Insights · Security data
How many phishing emails are sent daily?
About 3.4 billion phishing emails are sent worldwide every day — roughly 1% of all email, or around 39,000 every second. Here are the email-phishing statistics that matter for 2026, with sourced numbers and our own derived analysis.
Last updated: July 15, 2026 · Figures are cited from the sources listed at the end.
- ~3.4 billion phishing emails are sent every day (Valimail)
- That is about 1% of all email — roughly 1 in every 100 messages noKYCme analysis
- ~39,000 phishing emails are sent every second noKYCme analysis
- ~1.24 trillion phishing emails are sent per year noKYCme analysis
- 347 billion emails are sent worldwide every day (2023), rising to a projected 392 billion by 2026 (Radicati / Statista)
- Phishing was the most-reported cybercrime to the FBI in 2023, with 298,878 complaints (FBI IC3)
- Business email compromise caused $2.9 billion in reported losses in 2023 (FBI IC3)
- That is about $135,000 per reported BEC incident noKYCme analysis
- The average data breach costs $4.88 million, with phishing among the most common entry points (IBM, 2024)
- People take a median of just 21 seconds to click a phishing link (Verizon DBIR, 2024)
Email is still the world's favourite attack channel — and phishing is the payload. Below we pull together the most reliable numbers on email phishing, then do what most stat pages don't: derive our own figures from them so you can see the scale in human terms.
3.4 billion phishing emails are sent every day — about 1% of all the email on earth.
How many phishing emails are sent every day?
About 3.4 billion phishing emails are sent worldwide every single day — a figure widely cited by email-security vendors such as Valimail. Scaled out, that is roughly 1.24 trillion phishing emails a year, or around 39,000 every second of every day.
Spread across the world's ~5.5 billion internet users, that is about 226 phishing emails aimed at the average internet user each year — and far more for anyone whose address has leaked into breach databases, where the bulk of targeting happens.
3.4 billion per day ÷ 86,400 seconds ≈ 39,000 phishing emails per second; × 365 ≈ 1.24 trillion per year. These are derived from the daily figure, not separately sourced — the point is to make an abstract "billions" number legible.
Phishing by the clock
| Time window | Phishing emails sent |
|---|---|
| Per second | ~39,000 |
| Per minute | ~2.36 million |
| Per hour | ~142 million |
| Per day | ~3.4 billion |
| Per year | ~1.24 trillion |
noKYCme analysis, derived from the 3.4 billion/day figure (Valimail).
What share of all email is phishing?
Roughly 1% of all email is phishing — about 1 in every 100 messages. Around 3.4 billion phishing emails go out each day against a global total of about 347 billion emails sent and received per day, so phishing is a small fraction of volume but an outsized share of risk.
Crucially, "sent" is not "seen": modern spam filters catch the overwhelming majority before they reach an inbox. The 1% is the pressure on the front door — a much smaller share actually gets through, and a smaller share still is clicked.
3.4 billion phishing ÷ ~347 billion total emails per day ≈ 0.98%, which we round to about 1%, or 1 in 100. Because "phishing sent" and "total email" come from different sources measuring different things, treat this as an order-of-magnitude ratio, not a precise share.
How much email is sent worldwide each day?
About 347 billion emails were sent and received every day in 2023, and that is forecast to reach roughly 392 billion by 2026. The email attack surface keeps growing — more messages, more accounts, more chances for one convincing fake to land.
| Year | Emails sent/received per day | YoY change |
|---|---|---|
| 2020 | 306.4 billion | — |
| 2021 | 319.6 billion | +4.3% |
| 2022 | 333.2 billion | +4.3% |
| 2023 | 347.3 billion | +4.2% |
| 2024 | 361.6 billion | +4.1% |
| 2025* | 376.4 billion | +4.1% |
| 2026* | 392.5 billion | +4.3% |
* projected. Source: Radicati Group / Statista.
* projected. Source: Radicati Group / Statista.
Across 2020-2026 that is a compound annual growth rate of about 4.2% — steady, not explosive, but every extra billion messages is more cover for phishing to hide in.
How many phishing attacks are reported each year?
Phishing was the single most-reported cybercrime to the FBI in 2023, with 298,878 complaints — more than any other category. Reported complaints understate the real total (most victims never file), but the trend is unmistakable.
| Year | FBI-reported phishing complaints | YoY change |
|---|---|---|
| 2019 | 114,702 | — |
| 2020 | 241,342 | +110% |
| 2021 | 323,972 | +34% |
| 2022 | 300,497 | −7% |
| 2023 | 298,878 | −1% |
Source: FBI Internet Crime Complaint Center (IC3) annual reports.
Source: FBI Internet Crime Complaint Center (IC3).
Reported phishing complaints grew +160% from 2019 to 2023, but the story splits in two: an explosive +182% surge in 2019-2021, then a slight −8% drift in 2021-2023. That decline is almost certainly reporting fatigue and better filtering of obvious scams — not fewer attacks, which every "emails sent" and "losses" measure shows still rising.
How much does email phishing cost?
Business email compromise alone caused $2.9 billion in reported losses in the US in 2023 — and that is just one flavour of email phishing, aimed at tricking companies into wiring money or changing payment details.
Business email compromise caused $2.9 billion in reported losses in 2023 — roughly $135,000 per incident.
| Year | Reported BEC losses | YoY change |
|---|---|---|
| 2020 | $1.87 billion | — |
| 2021 | $2.40 billion | +28% |
| 2022 | $2.74 billion | +14% |
| 2023 | $2.90 billion | +6% |
Source: FBI IC3 annual reports.
With 21,489 BEC complaints behind $2.9 billion in 2023, the average reported loss is about $135,000 per incident — an order of magnitude larger than consumer scams, because BEC targets the finance team, not the individual. Zoom out and the average data breach costs $4.88 million (IBM, 2024), with phishing among the most common and expensive ways in.
What share of cyberattacks start with a phishing email?
The vast majority begin with email. Phishing is consistently the most-reported cybercrime, email is the leading delivery channel for malware and credential theft, and the "human element" — overwhelmingly phishing and stolen passwords — is involved in roughly two-thirds of all breaches (Verizon DBIR, 2024). It is why "90%+ of attacks start with phishing" has become a security cliché: the exact figure varies by study, but the direction never does.
How quickly do people fall for phishing emails?
People take a median of just 21 seconds to click a link in a phishing email, and only about 28 seconds more to enter their data — so under a minute from opening the message to handing over credentials (Verizon DBIR, 2024). Awareness training helps, but the speed is the point: phishing works because it is fast, familiar, and arrives looking like something you were already expecting.
People take a median of just 21 seconds to click a link in a phishing email.
Which brands are most impersonated in phishing emails?
Microsoft is consistently the most impersonated brand in phishing, followed by the other services people log into every day — Google, Apple, Amazon, LinkedIn and major banks. Attackers impersonate whatever login you will click without thinking; the quarterly ranking shifts, but the tactic (borrow a trusted brand, ask you to "verify" your account) does not.
Email, text or voice — where does phishing happen most?
Email is still by far the dominant phishing channel, but "smishing" (SMS text phishing) and "vishing" (voice phishing) are growing quickly as life moves to mobile. Email wins on sheer scale and cost — a single campaign can hit millions of inboxes for almost nothing — while text and phone attacks trade volume for a higher hit rate, because a text feels more personal and a phone call more urgent. The mechanics are identical across all three: impersonate something you trust, and manufacture urgency so you act before you think.
For businesses, the most expensive variant remains email-based business email compromise, because it targets the person who can move money. For individuals, the fastest-growing pain is smishing — but the inbox is still where the most attacks, and the most stolen credentials, begin.
Is AI making phishing worse?
Yes — generative AI has erased the two things that used to give phishing away: broken grammar and generic wording. Attackers now use large language models to write flawless, native-sounding emails and to personalise them at scale from scraped or breached data, and security vendors have reported steep rises in both the volume and the polish of phishing since late 2022.
The practical fallout is that "look for spelling mistakes" is dead as advice. What still works is technical and structural: multi-factor authentication and passkeys so a stolen password is not enough; strong filtering; and — the theme of this whole site — holding as little personal data as possible, so a convincing fake has less to unlock and a breach has less to leak.
How do we know these numbers? (methodology)
The single biggest reason phishing statistics disagree is that they count different things at different stages of the funnel. Four common figures measure four different realities:
| Metric | What it actually counts | Typical figure | Source |
|---|---|---|---|
| Emails sent / day | Phishing messages attempted (most get filtered) | ~3.4 billion/day | Valimail |
| Attacks / year | Detected phishing campaigns & URLs | ~5 million/year | APWG |
| Complaints / year | Victims who actually reported it | ~299,000 (2023) | FBI IC3 |
| Losses / year | Reported money lost (BEC) | $2.9 billion (2023) | FBI IC3 |
So "3.4 billion a day" (attempts) and "299,000 a year" (reported victims) are both correct — they sit at opposite ends of the same funnel: attempts → delivered → clicked → reported. Any page that presents them as competing figures is measuring the wrong thing. We keep them separate and label what each one is.
Why this matters for privacy. Every phishing email is an attempt to harvest an identity — a login, a card, an account. The less personal data a service holds about you in the first place, the less there is to steal or hand over. That is the whole case for identity-minimal, no-KYC services: fewer credentials on file, fewer things to phish. See our audited no-KYC VPNs and the methodology.
FAQ
Email phishing — common questions.
How many phishing emails are sent every day?
About 3.4 billion phishing emails are sent worldwide every day, according to figures widely cited by email-security vendors such as Valimail. That works out to roughly 1% of all email, around 39,000 phishing messages every second, and about 1.24 trillion phishing emails a year.
What percentage of email is phishing?
Roughly 1% of all email is phishing — about 1 in every 100 messages. Around 3.4 billion phishing emails are sent each day against a total of about 347 billion emails sent worldwide per day. Most are stopped by spam filters before they ever reach an inbox.
Is phishing increasing or decreasing?
The long-term trend is sharply up. FBI-reported phishing complaints rose from 114,702 in 2019 to 298,878 in 2023 — a 160% increase — though reported complaints dipped slightly after a 2021 peak, largely a reporting effect rather than fewer attacks.
How much does email phishing cost?
Business email compromise (BEC), a targeted form of email phishing, caused $2.9 billion in reported losses in the US alone in 2023 — about $135,000 per reported incident. The average cost of a data breach is $4.88 million, and phishing is one of the most common and costliest initial attack vectors.
What share of cyberattacks start with a phishing email?
The large majority. Email is the top delivery channel for attacks, phishing is consistently the most-reported cybercrime, and the human element (mostly phishing and stolen credentials) is involved in roughly two-thirds of all breaches.
How quickly do people fall for phishing emails?
Very quickly. According to the Verizon Data Breach Investigations Report, people take a median of just 21 seconds to click a link in a phishing email, and only about 28 seconds more to enter their data — under a minute from open to compromise.
Which brands are most impersonated in phishing?
Microsoft is consistently the most impersonated brand in phishing campaigns, followed by other services people log into every day — Google, Apple, Amazon, LinkedIn and major banks. The exact ranking shifts each quarter, but the pattern (impersonate a trusted login) does not.
Sources
Where the numbers come from.
- Valimail — phishing email volume (~3.4 billion/day) · valimail.com
- Radicati Group / Statista — worldwide email volume & forecasts · statista.com
- FBI Internet Crime Complaint Center (IC3) — Internet Crime Reports, phishing complaints & BEC losses · ic3.gov
- IBM — Cost of a Data Breach Report 2024 · ibm.com
- Verizon — Data Breach Investigations Report (DBIR) 2024 · verizon.com
- APWG — Phishing Activity Trends Report · apwg.org
Derived statistics are labelled noKYCme analysis and computed only between sourced figures — we never invent a data point.