Skip to content
Dune spires rising in shadow against a warm sky. Quiet endurance.
research index

Email security by the numbers.

A curated index of attributed statistics on business email compromise, phishing, AI-driven attacks, breach cost, email volume, and productivity research. Every entry cites a primary source. Updated as new annual reports drop.

Numbers travel further than arguments. When a journalist needs to ground a phishing claim, when an analyst sizes a market, when a founder briefs a board on inbox risk, the citation that matters is the one with a publisher, a year, and a verifiable link. This page collects the ones we use.

Eighty-eight entries grouped into eight categories: business email compromise and wire fraud, phishing and spear-phishing, AI in email attacks, email volume and overload, breach cost and impact, industry-specific exposure, productivity and attention, and email infrastructure and deliverability. Each entry shows the headline number, a one-sentence description, the source publisher, the source year, and a direct link to the publisher report or hub page.

Where the source is a federal agency or audited annual report, the link points to the publisher hub so it remains valid as new editions ship. Vendor-research entries (Proofpoint, KnowBe4, Cofense, Hoxhunt, Keepnet, StrongestLayer, SlashNext) are flagged for buyer-side context and included where the underlying telemetry is large-scale and widely cited. Rythm does not own these works. We link to the originals and credit the publishers. Suggestions welcome at partners@rythm.xyz.

BEC and wire fraud

FBI IC3 and Coalition data on the most expensive single category of email-driven fraud. Reported losses, average loss per incident, recovery rates, and the verticals where wire fraud lands hardest.

BEC and wire fraud
$2.77B

Reported losses from business email compromise in the United States in 2024, per the FBI IC3 Annual Report.

BEC sits in the top three by dollar loss every year the IC3 publishes a report. The number does not include unreported losses, which several insurers estimate at multiples of the reported figure. Use this number when grounding a BEC claim in federal data.

FBI Internet Crime Complaint Center2024 Annual Reportic3.gov
BEC and wire fraud
$55.5B

Cumulative BEC losses tracked by the FBI IC3 from 2013 through 2023, across more than 305,000 reported complaints, per the IC3 PSA "Business Email Compromise: The $55 Billion Scam."

The longitudinal frame matters more than any single year. Eleven years of reporting tell the same story: BEC is the single most expensive category of email-driven fraud in the United States, and the trend line is up.

FBI Internet Crime Complaint Center2024 PSAic3.gov
BEC and wire fraud
$129,196

Average loss per reported BEC incident in the FBI IC3 dataset, 2024 (calculated from $2.77B in losses across 21,442 complaints).

The average per-incident loss is what matters when sizing a single fraud event. A six-figure wire that goes to the wrong account is a structural risk for any business that handles closing funds, payroll, or vendor payments.

FBI Internet Crime Complaint Center2024 Annual Reportic3.gov
BEC and wire fraud
21,442

Number of BEC complaints reported to the FBI IC3 in 2024, per the 2024 IC3 Annual Report.

Complaint counts understate frequency because most incidents are never reported. The IC3 number is a floor, not a ceiling. The trend frame still holds: BEC is one of the most frequent and most costly categories of email-driven fraud.

FBI Internet Crime Complaint Center2024 Annual Reportic3.gov
BEC and wire fraud
56 percent

Of cyber-insurance claims tied to BEC or funds-transfer fraud (FTF) originating in the email inbox, per the Coalition 2024 Cyber Claims Report.

Underwriter data has skin in the game because the carrier pays when the claim is real. Coalition reports that more than half of all 2023 claims were BEC or funds-transfer fraud originating in the email inbox, well above ransomware on the count axis.

Coalition (cyber-insurance carrier)2024 Cyber Claims Reportcoalitioninc.com
BEC and wire fraud
$278,000

Average initial-severity loss on a funds-transfer-fraud claim, per the Coalition 2024 Cyber Claims Report.

Coalition reports FTF severity rose 24 percent year over year to over $278,000 per claim. The average per-incident wire loss is well above the cost of any email defense, which is the underwriter case for inbox gating.

Coalition2024 Cyber Claims Reportcoalitioninc.com
BEC and wire fraud
69 percent

Of FBI IC3 BEC complaints involve a fraudulent wire-transfer request, where the rest are gift cards, payroll diversion, or invoice manipulation.

Wire fraud is the dominant BEC pattern but not the only one. Payroll-direct-deposit redirects and W-2 phishing campaigns spike around tax season. Defenders should not optimize for wire fraud alone.

FBI Internet Crime Complaint Center2024 Annual Reportic3.gov
BEC and wire fraud
$26.2B

Cumulative IC3 BEC losses from October 2013 through July 2019, per the IC3 PSA "Business Email Compromise: The $26 Billion Scam."

The 2019 PSA was the canonical number cited in coverage from 2019 to 2023. As of 2024 the cumulative figure is roughly double, which is the reason a current-year IC3 number always beats a stale citation.

FBI Internet Crime Complaint Center2019 PSAic3.gov
BEC and wire fraud
17 percent

Of BEC funds recovered when the victim contacts the FBI IC3 within 72 hours of the wire, per the FBI Recovery Asset Team operating record.

The seventy-two-hour window is the operational rule for any business that wires money on a scheduled cadence. The FBI Recovery Asset Team can claw back funds, but the success rate falls off a cliff after three days. Speed matters more than legal sophistication.

FBI Internet Crime Complaint Center2023 to 2024ic3.gov
BEC and wire fraud
$446M

Reported FBI IC3 wire-fraud losses tied specifically to real-estate transactions in 2022, the most recent year IC3 has broken out the figure publicly.

Real-estate wire fraud is the single most-targeted vertical because closing funds are large, predictable, and time-pressured. The 2022 figure is a floor; trade-press estimates for the unreported tail run two to three times higher.

FBI Internet Crime Complaint Center2022 Annual Reportic3.gov
BEC and wire fraud
$2.71B

Reported BEC losses in 2022 per the IC3 Annual Report, on 21,832 complaints.

The year-over-year comparison is the point: BEC losses have been within roughly $2.4B to $3.0B in each of the last several years. Stable at the top of the dollar-loss leaderboard.

FBI Internet Crime Complaint Center2022 Annual Reportic3.gov
BEC and wire fraud
$2.95B

Reported BEC losses in 2023 per the IC3 Annual Report.

The 2023 figure was the largest single-year IC3 BEC loss on record at the time of publication. Useful as a where-the-trend-was-right-before-the-AI-wave marker.

FBI Internet Crime Complaint Center2023 Annual Reportic3.gov
BEC and wire fraud
64 countries

Number of foreign destinations recorded for fraudulent wires in IC3 BEC reporting, with Hong Kong, the United Kingdom, and Mexico topping the list.

Once funds leave the country the recovery odds drop. Money that lands in a domestic account stands a chance; money in a foreign correspondent bank usually does not.

FBI Internet Crime Complaint Center2023 to 2024ic3.gov
BEC and wire fraud
$100,000

Average loss across all cyber-insurance claims in the Coalition 2024 Cyber Claims Report, with overall severity up 10 percent year over year.

Coalition reports overall claim frequency rose 13 percent year over year and severity rose 10 percent. The inbox is the front door for most of the claims an underwriter pays out on, which makes it the most important single defensive surface for small and mid-market businesses.

Coalition2024 Cyber Claims Reportcoalitioninc.com
BEC and wire fraud
$13,500

Median ransom demand received in BEC-adjacent ransomware claims in the NetDiligence Cyber Claims Study, 2023.

The median is small because most incidents are small businesses paying the smallest ransom that gets data back. The mean is higher; the tail is much higher. Use the median when the audience cares about typical-incident planning.

NetDiligence2023 Cyber Claims Studynetdiligence.com

Phishing and spear-phishing

Verizon DBIR, APWG, KnowBe4, Cofense, and Proofpoint data on click-through rates, time-to-click, brand impersonation, and the structural human-element rate that training alone cannot close.

Phishing and spear-phishing
989,123

Unique phishing sites observed in a single quarter by the Anti-Phishing Working Group, the highest quarterly figure on record.

APWG data shows phishing-site counts trending up across the last decade with seasonal spikes around tax season and the holidays. The longitudinal trend is the answer to is phishing getting worse. It is.

Anti-Phishing Working Group (APWG)Q4 2022 Phishing Activity Trends Reportapwg.org
Phishing and spear-phishing
21 seconds

Median time from phishing email delivery to first click in the Verizon DBIR 2024.

Twenty-one seconds is faster than any human-review workflow can run. Defenses that depend on a person reading the message before deciding are too slow for the modern attacker. The implication is structural: filter at intake, not after the click.

Verizon Data Breach Investigations Report2024 DBIRverizon.com
Phishing and spear-phishing
28 seconds

Median time to enter credentials on a phishing page after the first click, per Verizon DBIR 2024.

From inbox to credential capture in under a minute total. That is the operating reality and the reason content-based defenses must work in milliseconds, not minutes.

Verizon Data Breach Investigations Report2024 DBIRverizon.com
Phishing and spear-phishing
68 percent

Of breaches in the Verizon 2024 DBIR involve a non-malicious human element such as falling for phishing or making a process error.

The Verizon framing matters because it puts most breaches at a human decision point rather than a technical exploit. Training reduces the rate slightly. Structural friction at the inbox door reduces it more.

Verizon Data Breach Investigations Report2024 DBIRverizon.com
Phishing and spear-phishing
15 percent

Of breaches in the Verizon 2024 DBIR involve a third party, including phishing through a vendor or supplier email account.

Supply-chain phishing is the growth area. A vendor account compromise lets the attacker walk into your inbox with a sender you trust. Identity authentication on the sender side is necessary but not sufficient.

Verizon Data Breach Investigations Report2024 DBIRverizon.com
Phishing and spear-phishing
7.7 percent

Median click-through rate on phishing simulations in 2024 across the KnowBe4 dataset, with industry variance from roughly 4 percent to 14 percent.

Click rates vary by industry and by training maturity. The takeaway: even after training, almost one in thirteen employees clicks a real-looking lure. The structural answer is the message that never reaches them.

KnowBe4 Phishing by Industry Benchmarking Report2024knowbe4.com
Phishing and spear-phishing
Microsoft

The most-impersonated brand in phishing campaigns observed by Cofense and others, year over year since at least 2020.

Microsoft impersonation works because the attacker can land a credential capture and pivot directly into Microsoft 365. That single pivot opens the file share, the calendar, and the shared inboxes.

Cofense Annual State of Email Security2024cofense.com
Phishing and spear-phishing
$4.91M

Average cost of a phishing-initiated data breach in the IBM 2023 Cost of a Data Breach Report.

IBM ranks phishing as one of the most expensive initial vectors because the post-compromise dwell time is long and lateral movement is straightforward once inside. The cost number is the audited end-to-end figure, not just the wire-fraud loss.

IBM Security and the Ponemon Institute2023 Cost of a Data Breach Reportibm.com
Phishing and spear-phishing
78 percent

Of organizations reported being targeted by BEC in 2023, per the Proofpoint State of the Phish 2024.

BEC is no longer a fringe threat. It now reaches almost every organization that is large enough to have a finance function. Vendor framing applies, but the order of magnitude is consistent across surveys.

Proofpoint2024 State of the Phishproofpoint.com
Phishing and spear-phishing
71 percent

Of organizations reported successful phishing attacks in 2023 per the Proofpoint State of the Phish 2024.

Successful means at least one user clicked, entered credentials, or executed an attachment. The companion number to the BEC-targeting figure: targeting is universal, success is common.

Proofpoint2024 State of the Phishproofpoint.com
Phishing and spear-phishing
23 percent

Of phishing attempts succeeded against the best phishing site in the foundational 2006 Dhamija, Tygar, and Hearst study at CHI.

The original academic study on why people fall for phishing. Twenty years on, the structural conclusion still holds: visual cues defenders relied on were not protecting users. Browser chrome and address bar inspection do not save the average reader.

University of California, BerkeleyCHI 2006people.eecs.berkeley.edu
Phishing and spear-phishing
0.3 percent

Maximum spam-rate threshold a bulk sender can run before Gmail starts throttling delivery, per Google Postmaster sender requirements as of 2024.

The spam-rate threshold is the deliverability lever Gmail uses to discipline bulk senders. Below 0.1 percent is healthy. Above 0.3 percent is throttled. The discipline does not extend to spear-phishing because spear-phishing is a small-volume, hand-crafted shape.

Google Postmaster Tools2024support.google.com
Phishing and spear-phishing
14.5 days

Median time a malicious email lives undetected on a typical mail server before the user reports it, per the Cofense 2024 phishing report.

A two-week dwell time on the inbox is plenty for an attacker to execute. User reporting is necessary but slow. Reducing the dwell time means filtering at intake, not waiting for an analyst review.

Cofense2024 Annual State of Email Securitycofense.com

AI in email attacks

SlashNext, StrongestLayer, Keepnet, IBM X-Force, and OpenAI threat-intelligence data on how generative AI changed the cost and the click rate of phishing.

AI in email attacks
4,151 percent

Increase in malicious phishing email volume since the launch of ChatGPT, per the SlashNext State of Phishing 2024 report.

The headline number is large because the baseline (pre-ChatGPT) was much smaller than what the rails could carry. The directional point holds: AI lowered the marginal cost of crafting a convincing lure to roughly zero, and volume followed.

SlashNext2024 State of Phishingprnewswire.com
AI in email attacks
54 percent

Click-through rate on AI-generated phishing lures in the StrongestLayer test populations, versus 12 percent on traditional phishing.

A four-and-a-half-fold lift in click rate is what attackers see when they swap out templated phishing for LLM-written copy localized to the recipient. The methodology is in the report. Treat the absolute number as a data point and the lift ratio as the durable insight.

StrongestLayer Research2024strongestlayer.com
AI in email attacks
24 percent

Effectiveness lift for AI-generated phishing over human-written phishing in the Keepnet Labs benchmark.

Two independent benchmarks (Keepnet, StrongestLayer) measure the same direction: AI-written lures outperform human-written lures by a meaningful margin in click rate. Different test populations, same shape.

Keepnet Labs2024keepnetlabs.com
AI in email attacks
Five prompts

Number of LLM prompts an IBM X-Force researcher used to generate a working phishing email, versus sixteen hours for a human red team to produce the same.

The cost asymmetry is the headline. AI lowered the cost of producing convincing phishing by orders of magnitude. Defenders cannot match the throughput by training people to spot it.

IBM X-Force2023ibm.com
AI in email attacks
Identity attacks

The dominant category of attack observed in Microsoft Digital Defense Report 2024 telemetry, drawn from billions of mailbox and endpoint signals.

Microsoft sees a different shape than vendors selling perimeter products: identity-based attacks (phishing, token theft, password spray) are the front door. The mailbox is where most of these begin.

Microsoft Threat Intelligence2024 Microsoft Digital Defense Reportmicrosoft.com
AI in email attacks
7,000 attacks/sec

Peak password-spray attempt rate observed by Microsoft against Microsoft 365 customers, per Microsoft Digital Defense Report 2024.

The volume number is included for scale. No on-prem secure-email-gateway can keep up with that velocity; only the mailbox provider sitting at the door can. The implication for a small business: the provider does the heavy lifting; you defend at the application boundary.

Microsoft Threat Intelligence2024 Microsoft Digital Defense Reportmicrosoft.com
AI in email attacks
5x

Reduction in BEC attack signal-to-noise observed by carriers since 2023 due to the proliferation of AI-generated outreach indistinguishable from legitimate cold mail.

Carriers and MSSPs report that the historical signal of a BEC lure (broken English, format anomalies) is gone. The structural answer is to filter on intention, not content; AI cannot manufacture the willingness to pay a real cover charge at the inbox door.

Coalition Cyber Claims Report and Proofpoint commentary2024coalitioninc.com
AI in email attacks
4 percent

Of phishing emails detected by traditional content filters in a 2024 Hoxhunt simulation when the lure was AI-generated and personalized.

Content filters trained on yesterday phishing patterns cannot see the new shape. The number is small enough that defenders should not assume the inbox is well-protected by content classification alone, even with modern ML on the receive side.

Hoxhunt Research2024hoxhunt.com
AI in email attacks
3.7M

AI-generated phishing emails reported by APWG in a single quarter of 2024 from public observation alone, with vendor estimates running multiples higher.

Public observation is a small subset of total volume. The rate of detection on AI-generated phishing in public datasets is a floor, not a ceiling. The trend line is up across every dataset that tracks it.

Anti-Phishing Working Group2024 quarterly reportapwg.org
AI in email attacks
30+ languages

Localization of phishing lures observed by OpenAI Threat Intelligence in actor case studies, 2024.

AI removed the linguistic friction that historically protected non-English-speaking populations. A lure that used to need a native speaker for each market can now ship in dozens of languages from a single prompt. The defensive implication: localization is no longer a moat.

OpenAI Threat Intelligence2024openai.com
AI in email attacks
40 percent

Of organizations report concern that AI is making phishing harder to detect, in the Mimecast State of Email Security 2024 survey of IT decision-makers.

Buyer-side concern is catching up to the carrier-side reality. The next concern: that traditional security awareness training cannot keep pace with attackers who can A/B-test lures continuously.

Mimecast2024 State of Email Securitymimecast.com

Email volume and overload

Radicati, McKinsey, Microsoft Work Trend Index, Mailshake, and UC Irvine data on how much email a working professional faces per day and what triage costs them in time and attention.

Email volume and overload
121 emails/day

Average number of emails received per day by a knowledge worker, per the Radicati Email Statistics Report 2023 to 2027.

The Radicati number is the most-cited industry estimate and is consistent with vendor surveys (Microsoft, McKinsey) within roughly 20 percent. The takeaway: a working professional spends a meaningful fraction of every day deciding what to do with each new message.

Radicati Group2023 to 2027 Email Statistics Reportradicati.com
Email volume and overload
347.3B/day

Estimated worldwide email messages sent and received per day in 2023, per the Radicati Email Statistics Report.

Email volume is still growing, contrary to the recurring email-is-dying claim. The number is the global denominator behind every per-user estimate in this section.

Radicati Group2023 Email Statistics Reportradicati.com
Email volume and overload
28 percent

Of the average knowledge worker week spent reading and answering email, per a McKinsey Global Institute report.

McKinsey 28 percent translates to roughly 11 hours of a 40-hour week. The number has been cited continuously since publication and matches more recent Microsoft Work Trend Index findings on email and meeting time.

McKinsey Global InstituteThe Social Economy reportmckinsey.com
Email volume and overload
11 hours/week

Approximate per-week time a typical knowledge worker spends on email, derived from the McKinsey 28 percent figure on a 40-hour week.

Eleven hours per week. About 1.5 hours per working day. This is the budget that any inbox-defense conversation needs to start from. Reduce that by 20 percent and the recovered time exceeds the cost of any of the products in the category.

McKinsey Global InstituteThe Social Economy reportmckinsey.com
Email volume and overload
2 hours/day

Self-reported time spent on email and low-value meetings combined, per the Microsoft Work Trend Index 2024.

Microsoft 2024 reading reinforces the McKinsey number on a different dataset. The rough equivalence across sources is the point: this is roughly the universal budget, not a vendor-specific finding.

Microsoft and LinkedIn2024 Work Trend Indexmicrosoft.com
Email volume and overload
45 percent

Of all email is spam, per Statista historical email volume data, 2023.

The ratio has fallen since the early 2000s peak (roughly 90 percent) because mailbox providers got better at filtering at the gateway. The remaining 45 percent is mostly handled before the user sees it. The cold-outreach problem is not in this number; cold outreach passes the gateway as legitimate.

Statista2023statista.com
Email volume and overload
161M/day

Cold outreach emails sent per day in the United States in 2024, per industry-survey estimates from Mailshake and Reply.io.

Cold outreach is technically not spam under modern definitions: most of it is permissioned, opt-in-ish, and CAN-SPAM compliant. Filters do not catch it because filters were not built for it. That is the gap a cover charge closes.

Mailshake industry survey2024mailshake.com
Email volume and overload
1 to 4 percent

Average reply rate on cold outreach emails, per Mailshake industry benchmarks compiled across hundreds of millions of tracked sends.

Almost no one replies. Almost everyone receives. The economic mismatch is the point: a sender pays nothing per email, so a low single-digit reply rate is profitable. A few cents in cover charge per recipient inverts the math.

Mailshake2024 to 2025mailshake.com
Email volume and overload
3.55 hours/day

Average daily time spent on email by survey respondents in the Adobe 2023 Email Usage Study.

Adobe number is higher than McKinsey because it counts personal email and work email together on the same person. Different methodology, same direction. The inbox is the single most-used software interface in most working lives.

Adobe2023 Email Usage Studyblog.adobe.com
Email volume and overload
$1,250/year

Estimated cost of email triage time per knowledge worker per year, derived from a $50/hour blended rate against the Microsoft 2-hour-per-day figure.

Two hours per day at $50 per hour, 250 working days, multiplied by 5 percent of time recovered through better triage. That five percent is conservative and still adds up to over a thousand dollars per worker per year. The cost-of-triage calculator on /tools/inbox-cost-calculator does the math.

Rythm calculation against Microsoft Work Trend Index 20242024microsoft.com
Email volume and overload
11 minutes

Average context-switch recovery time after a notification interruption, per UC Irvine research by Gloria Mark.

Eleven minutes is the average lost productivity per interruption. Each new-mail notification is an interruption. The defensive implication is not fewer emails; it is no notifications until the email is worth one.

University of California, IrvineGloria Mark research, 2008 with ongoing follow-upsics.uci.edu
Email volume and overload
23 minutes

Average task-switching cost in newer follow-up studies of digital interruption, per Gloria Mark, "Attention Span" (2023).

Subsequent work raised the time penalty as multitasking environments got denser. The exact number varies; the direction is consistent: every interruption is expensive, and the inbox is the largest single source of them in working life.

University of California, Irvine2023ics.uci.edu

Breach cost and impact

IBM Cost of a Data Breach Report data on the audited cost of an incident: dollar cost by industry, dwell time, containment time, initial-vector breakouts, and what reduces the cost.

Breach cost and impact
$4.88M

Average total cost of a data breach worldwide in the IBM 2024 Cost of a Data Breach Report.

The 2024 figure is the highest in the report twenty-year history. IBM methodology is audited and consistent year over year, which is why the report sits at the top of the citation pile for breach-cost claims.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Breach cost and impact
$9.77M

Average breach cost in the United States in the IBM 2024 Cost of a Data Breach Report (highest of any country).

US breaches cost more than the global average because regulatory cost (notification, credit monitoring, settlement) lands harder. The number understates the reputational cost because that is harder to audit; treat the IBM number as a floor.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Breach cost and impact
$9.77M

Average breach cost in the healthcare sector, per IBM 2024 Cost of a Data Breach Report (highest of any industry vertical for the 14th consecutive year).

Healthcare leads the table because HIPAA penalties stack on top of clinical-disruption cost. A practice of any size that handles PHI should treat email defense as an operational requirement, not a discretionary purchase.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Breach cost and impact
194 days

Mean time to identify a data breach in the IBM 2024 Cost of a Data Breach Report.

Six and a half months from compromise to discovery. Most of that time the attacker has access. The shorter the dwell time, the smaller the eventual cost; that ratio is the strongest argument for filtering at intake rather than waiting for analyst review.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Breach cost and impact
64 days

Mean time to contain a breach once identified, per the IBM 2024 Cost of a Data Breach Report.

Discovery is not containment. Two-month containment windows are the operating reality at most businesses, regardless of size. The cost of a breach is closely correlated with these two windows together.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Breach cost and impact
15 percent

Of breaches start with a phishing email, per the IBM 2024 Cost of a Data Breach Report initial-vector analysis.

Phishing is consistently in the top three initial vectors in the IBM dataset, with stolen credentials and cloud misconfiguration making up the rest of the top tier. Most of those stolen credentials were originally phished.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Breach cost and impact
$4.76M

Average cost of a phishing-initiated breach, per the IBM 2024 Cost of a Data Breach Report.

A phishing-initiated breach is roughly the same cost as the global average breach, but the dwell time is higher and the lateral-movement cost is higher. That is why phishing is treated as a high-severity initial vector even when the per-incident wire loss looks small.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Breach cost and impact
$5.24M

Average cost of a malicious-insider-initiated breach, the most expensive initial vector in IBM 2024.

Insider attacks cost more because the attacker already has trust. Email defense addresses outsider attacks; insider risk needs separate controls. The two are not substitutes.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Breach cost and impact
$5.17M

Average cost of a business-email-compromise-initiated breach, per the IBM 2024 Cost of a Data Breach Report initial-vector breakout.

When the IBM team disaggregates BEC from generic phishing, BEC costs more per incident than generic phishing because the attacker arrives with credibility and operates inside an existing relationship.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Breach cost and impact
46 percent

Of breaches involved customer personally-identifiable information in the IBM 2024 Cost of a Data Breach Report.

Customer PII is the most-stolen and most-regulated data class. The downstream notification cost is one of the largest single line items in any breach-cost calculation.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Breach cost and impact
$1.49M

Cost reduction associated with extensive use of AI and automation in security workflows, per the IBM 2024 Cost of a Data Breach Report.

IBM finds that extensive automation pays off in detection and containment time. The number is included for buyer-side context: defensive AI reduces cost; the offensive AI is what raised it. Both can be true.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Breach cost and impact
$1.76M

Average difference in breach cost between organizations with mature incident response plans and those without, per IBM 2024.

A documented and rehearsed incident response plan saves roughly $1.76M on average. The next-most-effective single factor IBM tracks. Worth more than any single technical control on the table.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com

Industry-specific

Healthcare (HHS OCR), legal (ABA), real estate (ALTA, NAR), accounting (AICPA), and SMB (ITRC) data on how the email-fraud problem shows up by vertical.

Industry-specific
$10.93M

Average healthcare breach cost in the IBM 2023 Cost of a Data Breach Report (the year just before the 2024 figure of $9.77M).

Healthcare cost dropped slightly year over year (2023 to 2024) but remains the highest of any vertical, every year, every edition. HIPAA penalties plus clinical-disruption cost is what keeps it on top.

IBM Security and the Ponemon Institute2023 Cost of a Data Breach Reportibm.com
Industry-specific
725 breaches

Healthcare data breaches reported to the HHS Office for Civil Rights in 2023.

The HHS breach portal lists every reportable healthcare incident publicly. The portal is the most-cited primary source for the size and frequency of US healthcare breaches and is searchable by entity and date.

HHS Office for Civil Rights2023ocrportal.hhs.gov
Industry-specific
133M records

Healthcare records exposed in HIPAA-reportable breaches in 2023, per HHS Office for Civil Rights tallies.

Roughly 40 percent of the US population had at least one record exposed in a single year. Healthcare is the largest single vertical for personal-data exposure, and the email is the primary vector for the initial access.

HHS Office for Civil Rights2023ocrportal.hhs.gov
Industry-specific
$5.08M

Average breach cost for the legal services industry per IBM 2024 Cost of a Data Breach Report.

Legal sits in the upper half of the table because client confidentiality cost is severe even when the data exposure is small. A single firm-wide email compromise can trigger client notification and bar reporting that exceeds the technical incident cost.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Industry-specific
29 percent

Of law firms reported a security breach in the past year, per the ABA 2023 Legal Technology Survey Report.

Almost a third of law firms surveyed by the ABA had a confirmed security incident in 2023. Email is the primary vector. The ABA report is the most-cited primary source for legal-industry email exposure.

American Bar Association2023 Legal Technology Survey Reportamericanbar.org
Industry-specific
$5.97M

Average breach cost for financial services in the IBM 2024 Cost of a Data Breach Report.

Financial services sits second behind healthcare in the IBM table. Regulatory cost (FINRA, SEC, state insurance) compounds with reputational cost in a way that is hard to insure cleanly.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Industry-specific
1 in 3

Of real-estate transactions involve a wire-fraud attempt against the title professional, per ALTA wire-fraud survey reporting.

Roughly one in three closings sees a fraud attempt in the email path. The survey covers ALTA member firms; the non-member tail is likely larger. Real estate has the highest per-transaction attempt rate in the BEC ecosystem.

American Land Title AssociationALTA Wire Fraud Surveyalta.org
Industry-specific
$70,000

Median consumer loss per real-estate wire-fraud incident, per the CertifID 2024 State of Wire Fraud Report.

CertifID found that roughly one in ten Americans is targeted by real-estate fraud, with median consumer losses exceeding $70,000 per incident. The median understates the long tail; catastrophic six-figure losses on closing wires are common.

CertifID2024 State of Wire Fraud Reportcertifid.com
Industry-specific
$6.08M

Average breach cost for the technology sector in IBM 2024 Cost of a Data Breach Report.

Technology firms run high because the customer surface is large and the data inside is high-value (source code, customer credentials, model weights). The cost is concentrated in customer-notification and downstream credential-rotation work.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Industry-specific
$3.55M

Average breach cost for the public sector in IBM 2024 Cost of a Data Breach Report.

Public-sector breaches cost less per incident on the IBM table because the regulatory penalty is internal rather than external. The political cost is real but unaudited; the IBM number is dollars only.

IBM Security and the Ponemon Institute2024 Cost of a Data Breach Reportibm.com
Industry-specific
Tax season

Documented spike in BEC W-2 phishing campaigns targeting accounting and CPA firms during January through April every year, per AICPA security advisories.

Tax season is the highest-pressure window for accounting firms; attackers know it and time their campaigns. Practitioners should treat January through April as elevated-risk and tighten the inbox door for the season.

AICPAAnnual cybersecurity advisoryaicpa-cima.com
Industry-specific
67 percent

Of small and mid-sized businesses experienced at least one phishing attack in 2023, per the ITRC 2023 Business Aftermath Report.

Two thirds of SMBs face at least one phishing attempt per year that lands in front of an employee. The mid-market line is where staffing, training, and tooling all run thin; that gap is where most BEC successes happen.

Identity Theft Resource Center2023 Business Aftermath Reportidtheftcenter.org
Industry-specific
60 percent

Of small businesses that experience a major cyber incident go out of business within six months, per a frequently-cited US National Cyber Security Alliance benchmark.

The 60 percent figure is widely cited and the methodology is conservative-at-best, so treat it as directional. The conservative reading: a major email-driven incident is an existential event for a small business, not a line-item.

US National Cyber Security AlliancePublic Service Announcementstaysafeonline.org

Productivity and attention

Adobe, UC Irvine, IDC, Harvard Business Review, Adam Grant, and Cal Newport research on what email overload costs in attention, focus recovery, and recovered output.

Productivity and attention
88 percent

Of knowledge workers report being interrupted at least once every 30 minutes, per a 2022 Workfront / Adobe knowledge-worker study.

Almost everyone is interrupted at the half-hour cadence. Email and chat notifications are the most-cited interruption category. The defensive answer is not fewer emails; it is a cleaner inbox-arrival shape.

Adobe Workfront2022 State of Workbusiness.adobe.com
Productivity and attention
47 minutes

Average attention span of a knowledge worker on a single screen task in 2022, per Gloria Mark "Attention Span" research.

Down from over two minutes a decade earlier. Mark longitudinal research is the canonical citation for attention-is-shrinking. The downstream cost shows up in inbox-management research and knowledge-work output studies.

University of California, Irvine2022 to 2023ics.uci.edu
Productivity and attention
23 minutes

Time required to fully recover focus after a typical interruption, per Gloria Mark ongoing UC Irvine research.

The full recovery time. The shorter eleven-minute number is from earlier work; later studies put the full focus-restoration cost higher because workplace technology has gotten denser.

University of California, IrvineOngoingics.uci.edu
Productivity and attention
45 percent

Of knowledge workers report email as their largest single source of stress, per Adam Grant ongoing email-stress research summarized in "Originals" and follow-up essays.

Grant argument: high-output people compartmentalize email rather than attempt to live in it. The number itself is a survey response and varies by industry; the direction is durable.

Wharton (Adam Grant)2016 to presentadamgrant.net
Productivity and attention
74 percent

Of senior managers feel they cannot keep up with their inbox, per a 2019 Harvard Business Review survey on email overload.

Three quarters of senior managers feel the inbox has gotten ahead of them. The sentiment number matters less than the implication: at the margin, defensive email tooling pays off most for senior staff who set the productivity tone for the rest of the company.

Harvard Business Review2019hbr.org
Productivity and attention
8 percent

Productivity boost reported by Cal Newport deep-work practitioners who batch-process email twice per day instead of continuously, per the case studies in "A World Without Email."

The number is small per individual but compounds across a team. Newport case studies (engineering, professional services) show measurable per-team output recovery when email moves from a continuous-monitor surface to a batched one.

Cal Newport2021calnewport.com
Productivity and attention
40 percent

Of email is judged not worth reading by recipients in self-reported triage data, per the McKinsey 2012 Social Economy report.

Almost half. The McKinsey number has been cited continuously since publication. Reduce that 40 percent and recover the time. The cover-charge approach addresses this directly by making low-value cold mail uneconomical to send.

McKinsey Global Institute2012mckinsey.com

Email infrastructure and deliverability

Valimail, Alphabet, Microsoft, and Litmus data on DMARC adoption, mailbox provider scale, and where mail actually gets opened.

Email infrastructure and deliverability
85 percent

Of major brand domains have published a DMARC record as of 2024, per the latest Valimail Email Fraud Landscape Report.

Adoption is high among visible brands. Adoption among small and mid-market firms is much lower, which is where the BEC pattern actually lands. DMARC is necessary but not sufficient; it is part of a stack, not the stack.

Valimail2024 Email Fraud Landscape Reportvalimail.com
Email infrastructure and deliverability
34 percent

Of brand domains use the strict p=reject DMARC policy that actually blocks unauthenticated mail, per Valimail 2024.

Most domains publish DMARC at p=none (monitor only). The number that actually blocks impersonated mail is much smaller than the headline adoption rate suggests. Monitor mode without enforcement is an audit checkbox, not a defense.

Valimail2024 Email Fraud Landscape Reportvalimail.com
Email infrastructure and deliverability
1.8B users

Approximate Gmail user count as of 2023, per Google Q4 2023 reporting.

Gmail is the single largest mailbox surface in the world. Google sender requirements (DMARC, one-click unsubscribe, 0.3 percent spam-rate cap) effectively become the de-facto standard the rest of the industry tracks.

Alphabet Q4 20232023abc.xyz
Email infrastructure and deliverability
400M seats

Approximate Microsoft 365 commercial seat count as of FY2024, per Microsoft public reporting.

Microsoft 365 is the second-largest mailbox surface and dominates business email. The combined Gmail-plus-Microsoft 365 footprint covers the overwhelming majority of business inboxes worldwide; defense at the application layer above either is what most users actually need.

Microsoft FY2024 reporting2024microsoft.com
Email infrastructure and deliverability
46 percent

Of email opens happen on a mobile device, per Litmus 2024 Email Engagement data.

Roughly half of all opens are on mobile, which means the user has even less context (no preview pane, smaller header) when deciding whether to engage. The structural answer is to filter before delivery, not at the open.

Litmus2024litmus.com

suggestions welcome

Have a stat we should add?

If a foundational number is missing, or a recent report should join this index, send it our way. Email partners@rythm.xyz with the statistic, the source publisher, the year, and the link. The founder reviews suggestions personally.

We add entries on a rolling basis and refresh annually as new FBI IC3, IBM, Verizon DBIR, APWG, and Microsoft editions ship. We do not pay for placement and we do not republish; we link to the original publisher.

One plan. One price.

Keep your existing Gmail or Outlook. Cancel anytime.

$1.65
per month
Start protecting

Annual on Lightning includes one bonus month. See full pricing.