Learning to avoid phishing scams matters more than almost any other single security habit — phishing is the most-reported crime type in the FBI’s own crime data, and real losses run into the billions every year. Antivirus and VPNs both have honest, well-defined limits against it, since phishing targets human judgment directly rather than your network connection or your files. Here’s what the real 2025-2026 statistics show, the distinct subtypes of phishing you’re actually likely to encounter, four named real cases, and what actually works — including where to report it if it happens to you.


Table of Contents
The Real Scale of Phishing: Government and Industry Data
FBI IC3 2025 Annual Report
The FBI’s IC3 2025 Internet Crime Report recorded over 1 million total complaints (up from 859,532 in 2024) and roughly $20.9 billion in total losses, a 26% year-over-year jump. Phishing/spoofing was the single most-reported crime category by complaint volume — ahead of every other crime type the FBI tracks. (FBI IC3 2025 Annual Report) Business Email Compromise specifically — a phishing-driven crime — accounted for $3.046 billion in losses, with an average loss per complaint over $122,000.
APWG Q1 2026 Trends Report
The Anti-Phishing Working Group’s Q1 2026 Phishing Activity Trends Report (released May 2026) recorded phishing attacks rising 13.8% quarter-over-quarter, from 853,244 (Q4 2025) to 971,181 attacks (Q1 2026). Impersonation made up 43.8% of social-media-based threats, and telephone-based fraud (vishing/smishing) rose 15% in the same quarter — a real, measured sign that phishing is expanding beyond the classic “fake email” format most people picture. (APWG Q1 2026 Report)
Phishing Isn’t Just One Thing: Understanding the Subtypes
Most people picture a generic “click this link” email when they hear “phishing.” In practice, the term covers several distinct attack styles, each with real, documented cases behind it.
Spear Phishing and Whaling: The FACC Case
Spear phishing targets a specific individual using research about them; “whaling” is spear phishing aimed specifically at executives. The clearest real, named example: in January 2016, attackers who had already breached Austrian aerospace parts manufacturer FACC‘s email systems studied the CEO’s actual writing style, then sent a convincingly spoofed email to a finance employee instructing a €42 million wire transfer for a fake “acquisition project.” FACC recovered roughly €10.9 million of it. The fallout was severe enough that FACC’s supervisory board fired CEO Walter Stephan on May 24, 2016 — a rare case where a phishing scam cost a real executive his job, not just the company its money. (Trend Micro; SecurityWeek)
Smishing: The 2024 FBI Toll-Scam Warning
Smishing is phishing delivered by text message rather than email. In April 2024, the FBI issued a public warning about a large, coordinated smishing campaign impersonating toll-road collection agencies — fake texts claiming an unpaid toll, with a link to a fraudulent payment page. IC3 had logged over 2,000 complaints tied to this specific campaign since early March 2024 alone. (Newsweek; official guidance also published by the FCC)
Business Email Compromise (BEC)
BEC doesn’t always involve a fake link at all — often it’s simply a convincingly spoofed sender address requesting a legitimate-looking wire transfer or payroll change, exactly as in the FACC case above. It’s the single most financially damaging phishing subtype tracked by the FBI, at over $3 billion in 2025 losses alone, precisely because it targets people already authorized to move money, rather than trying to steal a password first.
More Real, Named Phishing Cases
Evaldas Rimasauskas vs. Google & Facebook (2013–2015)
A Lithuanian man set up a fake company impersonating Taiwanese hardware supplier Quanta Computer, using forged invoices and contracts to trick finance staff at both companies into wiring money. He defrauded Google and Facebook of a combined figure widely reported between $100–122 million before pleading guilty to wire fraud in March 2019; he was sentenced to 5 years and ordered to forfeit roughly $50 million. (NPR, March 2019)
Reddit, February 2023
An employee was phished via a fake site cloning Reddit’s internal login page — a real-time “adversary-in-the-middle” proxy that captured both the password and the live two-factor code, bypassing 2FA entirely. See our full two-factor authentication guide for how this specific attack works and how hardware security keys resist it. (TechCrunch, Feb 2023)
Massachusetts Workers’ Union BEC Case
The U.S. Secret Service announced the forfeiture of over $5.3 million traceable to a Business Email Compromise scheme targeting a Massachusetts workers’ union, publicized in March 2025 — a real, government-confirmed case with a specific dollar figure. (U.S. Secret Service, March 2025)
Vishing: Phishing by Phone
Vishing (voice phishing) is a real, growing category — the APWG’s own Q1 2026 data shows telephone-based fraud rising 15% quarter-over-quarter — but named, fully-attributed vishing cases are rarer in public reporting than email-based cases, largely because victim organizations are frequently kept anonymous by the outlets covering them. A widely-circulated 2019 Wall Street Journal report described a UK-based energy firm losing roughly $243,000 after an employee was fooled by an AI-generated voice clone of the parent company’s CEO on a phone call — a real, dated report from a credible outlet, though the company itself was never publicly named, so treat the specific figure as reported-but-anonymized rather than independently verified the way the FACC or Reddit cases are.
The practical defense against vishing doesn’t depend on identifying every case by name: never act on a phone request for money, credentials, or account changes in the moment, no matter how urgent or how convincing the caller’s voice sounds. Hang up and call back using a number you already have on file — from a statement, a card, or an official website you type in yourself — not a number the caller gives you or that appears on your caller ID, which can be spoofed.
How to Actually Spot a Phishing Attempt


- Check the actual sending domain, not just the display name — a display name can say “Your Bank” while the real address is completely unrelated.
- Be suspicious of urgency — “your account will be suspended,” “wire this today” — urgency is a deliberate manipulation tactic used across nearly every real case above, including the €42 million FACC scheme.
- Never click a link in an unexpected email to log in — type the site’s real address directly, or use a saved bookmark.
- Verify unusual payment or wire requests by phone, using a number you already have on file, not one provided in the email itself — this single habit would have stopped the Massachusetts BEC case above.
- Watch for a password manager that won’t autofill — if your password manager doesn’t offer to fill your saved login on a page that looks right, that’s a real, concrete warning sign, since it only autofills on the exact domain you originally saved it for.
Spotting Smishing Specifically
Text-based phishing has its own tells: a link using a shortened or unfamiliar URL rather than the real organization’s domain, a message claiming urgency around a small, plausible-sounding amount (a toll, a delivery fee, a parking fine — exactly the 2024 FBI-flagged campaign’s pattern), and a sender number that’s an ordinary phone number rather than the short code a real company typically uses for automated texts.


Why Phishing Works, Even on Careful People
Every case in this guide, from a single consumer text message to a €42 million wire transfer, relies on the same small set of psychological levers, not technical sophistication. Recognizing the lever being pulled is often a faster defense than trying to spot a technical tell.
Authority
A message that appears to come from a CEO, a bank’s fraud department, or a government agency triggers a learned instinct to comply quickly rather than question the request — exactly what made the FACC whaling attack work on an otherwise competent finance employee.
Urgency and Scarcity
A deadline, a threatened account suspension, or a small unpaid toll with a looming late fee (the exact pattern behind the 2024 FBI-flagged smishing wave) is designed to get you to act before you’ve had time to verify anything. The fix is procedural, not vigilance-based: build a personal rule that any urgent financial or account request gets verified through a channel you already trust, every time, regardless of how convincing it feels in the moment.
Familiarity
A cloned company logo, a spoofed sender name, or — increasingly — an AI-generated voice matching someone you actually know all exploit the same shortcut: your brain treats “looks/sounds familiar” as a proxy for “safe,” even though familiarity is trivially easy to fake with modern tools. Verifying through a second, independent channel breaks this shortcut regardless of how convincing the original message was.
What Your Security Tools Actually Do (and Don’t) Against Phishing
Being honest about tool limitations matters here:
- Antivirus real-time protection is built to catch malicious files and known-bad URLs via signature or blacklist matching — useful, but reactive. A brand-new phishing domain registered hours ago is frequently not yet on any blacklist. See our honest antivirus comparison for real AV-TEST and AV-Comparatives data on each provider.
- A VPN encrypts your network connection; it does nothing to stop you from voluntarily entering credentials into a convincing fake page. See our VPN for online banking guide for the full breakdown of what a VPN does and doesn’t cover.
- A password manager’s domain-matching autofill is one of the few tools that directly targets this exact attack — it won’t fill credentials on a lookalike domain, giving you a visible signal before you manually type anything.
- Two-factor authentication helps, but as the 2023 Reddit case shows, SMS and app-based codes can still be relayed in real time by a sophisticated phishing kit — a hardware security key or passkey is the one method specifically designed to resist this.
How to Report Phishing
Reporting isn’t just for your own protection — it feeds the same data these organizations use to track and shut down active campaigns.
- APWG — forward phishing emails to reportphishing@apwg.org, APWG’s official submission address; these reports feed directly into its own eCrime data and the quarterly Phishing Activity Trends Reports cited throughout this guide. (APWG)
- Google Safe Browsing — has its own official mechanism for reporting phishing and malware URLs, which feeds into the same blocklist used across Chrome, Firefox, and Safari’s built-in fraud warnings.
- FBI’s IC3 (ic3.gov) — the correct official channel specifically when you’ve experienced a financial loss or identity theft, not just received a suspicious message.
Avoid Phishing Scams: Frequently Asked Questions
What’s the single best way to avoid phishing scams?
No single tool is complete — the strongest combination is a password manager with domain-matching autofill, a hardware security key or passkey for two-factor authentication where supported, and the habit of never clicking login links from unexpected emails or texts.
Can antivirus software stop phishing emails?
Partially — it can block some known-malicious attachments and blacklisted URLs, but brand-new phishing domains are frequently not yet blacklisted anywhere, so it’s not a complete defense on its own.
What’s the difference between phishing, spear phishing, and whaling?
Phishing is a broad, often mass-sent attempt; spear phishing targets a specific individual using research about them; whaling is spear phishing aimed specifically at executives, as in the real €42 million FACC case that cost a CEO his job.
How common is phishing really?
Very — per the FBI’s own IC3 2025 data, phishing/spoofing is the most-reported crime category by complaint volume, and the Anti-Phishing Working Group recorded 971,181 phishing attacks in Q1 2026 alone, up 13.8% from the previous quarter.
What should I do if I think I’ve been phished?
Change the affected password immediately (from a different, trusted device if possible), enable or verify two-factor authentication, check for unauthorized activity, and report it to APWG, Google Safe Browsing, and, for financial losses, to the FBI’s IC3 at ic3.gov.
What is vishing and how common is it?
Vishing is phishing conducted by phone, including AI-generated voice cloning of someone the victim trusts. APWG’s Q1 2026 data shows telephone-based fraud rose 15% quarter-over-quarter, though fully-named vishing cases are rarer in public reporting than email-based ones.
Why do smart, careful people still fall for phishing?
Phishing exploits universal psychological shortcuts — authority, urgency, and familiarity — rather than technical weaknesses, which is why even security-conscious people can be fooled by a well-crafted attack like the real €42 million FACC case.

