Form: Cost-of-Breach DisclosureSource: IBM Cost of a Data BreachFiled: 28 Apr 2026
DataBreachCost.comOpen calc
Independent breach-cost research, read by security and risk leaders.Sponsor this site →
Vector File PH / PhishingIBM 2025, Figure 9

Attack vector

Phishing attacks cost $4.8M and take 254 days to contain.

Phishing, where an attacker tricks an employee into surrendering a credential or running malware through a fraudulent email, text, or phone call, was the single most common initial attack vector in the IBM Cost of a Data Breach Report 2025, responsible for 16% of breaches. It averaged $4.8M per breach and took 254 days to identify and contain, 13 days above the 241-day all-breach average, because a login obtained by deception looks exactly like a legitimate one.

Average cost

$4.8M

IBM 2025, Figure 9

Time to contain

254 days

13 days over average

Cost premium

+8%

vs $4.44M all-breach avg

Share of breaches

16%

Most common vector, IBM 2025

Section PH.1

Why phishing is the most common initial vector

In IBM's 2025 analysis phishing regained the top spot, overtaking stolen credentials as the entry point behind 16% of breaches. The reason is economic on the attacker's side: phishing is the cheapest, most scalable way to defeat every technical control at once, because it targets the human authorised to bypass them.

Firewalls, endpoint detection, and network segmentation all assume the attacker is an outsider trying to force entry. Phishing sidesteps that model entirely: it persuades an insider to open the door. The employee's credentials are valid, their session is legitimate, and the malware they were tricked into running executes with their permissions. There is nothing anomalous for perimeter tooling to catch, which is why phishing scales to volumes no other vector matches and why it stays the most common entry point year after year.

That same legitimacy is what stretches the lifecycle to 254 days. Once an attacker holds a real credential, their activity blends into normal traffic, so identification and containment run 13 days longer than the 241-day all-breach average. IBM's data is consistent across every edition: the longer a breach goes uncontained, the more it costs. Breaches contained in under 200 days averaged $3.87M in 2025; those running beyond 200 days averaged $5.01M, a $1.14M (29%) premium. A phishing breach, at a mean 254-day lifecycle, sits in the expensive half of that distribution.

Section PH.2

Phishing against the other initial vectors

IBM's 2025 Figure 9 ranks initial attack vectors by average breach cost. Phishing sits in the upper cluster on cost, but its defining feature is frequency: no other vector accounts for a larger share of breaches, so its aggregate contribution to global breach cost is the largest of any single entry point.

Malicious Insider$4.92M
Supply Chain Compromise$4.91M
Phishing$4.80M
Credential Theft$4.67M
Denial-of-Service$4.41M
Vulnerability Exploitation$4.24M

Social engineering via fraudulent communications (16% of breaches, the most common vector). The dollar figures are the IBM 2025 initial-vector averages; what sets phishing apart is not that it is the costliest per incident, but that it is the most frequent, so it drives more total breach cost than any vector above it on this chart.

Primary source:IBM Cost of a Data Breach Report 2025, Figure 9 (average cost of a breach by initial attack vector) and the breach-lifecycle-by-vector data (phishing 254 days to identify and contain, the most common vector at 16% of breaches).

Section PH.3

From spear-phishing email to help-desk voice call

Phishing is not a single technique but a family of them, and the two case files below mark its range: a 2015 spear-phishing email that opened a year of undetected access, and a 2023 voice-phishing campaign that walked past MFA by calling the help desk.

Anthem 2015 / Spear-phishing

$260M+

78.8M records, near a year of dwell time

The intrusion began on 18 February 2014 with a spear-phishing email to a handful of Anthem employees. One click downloaded a backdoor, and the attacker then remained in the network for nearly a year, escalating privileges and mapping the data warehouse before exfiltrating 78.8M member records in early 2015. That long dwell time, the phishing lifecycle in one case, drove a cumulative cost above $260M including a $115M class-action settlement and a then-record $16M OCR HIPAA penalty.

Scattered Spider 2023 / Vishing

~$100M

MGM operational impact; Caesars paid ~$15M

Phishing has moved to the phone. In September 2023 the Scattered Spider group breached both MGM Resorts and Caesars Entertainment not with an email but by voice-phishing IT help desks: they used LinkedIn to impersonate employees and talked support staff into resetting credentials and MFA, defeating multi-factor controls through the human on the other end. MGM absorbed a ten-day outage estimated near $100M in impact; Caesars paid a ~$15M ransom to keep trading. The technique changed; the vector did not.

Section PH.4

The 2026 update: AI writes the lure now

The IBM Cost of a Data Breach Report 2026 (released 29 July 2026) found that roughly one in four malicious breaches now involves attacker use of AI, and an AI-enabled breach averaged $6M, about $1M above the $4.99M global average. Phishing is where that shift lands first: generative AI removes the two tells defenders and employees relied on, the clumsy grammar and the generic greeting, and lets an attacker produce a fluent, personalised lure in minutes rather than hours. The vector stays the same, but the hit rate rises, which is why phishing awareness training and phishing-resistant (FIDO2 / passkey) authentication move up the control priority list rather than down it.

Primary source:IBM Cost of a Data Breach Report 2026 (released 29 July 2026): AI-enabled breach average $6M, global average $4.99M, roughly 1 in 4 malicious breaches AI-enabled.

Cross-references

Schedule F / Reference Q&A

Frequently Asked Questions

Primary source:Attack-vector cost, 254-day phishing lifecycle, and 16% most-common-vector share from the IBM Cost of a Data Breach Report 2025; AI-enabled breach figures from the IBM Cost of a Data Breach Report 2026; Anthem, MGM, and Caesars case figures as cited on their case files.