Attack vector
Phishing attacks cost $4.8M and take 254 days to contain.
Phishing, where an attacker tricks an employee into surrendering a credential or running malware through a fraudulent email, text, or phone call, was the single most common initial attack vector in the IBM Cost of a Data Breach Report 2025, responsible for 16% of breaches. It averaged $4.8M per breach and took 254 days to identify and contain, 13 days above the 241-day all-breach average, because a login obtained by deception looks exactly like a legitimate one.
Average cost
$4.8M
IBM 2025, Figure 9
Time to contain
254 days
13 days over average
Cost premium
+8%
vs $4.44M all-breach avg
Share of breaches
16%
Most common vector, IBM 2025
Section PH.1
Why phishing is the most common initial vector
In IBM's 2025 analysis phishing regained the top spot, overtaking stolen credentials as the entry point behind 16% of breaches. The reason is economic on the attacker's side: phishing is the cheapest, most scalable way to defeat every technical control at once, because it targets the human authorised to bypass them.
Firewalls, endpoint detection, and network segmentation all assume the attacker is an outsider trying to force entry. Phishing sidesteps that model entirely: it persuades an insider to open the door. The employee's credentials are valid, their session is legitimate, and the malware they were tricked into running executes with their permissions. There is nothing anomalous for perimeter tooling to catch, which is why phishing scales to volumes no other vector matches and why it stays the most common entry point year after year.
That same legitimacy is what stretches the lifecycle to 254 days. Once an attacker holds a real credential, their activity blends into normal traffic, so identification and containment run 13 days longer than the 241-day all-breach average. IBM's data is consistent across every edition: the longer a breach goes uncontained, the more it costs. Breaches contained in under 200 days averaged $3.87M in 2025; those running beyond 200 days averaged $5.01M, a $1.14M (29%) premium. A phishing breach, at a mean 254-day lifecycle, sits in the expensive half of that distribution.
Section PH.2
Phishing against the other initial vectors
IBM's 2025 Figure 9 ranks initial attack vectors by average breach cost. Phishing sits in the upper cluster on cost, but its defining feature is frequency: no other vector accounts for a larger share of breaches, so its aggregate contribution to global breach cost is the largest of any single entry point.
Social engineering via fraudulent communications (16% of breaches, the most common vector). The dollar figures are the IBM 2025 initial-vector averages; what sets phishing apart is not that it is the costliest per incident, but that it is the most frequent, so it drives more total breach cost than any vector above it on this chart.
Primary source:IBM Cost of a Data Breach Report 2025, Figure 9 (average cost of a breach by initial attack vector) and the breach-lifecycle-by-vector data (phishing 254 days to identify and contain, the most common vector at 16% of breaches).
Section PH.3
From spear-phishing email to help-desk voice call
Phishing is not a single technique but a family of them, and the two case files below mark its range: a 2015 spear-phishing email that opened a year of undetected access, and a 2023 voice-phishing campaign that walked past MFA by calling the help desk.
Anthem 2015 / Spear-phishing
$260M+
78.8M records, near a year of dwell time
The intrusion began on 18 February 2014 with a spear-phishing email to a handful of Anthem employees. One click downloaded a backdoor, and the attacker then remained in the network for nearly a year, escalating privileges and mapping the data warehouse before exfiltrating 78.8M member records in early 2015. That long dwell time, the phishing lifecycle in one case, drove a cumulative cost above $260M including a $115M class-action settlement and a then-record $16M OCR HIPAA penalty.
Scattered Spider 2023 / Vishing
~$100M
MGM operational impact; Caesars paid ~$15M
Phishing has moved to the phone. In September 2023 the Scattered Spider group breached both MGM Resorts and Caesars Entertainment not with an email but by voice-phishing IT help desks: they used LinkedIn to impersonate employees and talked support staff into resetting credentials and MFA, defeating multi-factor controls through the human on the other end. MGM absorbed a ten-day outage estimated near $100M in impact; Caesars paid a ~$15M ransom to keep trading. The technique changed; the vector did not.
Section PH.4
The 2026 update: AI writes the lure now
The IBM Cost of a Data Breach Report 2026 (released 29 July 2026) found that roughly one in four malicious breaches now involves attacker use of AI, and an AI-enabled breach averaged $6M, about $1M above the $4.99M global average. Phishing is where that shift lands first: generative AI removes the two tells defenders and employees relied on, the clumsy grammar and the generic greeting, and lets an attacker produce a fluent, personalised lure in minutes rather than hours. The vector stays the same, but the hit rate rises, which is why phishing awareness training and phishing-resistant (FIDO2 / passkey) authentication move up the control priority list rather than down it.
Primary source:IBM Cost of a Data Breach Report 2026 (released 29 July 2026): AI-enabled breach average $6M, global average $4.99M, roughly 1 in 4 malicious breaches AI-enabled.
Cross-references
Case / Anthem 2015
→$260M+, 78.8M records. The spear-phishing email that opened a year of access.
Case / MGM 2023
→~$100M operational impact. Help-desk vishing and a ten-day outage.
Case / Caesars 2023
→~$15M ransom paid. The pay-side counterpart to MGM, same phishing crew.
Vector / Supply chain
→$4.91M average, 267-day lifecycle. The slowest vector to contain.
Reference / Global statistics
→Full attack-vector cost table, lifecycle data, year-over-year trends.
Prevention / Control ROI
→Where phishing-resistant MFA and awareness training rank on cost saved.
Schedule F / Reference Q&A
Frequently Asked Questions
Primary source:Attack-vector cost, 254-day phishing lifecycle, and 16% most-common-vector share from the IBM Cost of a Data Breach Report 2025; AI-enabled breach figures from the IBM Cost of a Data Breach Report 2026; Anthem, MGM, and Caesars case figures as cited on their case files.