Phishing has existed for more than 20 years. Email filtering has improved, security training is widespread, and multi-factor authentication is common. Yet, phishing remains a critical threat, with the 2025 Verizon Data Breach Investigations Report showing that approximately 60% of all confirmed breaches involved a human element, whether through phishing, social engineering, error, or misuse, and 16% of breaches began with phishing.
The reason is simple. Phishing does not rely on breaking systems. It relies on persuading people. That advantage has not disappeared and, in many cases, has grown. For most organizations, the practical win is tightening the basics to reduce the likelihood of believable inbox impersonation, which is why email security best practices and DMARC enforcement should be treated as ongoing operational work rather than a one-time project.
The Scale of Phishing
Phishing remains one of the highest-volume cyber threats globally.
- 3.4 billion phishing emails are sent every day.
- The median phishing simulation click-through rate has plateaued at approximately 1.5%, despite continuous awareness training.
- User reporting increased 4x after training, demonstrating that detection matters as much as prevention.
Financial impact continues to rise. Because many phishing campaigns are designed to trigger real-money actions, connect yourwire transfer fraud prevention process to your MSP cybersecurity incident response plan. The U.S. Federal Trade Commission reported that consumers lost $12.5 billion to fraud in 2024, a 25% increase over the prior year. This figure includes all types of fraud, with imposter scams (often delivered via phishing) accounting for $2.95 billion in losses. These figures reflect only reported incidents. Many organizations and individuals never disclose losses.
Even organizations with mature email security face persistent threats. Attack volumes continue to rise, with credential phishing attacks surging 703% in the second half of 2024. Filtering reduces volume, but sophisticated attacks continue to bypass defenses.
Why Phishing Continues to Work
Phishing Exploits Human Decision Making
Phishing targets predictable human behavior rather than technical weaknesses. Attackers succeed by triggering fast decisions under uncertainty.
Common tactics include:
- Artificial urgency that discourages verification
- Impersonation of authority figures or trusted brands
- Promises of rewards or warnings of loss
Under time pressure, people rely on fast, automatic judgment rather than deliberate analysis. This response is normal and consistent across roles, experience levels, and industries. The Verizon 2025 DBIR found that it takes a median of only 21 seconds for a user to click a malicious link, and another 28 seconds to enter personal data.
Familiarity and Context Increase Credibility
Messages that align with expected events are harder to question. Package deliveries, payment issues, system updates, tax notices, and internal requests all fit normal work patterns. Attackers time campaigns to match these expectations.
New employees, remote workers, and teams undergoing change face a higher risk because normal communication patterns are still forming or temporarily disrupted.
Overconfidence Reduces Scrutiny
Multiple studies show that people consistently overestimate their ability to spot phishing. This confidence reduces verification behavior and increases reliance on intuition, even among technical professionals.
Phishing Has Become More Sophisticated
AI Has Improved Quality and Scale
AI tools allow attackers to:
- Write error-free, natural language messages
- Personalize emails using public data
- Adjust tone, timing, and structure rapidly
While current research shows that under 5% of phishing attacks that bypass email filters are AI-written, with some studies showing 12% of caught phishing emails are AI-generated, the total volume of phishing attacks has increased by 4,151% since ChatGPT’s launch in 2022. AI-generated attacks show higher engagement rates and are becoming increasingly sophisticated.
Attacks Now Span Multiple Channels
Email remains the primary vector, accounting for 25% of fraud reports when a contact method was identified. However, attackers increasingly use multiple channels:
- SMS and messaging apps
- Collaboration tools such as Teams and Slack
- Social and professional platforms like LinkedIn
- QR codes that hide destination URLs
Using multiple channels increases trust and bypasses single-control defenses.
MFA Is No Longer a Hard Stop
Multi-factor authentication reduces risk but does not eliminate phishing. Adversary-in-the-middle (AiTM) phishing attacks increased 146% in 2024. Attackers capture session tokens after MFA completes, not just passwords.
Consent phishing also bypasses MFA by tricking users into authorizing malicious applications through legitimate OAuth flows. The Verizon 2025 DBIR found that prompt bombing occurred in 14% of social engineering incidents, in which users are bombarded with MFA login requests.
Why Attackers Keep Winning
The Economics Favor Phishing
Phishing is inexpensive to launch and easy to scale.
- Email lists cost a few dollars per thousand addresses
- Infrastructure is disposable and cheap
- Phishing-as-a-Service platforms cost less than many consumer tools
Even a 1-2% success rate produces returns at scale. Because so many phishing campaigns ultimately aim to capture and reuse credentials, consistent password management best practices reduce the blast radius when a click happens and limit how far attackers can go with what they steal.
The Verizon 2025 DBIR found that 22% of breaches began with credential abuse, and 88% of Basic Web Application attacks involved stolen credentials.
Enforcement remains limited. Most attackers face a low risk of identification or prosecution, especially across borders.
Defensive Models Lag Behind Attacker Speed
- Email-based threats rose by 202% in the latter half of 2024
- Training effectiveness shows a behavioral floor; the median click rate plateaus around 1.5% despite continuous training
- Detection often occurs after the click, not before
Perfect prevention is unrealistic when decisions are made by people under pressure.
What This Means in Practice
Phishing persists because it exploits human behavior, adapts quickly, and remains profitable. Organizations that assume phishing will be eliminated are planning incorrectly.
Effective strategies assume:
- Some users will click
- Detection must be fast
- Reporting must be easy and safe
- Damage must be contained quickly
Reducing impact matters more than expecting perfect avoidance. User reporting increased 4x after training, demonstrating that empowering users to detect and report threats is as critical as preventing initial clicks.
FAQ
Why does phishing still work despite better tools?
Because it targets human judgment rather than software vulnerabilities.
Is phishing mostly unsophisticated spam?
No. Most volume is simple, but high-impact attacks are targeted and well-crafted.
Does MFA stop phishing?
It helps, but attackers now bypass MFA using session hijacking and consent abuse.
Is security training enough?
Training improves awareness, but behavior degrades without reinforcement and support for reporting.
What reduces phishing damage most effectively?
Fast reporting, rapid containment, and limiting access after compromise.




