Phishing remains the single most common way attackers get into a small business, and the numbers behind that statement have only gotten worse. Below is a compiled, citable breakdown of the latest phishing, business email compromise (BEC), and email authentication data for small and midsize businesses, current as of 2026.
Phishing & BEC by the Numbers
| Metric | Figure | What It Means | Source |
|---|---|---|---|
| SMB phishing click rate (1–249 employees) | 24.6% | Roughly 1 in 4 employees at a small business will click a phishing link when tested | Kymatio via StationX |
| Phishing’s share of all SMB breaches | 33.8% | Phishing is the single largest cause of SMB security incidents, ahead of any other attack method | Heimdal Security via StationX |
| SMB breaches with a ransomware component | 88% | Most SMB breaches don’t stop at a stolen credential; they escalate into a ransomware event | Verizon DBIR 2025 via StationX |
| SMBs lacking a DMARC policy | 68% | Most small businesses have no protection in place against attackers spoofing their domain in emails | Heimdal 2025 via StationX |
| BEC losses reported to FBI IC3 in 2025 | $3.05 billion | Total dollars lost to business email compromise scams in the US in one year, reported losses only | DeepStrike, BEC Statistics 2026 |
| BEC complaints filed with FBI IC3 in 2025 | 24,768 | The number of individual BEC incidents reported to federal law enforcement in a single year | DeepStrike, BEC Statistics 2026 |
| Total cybercrime losses reported to FBI IC3 in 2025 | $20.9 billion | All internet-crime losses reported to the FBI in 2025, the broader category BEC and phishing fall under | DMARC Report, State of DMARC Adoption 2026 |
| AI-enabled cybercrime losses (new IC3 category, 2025) | $893 million+ | The first year the FBI tracked AI-generated scams separately, covering AI phishing, voice cloning, and deepfakes | DMARC Report, State of DMARC Adoption 2026 |
| Global DMARC adoption (top domains) | 52.1% | Just over half of major domains have published a DMARC record of any kind, including weak, monitoring-only ones | DuoCircle, DMARC/SPF/DKIM in 2026 |
| DMARC domains actually enforcing (p=reject) | 18.4% | The share of domains with DMARC set strictly enough to actually block spoofed email, not just monitor it | Medha Cloud, Email Security Statistics 2026 |
Why Small Businesses Are the Preferred Target
Attackers aren’t picking on small businesses by accident. They’re picking on them because the math works in their favor. Roughly one in four SMBs was breached in the past year despite the vast majority already having some security tools in place, a gap that points less to a lack of effort and more to a lack of the right configuration and oversight.
The entry point is almost always the inbox. Phishing accounts for roughly a third of SMB breaches, and nearly nine in ten SMB breaches now involve a ransomware component that typically starts with a phishing email, compared to a much lower share at larger enterprises with dedicated security teams. Once an employee clicks, the window to react is short. The median time from opening a phishing link to clicking it is under 60 seconds, and one in five people who click go on to actually enter their credentials on the fake page.
Training helps, but most SMBs aren’t doing it consistently. Only about 9% of small businesses run phishing awareness training on a quarterly basis, and more than two-thirds of SMB phishing breaches trace back to a single untrained employee. That’s a meaningful gap given that employees who receive consistent, simulation-based training are seven times less likely to fall for a phishing attempt.
Business Email Compromise: The Costliest Email-Based Crime
BEC doesn’t rely on malware, ransomware payloads, or any technical exploit. It relies on a convincing email and a busy employee with access to a bank account. That simplicity is exactly why it remains so expensive.
The FBI’s 2025 Internet Crime Complaint Center report logged 24,768 BEC complaints and $3.05 billion in reported losses, up from 21,442 complaints and $2.77 billion the year before, a roughly 16% increase in complaints year over year. For businesses that get hit, the money moves fast: 86% of BEC losses are transmitted via wire transfer or ACH, making them fast-moving and often unrecoverable once fraud is detected.
This isn’t a large-enterprise problem that occasionally trickles down. Industry projections based on 2025 year-end data put annual BEC incidents at approximately 28,000 in 2026, a significant increase compared with 2024. Microsoft’s own telemetry underscores just how much damage a small number of these attacks can do: according to Microsoft’s 2025 Digital Defense Report, BEC represented only 2% of observed threats but drove 21% of attack outcomes, meaning low-volume attacks still produce outsized business impact.
Recovery odds aren’t great once money is gone. Only about 23% of reported BEC wire transfers are successfully recovered, down from 29% in 2023, as attackers route funds through cryptocurrency and overseas accounts faster than victims and banks can react.
The Authentication Gap: DMARC, SPF, and DKIM
Email authentication is one of the most effective, and most neglected, defenses against spoofing and impersonation. It’s also directly relevant to email administration, since DMARC, SPF, and DKIM records live in the same DNS configuration that gets set up (or missed) during a mailbox migration.
Global DMARC adoption reached 52.1% in 2026, up from just 27.2% in 2023, with roughly 412,000 domains now enforcing a policy rather than just monitoring. But adoption and protection aren’t the same thing. More than 80% of domains worldwide still have no DMARC record at all or use a non-enforcing “p=none” policy, and over 70% of DMARC-enabled domains lack the reporting tags needed to see who is actually sending email on their behalf.
The gap between large and small organizations is stark. By early 2026, 95% of Fortune 500 companies had implemented DMARC, with more than 80% enforcing policies that actively block unauthorized email, compared to just over half of Inc. 5000 companies. Enforcement lags even further behind adoption: only 18.4% of domains use a reject policy, meaning roughly a third of DMARC-enabled domains are monitoring spoofing attempts without actually stopping them.
DKIM, the protocol that cryptographically signs outbound mail, lags even further behind. Across a study of 5.5 million domains, DKIM adoption sat at 22.7%, well behind SPF at 56.0% and DMARC at 30.4%. Roughly 41% of the domains studied had no email authentication whatsoever, leaving them fully exposed to spoofing and impersonation.
Microsoft 365 and Google Workspace: The Preferred Targets
Cloud email platforms are attractive targets precisely because compromising one account often unlocks far more than the inbox. Microsoft 365 and Google Workspace are the two most targeted platforms in credential-harvesting campaigns, since a convincing fake login page or shared-document notification matches the exact interface employees use every day, and a single compromised account can expose email, files, and connected apps at once.
The scale of the targeting is enormous. SaaS and webmail platforms including Microsoft 365 and Google Workspace account for roughly 19.4% of all phishing targets tracked by the Anti-Phishing Working Group. On the Microsoft side specifically, Microsoft detected approximately 7.6 billion email-based phishing threats between April and June 2026 alone, with credential theft as the goal in 94 to 96% of malicious payload attacks.
Built-in filtering catches most, but not all, of this volume. Microsoft 365’s native filtering catches roughly 93% of phishing attempts, but at billions of phishing emails sent daily, that remaining gap still represents massive exposure, which is why most managed providers layer additional filtering and monitoring on top of what ships by default. On the BEC side, Microsoft 365 services block an estimated 156,000 business email compromise attempts per day across its customer base, with Defender for Office 365 telemetry showing BEC volume growing 38% year over year.
AI Is Changing the Economics of Phishing
The single biggest shift in the phishing landscape over the past year has been the use of generative AI to write more convincing lures at essentially no cost. AI-generated phishing achieves open rates of 54 to 78%, compared to roughly 12% for traditional phishing attempts, while costing attackers about 95% less to produce. Employees are noticing the difference. 72% of workers say phishing attempts have become more convincing over the past year specifically because of AI-written language.
Despite the shift in threat sophistication, most small businesses haven’t adjusted their defenses to match. Only about 11% of small businesses have deployed AI-powered security defenses, leaving a widening gap between attacker capability and business preparedness.
Prevention Is Still Far Cheaper Than Recovery
For SMB owners weighing whether email security is worth the investment, the cost comparison isn’t close. Prevention typically runs $5,000 to $15,000 annually, while recovery from an actual incident averages a minimum of $120,000 and can exceed $1.24 million. Despite that gap, safety nets remain thin. Only 17% of U.S. small businesses currently carry cyber insurance, compared to 62% in the UK, leaving most American SMBs fully exposed to the direct cost of a successful attack.
FAQ
What percentage of small business breaches start with phishing? Phishing accounts for roughly 33.8% of SMB breaches, and it’s the entry point for most ransomware incidents as well, which are present in 88% of SMB breach cases (StationX).
How much has business email compromise cost businesses recently? The FBI’s IC3 recorded $3.05 billion in reported BEC losses in 2025 alone, across nearly 25,000 complaints, and BEC has caused over $55 billion in cumulative losses since 2013 (DeepStrike).
Do most small businesses have DMARC set up correctly? No. While global DMARC adoption has passed 50%, most of those domains are set to a monitoring-only policy rather than one that actually blocks spoofed email, and 68% of SMBs specifically have no DMARC policy at all (DuoCircle; StationX).
Is Microsoft 365’s built-in security enough on its own? Native filtering catches around 93% of phishing attempts, but given the billions of phishing emails sent daily, that remaining gap still lets a meaningful volume through, which is why layered protection and properly configured authentication records matter (Medha Cloud).
Why are AI-generated phishing emails more dangerous? They achieve open rates of 54 to 78%, versus about 12% for traditional phishing, while costing attackers a fraction as much to produce, making high-volume, well-written attacks accessible to far more threat actors (Total Assure).
Compiled by EMNMS from FBI IC3, Verizon DBIR, Microsoft, EasyDMARC, and other primary and industry sources, current as of 2026. For help auditing or hardening your Microsoft 365 or Google Workspace email security, get in touch with our team.
Recent Comments