
Why (Almost) Every Cyberattack Still Starts With an Email
Cybersecurity advice tends to focus on technical defences, and modern defences genuinely are stronger than they used to be. What has not changed nearly as much is where most attacks actually begin. The figures below come from several independent industry sources, and they do not all agree on the exact percentage — which is itself worth understanding before quoting any single number as definitive.
The Numbers, Reported Honestly
Proofpoint's 2026 State of the Phish report puts the figure at 91% of cyberattacks beginning with an email — a number the company says has remained remarkably consistent since it first reported it back in 2019. The US Cybersecurity and Infrastructure Security Agency (CISA) similarly states that over 90% of cyberattacks globally begin with phishing as the initial vector. A separate 2025 report from KnowBe4 puts the figure somewhat lower, at 68% of cyberattacks originating from email — still a clear majority, but a meaningfully different number, which reflects different methodologies and different definitions of "cyberattack" across these reports rather than a single settled statistic.
Other major industry reports frame the same underlying pattern differently again: Verizon's 2025 Data Breach Investigations Report found phishing present in 36% of all data breaches, while IBM's 2025 research puts phishing as the specific initial attack vector in 16% of breaches. The range across all these figures is wide, but the underlying conclusion each of them supports is the same — email remains, by a clear margin, the most common way a real-world attack actually begins.
The Scale Involved
The Anti-Phishing Working Group's Q4 2025 Phishing Activity Trends Report estimates roughly 3.4 billion phishing emails are sent every single day, accounting for around 1.2% of all email traffic worldwide. That is a genuinely enormous volume set against a single, well-understood defence: recognising what a phishing email looks like before acting on it.
AI Has Changed the Threat, Not the Channel
What has changed recently is the sophistication of the emails themselves rather than the channel they arrive through. Industry data covering September 2024 to February 2025 found that 82.6% of detected phishing emails used AI in their construction — a 53.5% year-on-year increase — meaning the crude, typo-ridden phishing email of a decade ago is being steadily replaced by messages that read as genuinely fluent and well-targeted.
What This Means Practically
Cybersecurity for Everyone is built around exactly this finding: the single highest-value skill for most people is not a piece of software, it is the habit of pausing before clicking a link or opening an attachment in an unexpected email — because whichever precise percentage you trust, every credible source agrees that is still where almost everything starts.