Phishing has not slowed down. It has simply got better at pretending to be someone you trust. Criminals now write near-perfect emails, clone voices, and hide malicious links inside QR codes that most spam filters still can’t read. Understanding current Phishing Attack Trends matters because the tactics that fooled people five years ago look nothing like the ones catching people out today.
This guide brings together the newest UK, Irish, and global data on phishing, including how artificial intelligence has changed attacker success rates, which sectors and age groups face the highest risk, why small businesses are struggling to keep pace, and what actually happens once someone clicks. You’ll also find a practical defence checklist and answers to the questions people ask most often about phishing.
Table of Contents
Phishing Attack Trends in 2026: The Global Picture
Phishing remains the most common way criminals get into a network, a device or a bank account. Industry trackers such as the Anti-Phishing Working Group (APWG) have recorded phishing volumes climbing year on year, with 2024 setting a record high before activity stayed elevated through 2025 and into 2026.
Verizon’s 2025 Data Breach Investigations Report found phishing involved in around 15% of breaches as an initial point of entry, with social engineering as a broader category present in roughly 17% of cases, and a human element (someone clicking, replying or handing over a password) contributing to well over half of all breaches analysed.
What’s changed is not just volume. It’s quality. The table below summarises the headline figures referenced throughout this article.
| Statistic | Figure | Source |
|---|---|---|
| UK businesses hit by phishing (2025/26) | 38% | Cyber Security Breaches Survey 2025/26 |
| UK breaches rated “most disruptive” as phishing | 69% | Cyber Security Breaches Survey 2025/26 |
| Phishing emails containing AI-generated content | 82.6% | Keepnet Labs / VIPRE |
| AI-automated spear phishing click-through rate | 54% (vs 12% traditional) | Heiding, Schneier & Vishwanath study |
| UK payment fraud losses, 2025 | £1.28 billion | UK Finance Annual Fraud Report 2026 |
| Share of phishing attacks using a QR code (2025) | around 12% | Keepnet Labs |
These figures point to a threat that is broader, faster and harder to spot than the phishing of even two or three years ago, which is exactly why the sections below go beyond the headline numbers.
Volume alone doesn’t tell the whole story either. The Anti-Phishing Working Group and similar trackers count phishing incidents in the millions each year, but a growing share of those incidents are automated end-to-end: an AI model drafts the message, a scraping tool finds the target’s job title and recent activity online, and a templated landing page collects whatever the victim types in. Attackers no longer need language skills, local knowledge of a target country, or much technical ability at all. That’s a meaningful change from the phishing of a decade ago, when poor grammar and generic greetings were often the easiest way to spot a scam.
How AI Is Changing Phishing Attack Trends
The single biggest shift behind current Phishing Attack Trends is automation. Generative AI has removed the spelling mistakes and clumsy phrasing that used to give scams away, and it has made two specific attack formats far more common: QR-code phishing and voice-based impersonation.
Quishing: QR Codes as an Attack Vector
Quishing (phishing delivered through a QR code rather than a text link) has grown sharply. Keepnet Labs data puts QR codes in roughly 12% of all phishing attacks during 2025, up from under 1% in 2021, and Microsoft reported a further 146% rise in quishing volume in the first quarter of 2026 alone. The appeal for attackers is simple: a QR code is an image, not a text string, so it slips past filters built to scan for suspicious links. Because most people scan a QR code on a phone, where the full destination web address is often hidden or truncated, victims frequently can’t check where the code actually leads before they’ve already landed on a fake login page.
Deepfake Voice Phishing (Vishing)
Voice cloning tools have made vishing calls (phone-based phishing) far more convincing. A caller can now sound exactly like a company director or a family member with only a few seconds of publicly available audio to train the model. Security researchers have documented a growing number of deepfake-assisted business email compromise cases, where a cloned voice authorises a payment that a text-only scam would never have got past. This matters for the UK in particular, given how often fraudsters impersonate HMRC, banks and delivery firms by phone as well as by email.
Business Email Compromise: Where AI and Phishing Meet Finance Teams
Business email compromise (BEC) sits at the point where phishing tactics do the most financial damage. A convincing message, often reinforced by a cloned voice or a spoofed video call, asks a finance employee to change a supplier’s bank details or urgently release a payment. Because there’s no malware involved and no link to click, many technical defences never see the attack at all; it succeeds or fails purely on whether a human believes the request is genuine.
BEC losses have consistently run into the billions of dollars globally each year, and industry researchers now attribute a rising share of these messages to AI assistance, since generative tools make it easy to mimic a specific person’s writing style after reading only a handful of their genuine emails.
Phishing Attack Trends Across the UK and Ireland
Global reports rarely break out UK and Irish figures on their own, which leaves a gap that UK-specific sources fill well. The government’s Cyber Security Breaches Survey 2025/26 found that 38% of UK businesses and 25% of charities experienced a phishing attempt in the past year, and among organisations that had any kind of breach, 69% named phishing as the most disruptive type. Interviewees told researchers that phishing attacks felt easier for criminals to pull off than in previous years, largely because of how convincing AI-written messages have become.
There has also been a significant change to how phishing losses reach the authorities. Action Fraud, the UK’s long-standing reporting service, was formally replaced by Report Fraud on 4 December 2025. If your organisation’s incident response documentation, staff training materials or internal guidance still points to Action Fraud, it needs updating: Report Fraud now covers England, Wales and Northern Ireland, while people in Scotland continue to report through Police Scotland on 101.
On the financial side, UK Finance’s Annual Fraud Report 2026 recorded £1.28 billion in payment fraud losses across 2025, with authorised push payment fraud (where a victim is tricked into sending money themselves, often after a phishing message) rising 19% to £576.4 million, and around two-thirds of that fraud starting online.
Ireland’s picture is more mixed than the UK’s, which is worth stating plainly rather than assuming the trend is identical. An Garda Síochána’s provisional year-end figures for 2025 showed fraud and economic crime offences overall up 137% compared with 2024, driven mostly by deception, forgery and online shopping fraud. Reported phishing, vishing and smishing offences specifically fell by 11% over the same period, a reminder that headline fraud growth doesn’t always mean every category is getting worse. Organisations operating across both jurisdictions should treat UK and Irish data as distinct rather than interchangeable when reporting on social engineering risk to a board.
Regulatory pressure adds another reason to get this right. UK organisations handling personal data still need to consider their obligations under UK GDPR when a phishing attack leads to a data breach, including whether the incident meets the threshold for notifying the Information Commissioner’s Office. The Online Safety Act 2023 has also increased scrutiny of how platforms handle scam content shared or hosted on their services, which is gradually changing how quickly fraudulent posts and adverts get removed. None of this replaces good staff awareness, but it does mean that a phishing incident is rarely just an IT problem; it can carry compliance and reporting obligations that extend well beyond the security team.
Which Industries and Groups Are Most at Risk?
Not everyone faces the same odds. Financial services and SaaS platforms remain among the most heavily targeted sectors, largely because a single compromised login can give direct access to money or customer data. Public sector and healthcare organisations are also frequent targets, since both hold sensitive personal information and often run a mix of older and newer IT systems that’s harder to secure consistently.
Age and job role matter too. Employees in finance, HR and IT support are disproportionately targeted because they can approve payments, reset passwords or grant system access, making them useful entry points for a business email compromise attempt. Older adults remain a heavily targeted group for romance and investment-style scams that often begin with a phishing message, while younger, highly online users are more exposed to smishing and social media impersonation.
In short, the population “most vulnerable” to phishing isn’t a single group; it’s whoever holds a password, a payment authority or a public profile that a scammer can convincingly imitate, which is why current Phishing Attack Trends increasingly follow job function rather than industry alone.
Why Small and Medium-Sized Businesses Face Disproportionate Risk
Large enterprise breach reports dominate the headlines, but recent Phishing Attack Trends show SMEs carrying more of the practical burden than their size would suggest. The Cyber Security Breaches Survey 2025/26 found phishing prevalence broadly stable among the largest firms, while smaller businesses reported somewhat lower rates, not because they’re safer but because they’re less likely to have the monitoring in place to detect an attempt at all. A smaller IT team, no dedicated security analyst, and email systems configured with default settings all add up to a longer gap between a phishing email arriving and anyone noticing.
Cost also lands differently on a smaller business. A large company can often absorb a six-figure loss and keep operating. A five-person firm that loses access to its banking portal for a week, or pays an invoice to a spoofed supplier account, can be in genuine financial difficulty. Phishing is also the most common way ransomware first gets a foothold, and the impact of a successful infection on a small operation is rarely proportionate to its size.
What Happens After the Click
Most coverage of Phishing Attack Trends stops at the moment someone clicks a link. What happens in the minutes and hours afterwards matters just as much. Where an attack succeeds, credential theft is the most common outcome: recent analysis of AI-generated phishing campaigns puts the credential theft success rate at around 33.6% once a target has clicked through. From there, attackers typically move quickly to test the stolen credentials against other accounts, since password reuse means a single leaked login often opens several doors at once.
Increasingly, the real prize isn’t the password itself but the active session sitting behind it. Infostealer malware distributed through phishing emails has shifted its focus toward harvesting browser cookies and session tokens, which can let an attacker bypass multi-factor authentication entirely because the session is already authenticated. This is one reason security teams increasingly talk about the minutes immediately after a click as a genuine race against the clock, not just the moment of compromise itself. Anyone wanting to understand this shift in more depth can review current dark web trends around stolen credentials and session data.
Detection speed matters as much as prevention at this stage. The longer a stolen credential or session token sits unused before anyone notices, the more time an attacker has to explore a network, locate sensitive files, and set up a ransomware payload or a fraudulent payment before triggering any alarms. Organisations that review login activity and flag unusual locations or devices quickly tend to limit damage far more effectively than those relying on prevention alone, since no filter catches every message and no training programme achieves a zero click rate.
How to Defend Against Current Phishing Attack Trends
None of this means phishing is unstoppable. It means the basics matter more than ever, and a handful of them now matter more than they used to.
Multi-factor authentication remains one of the most effective single controls available, though it’s worth remembering it isn’t foolproof against session-token theft, which is why pairing it with monitoring for unusual login locations adds a useful second layer. Staff training works best when it’s frequent and specific rather than an annual slideshow.
The Cyber Security Breaches Survey found that only 22% of UK businesses had tested staff with mock phishing exercises in the past year, which leaves considerable room for improvement. Technical controls such as SPF, DKIM and DMARC email authentication reduce the chance that a spoofed domain reaches an inbox at all, and modern email filtering can catch a meaningful share of AI-generated phishing before a human ever sees it.
For individuals, a password manager reduces the damage a single successful phish can do, since reused passwords are what let one stolen login open several accounts. Our digital security checklist covers the practical steps in more detail. If you receive a suspicious email in the UK, forward it to the National Cyber Security Centre’s Suspicious Email Reporting Service rather than simply deleting it; reported scams are analysed and, where possible, taken down, which helps protect the next person the same email is sent to.
If you’ve spotted a phishing trend in your own inbox that isn’t covered here, or you’d like a topic added to a future update of this guide, let us know in the comments below. Understanding current Phishing Attack Trends is only useful if the information stays current, and reader reports of new scam formats help keep this page accurate for everyone who reads it after you.
Frequently Asked Questions
How common is phishing?
Phishing is the most frequently reported cyber attack type in the UK. The Cyber Security Breaches Survey 2025/26 found 38% of UK businesses and 25% of charities had experienced a phishing attempt in the past 12 months, more than any other attack category measured.
What are the latest trends in phishing attacks?
The clearest current Phishing Attack Trends are the use of generative AI to write more convincing messages, a sharp rise in QR-code phishing (quishing), and growing use of voice cloning in vishing calls. Together, these have pushed click-through rates on the best AI-generated attacks close to the level achieved by skilled human scammers.
How many phishing emails are sent each day?
Estimates vary by source and methodology, but industry figures commonly cite billions of phishing emails sent each day globally, with a large and growing share now containing AI-generated text.
Is phishing one of the most common cyber attacks?
Yes. Across UK government survey data and multiple international breach reports, phishing consistently ranks as either the most common or the most disruptive attack type organisations face.
How successful are phishing attacks?
Success rates vary hugely by attack quality. Generic, mass-sent phishing converts at around 12%, while AI-automated, personalised attacks have reached click-through rates of roughly 54% in controlled studies, on par with skilled human scammers. Once a target clicks through, credential theft succeeds in around a third of AI-generated phishing cases analysed so far.
Which populations are most vulnerable to phishing attempts?
No single group is uniquely at risk. Employees with financial or IT access are targeted for business email compromise, older adults are frequently targeted with romance and investment scams, and younger, highly online users see more smishing and social media impersonation attempts.
What percentage of data breaches are caused by phishing?
Verizon’s 2025 Data Breach Investigations Report found phishing involved in around 15% of breaches as the initial access method, while social engineering more broadly featured in roughly 17% of cases and a human element contributed to well over half of all breaches studied.
Does multi-factor authentication stop all phishing?
No. MFA blocks the majority of credential-based attacks, but it can’t stop session-token theft carried out by infostealer malware, which is why monitoring login behaviour alongside MFA gives stronger protection.
Why is QR code phishing (quishing) increasing?
Quishing has grown because QR codes are images rather than text, so many email filters built to scan for suspicious links simply don’t read them. Mobile phones also tend to hide or shorten the full web address behind a code, meaning a scan often lands on a fake page before anyone gets the chance to check where the code actually pointed.
Are Irish businesses targeted differently from UK businesses?
The available data tells a more mixed story on Phishing Attack Trends in Ireland than a simple copy of UK trends. Provisional figures for 2025 showed overall fraud and economic crime offences up sharply on the previous year, while reported phishing, vishing and smishing specifically fell, which points to attackers shifting toward other fraud types such as deception scams and online shopping fraud rather than phishing volumes rising uniformly across both jurisdictions.