Why Phishing Still Works and How Attackers Keep WinningHow Frequent Are Cyber Attacks

Feb 23, 2026 | Cybersecurity

Phishing has existed for more than 20 years. Email filtering has improved, security training is widespread, and multi-factor authentication is common. Yet, phishing remains a critical threat, with the 2025 Verizon Data Breach Investigations Report showing that approximately 60% of all confirmed breaches involved a human element, whether through phishing, social engineering, error, or misuse, and 16% of breaches began with phishing.

The reason is simple. Phishing does not rely on breaking systems. It relies on persuading people. That advantage has not disappeared and, in many cases, has grown. For most organizations, the practical win is tightening the basics to reduce the likelihood of believable inbox impersonation, which is why email security best practices and DMARC enforcement should be treated as ongoing operational work rather than a one-time project.

The Scale of Phishing 

Phishing remains one of the highest-volume cyber threats globally.

Financial impact continues to rise. Because many phishing campaigns are designed to trigger real-money actions, connect yourwire transfer fraud prevention process to your MSP cybersecurity incident response plan. The U.S. Federal Trade Commission reported that consumers lost $12.5 billion to fraud in 2024, a 25% increase over the prior year. This figure includes all types of fraud, with imposter scams (often delivered via phishing) accounting for $2.95 billion in losses. These figures reflect only reported incidents. Many organizations and individuals never disclose losses.

Even organizations with mature email security face persistent threats. Attack volumes continue to rise, with credential phishing attacks surging 703% in the second half of 2024. Filtering reduces volume, but sophisticated attacks continue to bypass defenses.

Why Phishing Continues to Work

Phishing Exploits Human Decision Making

Phishing targets predictable human behavior rather than technical weaknesses. Attackers succeed by triggering fast decisions under uncertainty.

Common tactics include:

  • Artificial urgency that discourages verification
  • Impersonation of authority figures or trusted brands
  • Promises of rewards or warnings of loss

Under time pressure, people rely on fast, automatic judgment rather than deliberate analysis. This response is normal and consistent across roles, experience levels, and industries. The Verizon 2025 DBIR found that it takes a median of only 21 seconds for a user to click a malicious link, and another 28 seconds to enter personal data.

Familiarity and Context Increase Credibility

Messages that align with expected events are harder to question. Package deliveries, payment issues, system updates, tax notices, and internal requests all fit normal work patterns. Attackers time campaigns to match these expectations.

New employees, remote workers, and teams undergoing change face a higher risk because normal communication patterns are still forming or temporarily disrupted.

Overconfidence Reduces Scrutiny

Multiple studies show that people consistently overestimate their ability to spot phishing. This confidence reduces verification behavior and increases reliance on intuition, even among technical professionals.

Phishing Has Become More Sophisticated

AI Has Improved Quality and Scale

AI tools allow attackers to:

  • Write error-free, natural language messages
  • Personalize emails using public data
  • Adjust tone, timing, and structure rapidly

While current research shows that under 5% of phishing attacks that bypass email filters are AI-written, with some studies showing 12% of caught phishing emails are AI-generated, the total volume of phishing attacks has increased by 4,151% since ChatGPT’s launch in 2022. AI-generated attacks show higher engagement rates and are becoming increasingly sophisticated.

Attacks Now Span Multiple Channels

Email remains the primary vector, accounting for 25% of fraud reports when a contact method was identified. However, attackers increasingly use multiple channels:

  • SMS and messaging apps
  • Collaboration tools such as Teams and Slack
  • Social and professional platforms like LinkedIn
  • QR codes that hide destination URLs

Using multiple channels increases trust and bypasses single-control defenses.

MFA Is No Longer a Hard Stop

Multi-factor authentication reduces risk but does not eliminate phishing. Adversary-in-the-middle (AiTM) phishing attacks increased 146% in 2024. Attackers capture session tokens after MFA completes, not just passwords.

Consent phishing also bypasses MFA by tricking users into authorizing malicious applications through legitimate OAuth flows. The Verizon 2025 DBIR found that prompt bombing occurred in 14% of social engineering incidents, in which users are bombarded with MFA login requests.

Why Attackers Keep Winning

The Economics Favor Phishing

Phishing is inexpensive to launch and easy to scale.

  • Email lists cost a few dollars per thousand addresses
  • Infrastructure is disposable and cheap
  • Phishing-as-a-Service platforms cost less than many consumer tools

Even a 1-2% success rate produces returns at scale. Because so many phishing campaigns ultimately aim to capture and reuse credentials, consistent password management best practices reduce the blast radius when a click happens and limit how far attackers can go with what they steal.

The Verizon 2025 DBIR found that 22% of breaches began with credential abuse, and 88% of Basic Web Application attacks involved stolen credentials.

Enforcement remains limited. Most attackers face a low risk of identification or prosecution, especially across borders.

Defensive Models Lag Behind Attacker Speed

Perfect prevention is unrealistic when decisions are made by people under pressure.

What This Means in Practice

Phishing persists because it exploits human behavior, adapts quickly, and remains profitable. Organizations that assume phishing will be eliminated are planning incorrectly.

Effective strategies assume:

  • Some users will click
  • Detection must be fast
  • Reporting must be easy and safe
  • Damage must be contained quickly

Reducing impact matters more than expecting perfect avoidance. User reporting increased 4x after training, demonstrating that empowering users to detect and report threats is as critical as preventing initial clicks.

FAQ

Why does phishing still work despite better tools?

Because it targets human judgment rather than software vulnerabilities.

Is phishing mostly unsophisticated spam?

No. Most volume is simple, but high-impact attacks are targeted and well-crafted.

Does MFA stop phishing?

It helps, but attackers now bypass MFA using session hijacking and consent abuse.

Is security training enough?

Training improves awareness, but behavior degrades without reinforcement and support for reporting.

What reduces phishing damage most effectively?

Fast reporting, rapid containment, and limiting access after compromise.

Temple-IT Team 

The Temple-IT team combines over 30 years of experience in delivering fully managed IT operations, enterprise-grade cybersecurity, and strategic technology leadership for growing businesses. We act as embedded technology partners rather than outsourced vendors, aligning your infrastructure and security with your business goals.

Temple IT blue graphic with a document and magnifying glass icon and the text “How to Prepare for a HIPAA Audit Without Rebuilding Your IT Environment.”

How to Prepare for a HIPAA Audit Without Rebuilding Your IT Environment

How to prepare for a HIPAA audit using existing IT systems by validating access controls, monitoring, and incident response procedures.
Temple IT blue graphic showing a tablet with security settings and the text “Understanding NIST 800-171 Controls for Small Businesses.”

Understanding NIST 800-171 Controls for Small Businesses

NIST 800-171 compliance explained for small businesses. Learn which controls matter most and how to maintain monitoring, access management, and incident response.
Temple IT blue graphic with a shield and lock icon held by hands, alongside the text “What Does a Chief Information Security Officer Do and Does Your Business Need One?”

What Does a Chief Information Security Officer Do and Does Your Business Need One?

What a Chief Information Security Officer does, how CISOs manage cybersecurity risk, and when businesses need security leadership to support compliance and operations.