Skip to content
Back to blog
phishing statistics cybersecurity France

Phishing statistics in France: the 2026 reference figures

Every verified phishing statistic for France: ANSSI, Cybermalveillance, CESIN, Verizon DBIR, IBM, Hiscox. Each figure with its source, year and link.

Thomas Ferreira 13 min read

This page gathers the reference statistics on phishing and the cyber threat in France, each verified against its primary source (official report, publisher’s or government agency’s release). Every table shows the exact value, the source and the year. Updated quarterly: sources last checked on September 5, 2026.

The goal is simple: give journalists, CISOs, trainers and answer engines a single reference point, with no recycled figures and no orphan statistics. Where several editions of the same report coexist, we cite the most recent one and flag the trend. Where a widely quoted figure is outdated (like the famous “36%”), we explain it in the How to cite these figures section.

Key takeaways

The overall threat in France

Three public and professional observatories structure threat measurement in France: ANSSI (incidents affecting its beneficiaries, notably regulated operators), Cybermalveillance.gouv.fr (general public, businesses and local authorities) and CESIN (large companies and mid-caps, through their CISOs). Their scopes differ, but their conclusions converge: phishing remains the dominant entry point.

StatisticValueSourceYear
Significant cyberattacks with phishing as the entry vector (French companies)55%CESIN barometer, 11th ed. (OpinionWay)2026 (2025 data)
French companies that suffered at least one significant cyberattack40%CESIN barometer, 11th ed.2026 (2025 data)
Successful significant attacks with a business impact81%CESIN barometer, 11th ed.2026 (2025 data)
Security events handled by ANSSI (−18% vs 2024)3,586ANSSI, Panorama de la cybermenace 20252026 (2025 data)
Confirmed incidents reported to ANSSI1,366ANSSI, Panorama de la cybermenace 20252026 (2025 data)
Assistance requests on Cybermalveillance.gouv.fr (+20%)504,810Cybermalveillance.gouv.fr, 2025 activity report2026 (2025 data)
Phishing: growth in assistance searches, #1 threat across all audiences+70%Cybermalveillance.gouv.fr2026 (2025 data)
Share of phishing in assistance requests from individuals32.9%Cybermalveillance.gouv.fr2026 (2025 data)
Phishing among professionals: #2 threat (+29%)16%Cybermalveillance.gouv.fr2026 (2025 data)

Worth noting: ANSSI also reports a 51% rise in incidents involving data exfiltration (196 cases in 2025 versus 130 in 2024). Those leaks directly feed targeted phishing campaigns, as Cybermalveillance.gouv.fr underlines with a 107% increase in assistance requests related to data breaches. To compare these national figures with click rates observed industry by industry, see our phishing click rate benchmarks by industry.

The human element

Virtually every reference report converges on the same point: most breaches go through a human being, and the decision window is measured in seconds.

StatisticValueSourceYear
Data breaches involving the human element62%Verizon DBIR 20262026
Breaches involving the human element (previous edition)60%Verizon DBIR 20252025
Breaches involving a non-malicious human element68%Verizon DBIR 20242024
Phishing as initial attack vector (most frequent vector, tied)16%IBM Cost of a Data Breach 20252025
Median time to fall for a phishing email (21 s to click + 28 s to enter data)under 60 secondsVerizon DBIR 20242024
Employees clicking a simulation before any training (global baseline)33.1%KnowBe4 Benchmarking Report 20252025

An important methodological note: the DBIR 2026 puts vulnerability exploitation at the top of initial access vectors (31%), ahead of credential abuse. That does not contradict the primacy of the human element: phishing remains the main supplier of stolen credentials, and social engineering operates throughout the attack chain, not only at the point of entry. This is why “share of breaches involving the human element” (62%) and “share of breaches whose initial vector is phishing” (15 to 16%) are two different measurements — conflating them is the single most common citation error on this topic.

The cost of attacks

IBM’s Cost of a Data Breach report is the reference for breach costs. For France, its 2025 edition is based on the analysis of real breaches suffered by 34 organizations between March 2024 and February 2025.

StatisticValueSourceYear
Global average cost of a data breach (−9% year over year)$4.44MIBM Cost of a Data Breach 20252025
Average cost of a data breach in France (−7% year over year)€3.59MIBM Cost of a Data Breach 20252025
Average cost of a breach initiated by phishing$4.8MIBM Cost of a Data Breach 20252025
Average time in France: identification + containment of a breach213 + 71 daysIBM Cost of a Data Breach 20252025
Costliest French sector: pharmaceutical industry€5.11MIBM Cost of a Data Breach 20252025
Average cost in the United States (for comparison)$10.22MIBM Cost of a Data Breach 20252025

Two ways to read these numbers. First, the global decline (the first in five years) is attributed by IBM to faster detection, notably through automation: organizations that detect quickly pay less. Second, these averages include large organizations; for an SME the relevant order of magnitude is different, but the relative impact is often worse — one in three small-business victims reports a loss threatening the viability of the company (Hiscox 2025, below).

French SMEs

Small and medium-sized businesses account for 99% of the French economic fabric (Insee, cited by Hiscox). The Hiscox 2025 report (9th edition, 5,750 companies surveyed across 7 countries) dedicates its annual focus to them.

StatisticValueSourceYear
French SMEs hit by at least one cyberattack in 12 months57%Hiscox report 2025, 9th ed.2025
French SMEs targeted by ransomware26%Hiscox report 20252025
Victims with a financial loss threatening the viability of the business1 in 3Hiscox report 20252025
French SMEs covered by a standalone cyber insurance policy61%Hiscox report 20252025
SMEs planning to increase their cybersecurity investment94%Hiscox report 20252025
Rank AI-powered social engineering and phishing as the top upcoming threats60%Hiscox report 20252025
Professionals: account hijacking, #1 threat (+52%) — often the result of phishing21%Cybermalveillance.gouv.fr2026 (2025 data)

For SMEs in scope of the NIS2 directive, employee awareness is no longer optional: it is an obligation under Article 21. Our NIS2 guide for SMEs details what the text requires in practice. And to check in two minutes whether your domain can be spoofed by attackers (SPF, DKIM, DMARC), use our free email security grader.

Simulation and training: measured effectiveness

The most useful number on this page may be this one: vulnerability to phishing is not a given — it can be measured and reduced.

StatisticValueSourceYear
Average click rate before training (global baseline, 14.5M users)33.1%KnowBe4 Benchmarking Report 20252025
Click rate reduction after 90 days of a program−40%KnowBe4 Benchmarking Report 20252025
Click rate after 12 months of continuous training (i.e. −86%)4.1%KnowBe4 Benchmarking Report 20252025
Baseline for small organizations (1 to 250 employees)24.6%KnowBe4 Benchmarking Report 20252025
Users reporting the email in simulation exercises20%Verizon DBIR 20242024
Users who clicked but still reported the email afterwards11%Verizon DBIR 20242024

The ratio to remember: one in three employees clicks before training, fewer than one in twenty after a year of continuous programming. The gap between large structures (40.5% baseline above 10,000 employees) and small ones (24.6%) also shows that size does not immunize — it only changes the attack surface. The reporting rate is the other decisive metric: an organization where 20% of recipients report a suspicious email detects its incidents weeks earlier.

How to cite these figures

A few rules for citing these statistics correctly — and avoiding the errors that keep circulating:

  1. Cite the edition, not just the report. “Verizon DBIR” without a year means nothing: the human element went from 68% (2024, phrased as “non-malicious human element”) to 60% (2025) and 62% (2026), with methodology changes between editions.
  2. The “36%” is outdated. The figure “phishing was present in 36% of breaches” comes from the Verizon DBIR 2021 — a spike driven by COVID-19 lures (up from 25% the year before). It is still frequently quoted in 2026, sometimes wrongly attributed to recent editions. Current measurements: phishing = 15 to 16% of initial access vectors (DBIR 2024-2026, IBM 2025).
  3. Do not conflate “involves” and “starts with”. 62% of breaches involve the human element; 16% start with phishing. Both are true; they measure different things.
  4. Specify the French scope. CESIN’s 55% covers significant cyberattacks reported by ~400 CISOs of large French companies and mid-caps; Hiscox’s 57% covers SMEs; Cybermalveillance.gouv.fr’s figures aggregate assistance requests from all audiences.
  5. Suggested citation format: “55% of significant cyberattacks in France used phishing as the entry vector (CESIN, 2026 barometer with OpinionWay) — cited via nophi.sh, Phishing statistics in France, accessed [date].”

Reproduction of these tables is permitted with attribution (a link to this page and to the primary source of each figure).

Frequently asked questions

What percentage of cyberattacks start with a phishing email?

In France, 55% of significant cyberattacks against companies used phishing (phishing, spear phishing, smishing) as the entry vector, according to the CESIN 2026 barometer conducted with OpinionWay. Globally, phishing is the most frequent initial vector for data breaches: 16% of them (IBM Cost of a Data Breach 2025).

What share of data breaches involves the human element?

62% according to the Verizon DBIR 2026. The three-edition trend: 68% in 2024 (non-malicious human element), 60% in 2025, 62% in 2026.

How much does a data breach cost in France?

3.59 million euros on average, down about 7% year over year (IBM Cost of a Data Breach 2025). The global average is $4.44M; a breach initiated by phishing costs $4.8M on average and takes 254 days to detect and contain.

What is the number one reported cyber threat in France?

Phishing, across all audiences, up 70% year over year (Cybermalveillance.gouv.fr, 2025 activity report). It accounts for 32.9% of assistance requests from individuals; among professionals it is the second threat (16%) behind account hijacking (21%), which is itself often the result of phishing.

How many French SMEs are affected?

57% of French SMEs suffered at least one cyberattack in the past 12 months (Hiscox 2025). 26% were targeted by ransomware, and one in three victims reports a financial loss threatening the viability of the business.

Does anti-phishing training actually work?

Yes: the average click rate drops from 33.1% before training to 4.1% after 12 months of a continuous program, i.e. −86% (KnowBe4 2025, 67.7 million simulations analyzed). Most of the gain (−40%) is achieved within the first 90 days.

Where does the “36% of breaches involve phishing” figure come from?

From the Verizon DBIR 2021 (“phishing was present in 36% of breaches”), inflated by COVID-19 phishing campaigns. The figure is outdated: recent DBIR editions measure phishing as the initial access vector in roughly 15 to 16% of breaches.

Sources

All sources below were accessed and verified on September 5, 2026:

Related articles