonstrate improvement.
A stage-specific review produces a more useful outcome than a single global “phishing risk” number assembled from unrelated reports. It tells the team what it knows, what it still needs to establish, and which control or process should change next.
For example, a team may receive many reports about one impersonation campaign. Counting each employee submission is appropriate for measuring reporting workload, while grouping the related messages may be appropriate for measuring investigated campaigns. Neither count is inherently wrong. The error occurs when the report changes units without telling the reader.
A useful dashboard can show both measures with clear labels and then add the investigation disposition. That allows managers to see the volume the team handled and the number of distinct cases it assessed. If a case involves verified compromise, it can move into the appropriate incident process without rewriting every earlier submission as a successful attack. The measurement then supports staffing, control review, and investigation while preserving the meaning of each stage.
Keep the review focused on a decision that can change. A useful action has an accountable owner, a defined completion condition, and evidence that the intended behavior works. Revisit the result when the service or measurement scope changes, rather than treating the first review as permanent assurance.
Frequently Asked Questions
These answers clarify the different units used to measure phishing activity.
Are Phishing Sites the Same as Phishing Emails?
No. A site or URL observation describes infrastructure under the source’s method. A message count describes communication attempts within a defined collection scope. One site may be associated with many messages, and the cited report does not provide a universal conversion between them.
Why Is the Quarterly APWG Total Not Used?
The monthly figures sum to one more than the stated quarterly total. The article preserves the individual monthly observations and discloses the inconsistency. It does not silently repair the source or use the conflicting aggregate for a growth calculation.
Can Complaints Be Divided by Site Counts to Estimate Success?
No. The cited figures concern different periods, populations, and counting units. The underlying events are not linked. A success rate requires a defined population followed through the relevant stages, with consistent rules for duplicates and outcomes.
What Is the Most Useful Internal Phishing Metric?
It depends on the decision. Reporting, investigation, compromise, and disclosure require different measures. Choose a defined stage and a clear denominator. These figures are most useful when they support a specific operational question rather than an undefined total of “attacks.”
Resources
APWG’s Q2 2026 report supplies the monthly site figures and brand count. The FBI’s 2025 IC3 report supplies the phishing/spoofing complaint count. Verizon’s 2026 DBIR executive summary supplies event-definition context. Each source is linked at its substantive use.
