Why Are Phishing Attacks So Dangerous?

What makes phishing uniquely dangerous is that it targets something no software update can fix: human behavior. A well-timed email that creates panic or impersonates your CEO bypasses even the most cautious employee.

Not because they’re careless, but because they’re human.

And it isn’t just individuals who fall for it. In April 2025, Marks & Spencer, one of Britain’s most recognised retail brands, suffered one of the most disruptive cyberattacks in UK history.

The attackers impersonated an M&S employee and convinced an IT helpdesk to reset credentials, and used those to deploy ransomware on the organisation. The damage?

  • The attack wiped roughly £750 million off M&S’s market value
  • Cost £300 million in operating profit
  • Erosion of trust among employees and customers
  • Reputational damage, which lasts the longest

And M&S is not an outlier. Over 90% of all cyberattacks worldwide begin with phishing. It is not a niche threat or a problem reserved for careless organisations.

On top of that, a single case of credential theft, where hackers have access to a company, can cascade into problems like ransomware, wire fraud, account lockouts and more.

According to IBM’s 2024 Cost of a Data Breach Report, successful phishing breaches cost ~$4.8 million on average globally and take 254 days to detect/contain.

Phishing is dangerous because it is the single most common way attackers get in, and it works because there is always a human on the other end.

In this post I will cover why phishing attacks are so dangerous for individuals, companies, but any person worldwide that has access to the internet.

Impact of Phishing Attacks on Individuals

In only the first half of 2024, over 20 million social media accounts were targeted through phishing attacks globally. Furthermore, Google blocks about 100 million phishing emails daily.

The impact of phishing attacks on individuals includes but is not limited to:

  • Financial loss
  • Identity theft
  • Professional consequences
  • Psychological impact
  • Reputational damage
  • Emotional distress

The real attack behind phishing starts when you’ve entered your credentials, downloaded a malicious file or approved permission for a certain application.

So the impact on individuals through phishing is mainly determined whether they took one of the above actions or not. But after having taken one of those actions, as you know, they can lead to financial loss, identity theft, reputational damage, etc.

With our new tool, you can assess the risk of your specific situation after you clicked a phishing link. It also tells you the recommended steps to take to limit damage. You can find our tool here.

How a Single Click Can Hand Over Your Identity

Phishing often harvests far more than just passwords.

A single successful attack can expose your home address, date of birth, national ID number, medical and financial information, and other data that the hacker can use for personal gain.

Data that goes well beyond what you typed into a fake login page.

The moment you enter any credentials, the attacker has them instantly. What they do with that information next is where the real damage begins.

The most critical part as you’ve is what happens after you click a phishing link. If you enter any credentials, the phisher immediately has access to that data, or worse.

When Hackers Use Your Identity Against the People You Know

For individuals specifically, if your email or social accounts are hijacked and used to send phishing emails to your contacts, your personal and professional reputation take a hit.

This is more common than most people realise. Research shows that 57.9% of all phishing emails detected between September 2024 and February 2025 were sent from compromised real accounts rather than fake ones.

Attackers deliberately use legitimate accounts because recipients are far more likely to trust a message from someone they know.

The Barracuda research mentioned that 24% of organizations had at least one email account compromised through account takeover, and those accounts were then used for ”lateral phishing.”

Unfortunately there are no statistics available for how often phishers use email accounts to target friends and acquiantances afterwards.

Impact of Phishing Attacks on Organizations

For organizations, a successful phishing attack rarely ends with a single compromised account. It is usually the beginning of a chain.

It leads to credential theft, which leads to network access, network access leads to stolen data or ransomware deployment, and ransomware leads to operational shutdown and significant financial losses. Not to mention the reputational damages that are incurred.

According to IBM’s 2024 Cost of a Data Breach Report, the average cost of a phishing-initiated breach for an organization is $4.88 million globally, as confirmed b

In the following part we will cover the different impact phishing attacks have on organizations, starting with financial impact.

Financial Impact of Phishing Attacks on Organizations (from BEC to Ransomware and more)

According to Hoxhunt’s Phishing Trends Report, which draws data from 4 million users globally:

A staggering 64% of businesses report facing BEC attacks in 2024, with a typical financial loss averaging $150,000 per incident​. These phishing attacks frequently target employees with access to financial systems, mimicking executives or trusted contacts.

And BEC is just one form of phishing. This is what BEC is in Microsoft’s words: Business email compromise (BEC) occurs when cybercriminals impersonate trusted leaders to trick employees into sending money or data. These scams cost businesses millions, with small companies often unable to recover from the losses.

Ransomware

If it wasn’t already the case, ransomware has developed into a ”systemic risk” for businesses in 2026. In 2025, nearly 63% of businesses worldwide were affected by Ransomware in some way.

Through phishing or other exploited vulnerabilities, hackers work their way into a company’s systems to install ransomware. The attackers ”move laterally” through the organization to infect as many systems as possible.

More often than not this results in encryption of data on the servers of the company. This includes files, databases, backups, software, and more.

The final part of the ransom is where hackers exchange the encryption key (to unlock all of the above) in exchange for payment, often cryptocurrency.

The Psychological Toll on Victims

PubMed has done research ”into the profound and hidden health impacts of internet scams manifesting emotional distress, including depression, anxiety, shame, and embarrassment.”

In the article they mention a group of Australian investors who fell victim to an elaborate phishing scam.

PubMed shares details:

Some victims lost substantial sums, and others lost more modest sums, while a few avoided substantial financial losses after canceling the payment and/or successful bank recalls.

But later on they write specifically about the emotional fallout:

In terms of the mental health impacts of the scam, the group reported significant psychological distress manifesting as insomnia, anxiety, depression, and trauma (notably, post-traumatic stress disorder). Insomnia was noted as temporary while awaiting the decision of bank recalls (1–2 months). The experience of anxiety and depression was prolonged in those who suffered major financial loss. It was compounded by a perception of not being adequately served by banks and AFCA as well as unproductive and/or slow police inquiries (up to 2 years if investigated).

Phishing Statistics Worldwide

The numbers below show exactly why phishing remains the single most dangerous cyber threat facing individuals and organisations worldwide.

Station X, in their Phishing Statistics [2026]: Latest Attack Data & Trends article, states that 3.4 billion phishing emails are sent worldwide each and every day. That is +- 39.000 phishing emails sent out per second.

To put that in perspective: by the time you finish reading this paragraph, over 200,000 phishing emails will have landed in inboxes around the world.

And attackers are deliberate about timing. Phishing activity peaks on Sundays and Fridays, with those two days alone accounting for over 40% of all weekly phishing email volume.

These are the days when most people are least focused, most rushed and most likely to act without stopping to verify.


Station X also reports that global phishing losses are estimated at $25 billion annually, which roughly amounts to $18.000 per minute lost to phishing. For individuals it means a drained bank account; for companies it could mean the end of the line entirely.


Since the release of ChatGPT in late 2022, the volume of phishing emails has increased with 1,265%. It lead to the removal of poor grammar and awkward phrasing in phishing emails, which increases effectiveness of phishing campaigns.

A Phishing Attack on a Regular User Account Could Result in…

The most common outcomes of phishing attacks on a regular user’s account are:

  • Identity theft
  • Malware on your device
  • Unauthorized access to accounts
  • Unauthorized network access
  • Email account used for more phishing
  • Hackers monitoring your inbox for sensitive information

Overwhelmingly, the majority of broad ”regular” phishing attempts are still aimed at credential theft. Only a very small number of phishing attacks results in malware download through something that is called ”drive-by.”

And the phishing emails are still mainly delivered via email as the main vehicle.

If you haven’t clicked a link and want to know how to avoid phishing scams, read our article: How to Avoid Phishing Scams: a Step-by-Step Guide

If you did click a link or possibly approved permission or downloaded something malicious, you can use our free tool. This will help you assess the risk and gives you recommended next steps.

We have also created an article on how to avoid phishing for the workplace specifically. It shows 6 examples of phishing email examples targeted at employees. You can read it here: 6 Phishing Email Examples for Employees: Real Emails That Fooled Real People

Last but not least, we should take a closer look at spear phishing, since it is, and has been, one of the most dangerous forms of phishing around.

Spear Phishing Emails are the Most Common Targeted Attacks

As you can see below, spear phishing emails is still the most common among targeted cyberattacks:

Phishing Attack Types

Sources: NordVPN citing Barracuda Networks 2024; Verizon DBIR 2025; Keepnet 2024

Attack type Description Primary target Channel Key stat
Spear phishing Targeted at specific individuals using personal data Employees, executives Email 65% of breaches
Whaling Spear phishing aimed at C-suite executives CEO, CFO, CXO Email Up to $60M in losses (Orion S.A.)
Vishing Voice phishing via phone calls Individuals, IT staff Phone +28% in 2024
Smishing Phishing delivered via SMS text message Mobile users SMS +22% in 2024
Quishing Phishing via malicious QR codes General public QR / email 5x growth 2025
Angler phishing Impersonating brands on social media Social media users Social media Rising
Spear phishing (65% of successful attacks) Other targeted types
Spear phishing: 65% of successful breaches. All other types combined: 35%.

As NordVPN states in their article, 65% of succesful phishing attacks in 2024 are attributed to spear phishing. Spear phishing emails are by far the most common targeted attacks used today, with no sign of it stopping.

Sources: Barracuda Networks, Verizon DBIR, Keepnet, NordVPN, Helpnetsecurity.com

Frequently Asked Questions

What is the most common type of phishing attack?

Bulk email phishing is as of today still the most common type of phishing attack.

How much does a phishing attack cost a business?

According to IBM, organizations that suffer a breach initiated by phishing face an average cost of $4.88 million globally.

How long does it take to detect a phishing breach?

On average, it takes organizations worldwide 254 days to detect and contain a phishing-initiated breach.

Can phishing happen outside of email?

Yes. The types of phishing to mention here are: vishing, smishing and quishing. Vishing. which refers to voice + phishing, is where scammers call and impersonate a government official, bank employee, or another person with authority.

Smishing is phishing through text messages. Again, fake text from banks, companies, government agencies designed to steal sensitive information.

Quishing, QR-code phishing, can also be delivered to you through other ways outside of email.

What should I do immediately after clicking a phishing link?

After clicking a phishing link it is recommended that you try our free tool:

Clicked a phishing link? Assess your risk with the tool below.

Comments

Leave a Reply

Discover more from OZARC

Subscribe now to keep reading and get access to the full archive.

Continue reading