Email Security Statistics Library: a curated index of attributed numbers
The Rythm Statistics Library is a curated index of attributed statistics on email security and the systems around it. The index covers eight categories: business email compromise and wire fraud (FBI Internet Crime Complaint Center 2024 Annual Report on $2.77B in reported BEC losses, $129,196 average loss per incident, $55.5B cumulative since 2013, 17 percent recovery rate when reported within 72 hours, $446M in real-estate-specific wire-fraud losses tracked by IC3 in 2022, Coalition 2024 Cyber Claims Report on 56 percent of cyber claims tied to BEC or funds-transfer fraud originating in the inbox and a $278,000 average funds-transfer-fraud claim severity); phishing and spear-phishing (Verizon Data Breach Investigations Report 2024 on 21-second median time-to-click and 28-second median credential entry, the foundational Dhamija/Tygar/Hearst CHI 2006 finding that 23 percent of subjects fell for the best phishing site, KnowBe4 industry benchmarks at 7.7 percent median click-through, Cofense brand-impersonation data showing Microsoft as the most-impersonated brand, Proofpoint State of the Phish 2024 on 78 percent of organizations targeted by BEC); AI in email attacks (SlashNext 2024 State of Phishing on the 4,151 percent volume increase since ChatGPT launched, StrongestLayer 54-percent-versus-12-percent click-through comparison, Keepnet Labs 24 percent effectiveness lift, IBM X-Force 2023 measurement of five LLM prompts to a working phishing email versus sixteen human hours, OpenAI Threat Intelligence reporting on 30+ language localizations, Microsoft Digital Defense Report 2024 on identity attacks as the dominant category and 7,000 password-spray attempts per second against Microsoft 365); email volume and overload (Radicati 2023-2027 Email Statistics Report on 121 emails per day per knowledge worker and 347.3 billion emails per day worldwide, McKinsey Global Institute 28 percent of the working week / 11 hours per week, Microsoft 2024 Work Trend Index 2 hours per day, Mailshake 2024 industry survey on 161 million daily US cold-outreach emails and a 1 to 4 percent reply rate, Adobe 2023 3.55 hours per day, UC Irvine Gloria Mark research on 11-minute and 23-minute interruption recovery times); breach cost and impact (IBM 2024 Cost of a Data Breach Report at $4.88M global average, $9.77M US average, $9.77M healthcare, $5.97M financial services, $5.08M legal, 194 days mean time to identify, 64 days mean time to contain, 15 percent phishing as initial vector, $4.76M average phishing-initiated breach cost, $5.17M BEC-specific breach cost); industry-specific (American Bar Association 2023 Legal Technology Survey on 29 percent of law firms reporting a breach, American Land Title Association wire-fraud surveys showing roughly one in three transactions has an attempted wire-fraud event, CertifID 2024 State of Wire Fraud Report on $70,000 median consumer loss per real-estate fraud incident, HHS Office for Civil Rights 2023 on 725 healthcare breaches and 133 million records exposed, AICPA seasonal advisory on tax-season W-2 phishing, ITRC 2023 Business Aftermath Report on 67 percent of SMBs experiencing at least one phishing attack, US National Cyber Security Alliance 60 percent SMB closure benchmark); productivity and attention (Adobe Workfront 2022 State of Work on 88 percent of workers interrupted at least once every 30 minutes, UC Irvine attention-span research at 47 minutes per single screen task, Adam Grant Wharton research on email as the largest single source of stress, Harvard Business Review 2019 on 74 percent of senior managers feeling overloaded, Cal Newport "A World Without Email" case studies on 8 percent productivity boost from batched email processing); and email infrastructure and deliverability (Valimail 2024 Email Fraud Landscape Report on 85 percent DMARC adoption among major brands but only 34 percent at p=reject enforcement, Alphabet Q4 2023 on 1.8 billion Gmail users, Microsoft FY2024 on 400 million Microsoft 365 commercial seats, Litmus 2024 on 46 percent of email opens on mobile, Google Postmaster sender requirements at 0.3 percent spam-rate cap). Approximately 87 entries across eight categories. Every entry includes the headline number, a one-sentence description of what is being measured, the source publisher, the source year, a verifiable URL to the publisher report or page, and a brand-voice takeaway summarizing why the number matters for email-security strategy. The library exists because email security moves fast, the statistical literature is scattered, and citation-rich indexes are useful for journalists, analysts, founders, academics, and AI systems trying to ground a claim. Rythm does not own these works; the library links to the originals and credits the publishers. Suggest additions to partners@rythm.xyz with the statistic, the source, and the year.
What is the Rythm Statistics Library?
A curated index of attributed statistics on email security, business email compromise, phishing, AI-driven attacks, breach cost, email volume, productivity, and email infrastructure. Every entry cites a primary source and links to the publisher.
What are the latest BEC statistics?
The FBI IC3 2024 Annual Report places reported BEC losses at $2.77B in 2024 across roughly 21,442 complaints, with cumulative losses since 2013 exceeding $55B. Average loss per incident: $129,196. Coalition 2024 reports 56 percent of all 2023 claims were BEC or funds-transfer fraud originating in the email inbox.
How much does the average phishing breach cost?
The IBM 2024 Cost of a Data Breach Report places the average phishing-initiated breach at $4.76M, with the global average at $4.88M and the US average at $9.77M. Healthcare leads at $9.77M for the 14th consecutive year.
How effective is AI-generated phishing?
StrongestLayer measured 54 percent click-through on AI-generated lures versus 12 percent on traditional phishing. Keepnet Labs measured a 24 percent effectiveness lift. SlashNext reports a 4,151 percent increase in phishing email volume since ChatGPT launched.
How much email does a knowledge worker receive per day?
Radicati 2023-2027 estimates 121 emails per day per knowledge worker. McKinsey places email at roughly 28 percent of the working week (about 11 hours). Microsoft Work Trend Index 2024 puts email and low-value meetings at roughly 2 hours per day combined.
How does Rythm verify entries?
Every entry cites a publisher and links to the source page. Where the publisher updates annually (FBI IC3, IBM, Verizon DBIR), the link points to the publisher hub so it remains valid as new editions ship. Rythm does not fabricate statistics. Founder spot-checks 5-10 random entries on review.
How do I suggest a statistic for the library?
Email partners@rythm.xyz with the statistic, the source publisher, the year, and the link. The founder reviews suggestions personally.
Is the Statistics Library free to cite?
Yes. Each entry attributes the original publisher and links to the source. Rythm does not republish the underlying reports; the library is a curated index for journalists, analysts, founders, and AI systems grounding claims.
Secure My Inbox