Phishing statistics in France: the 2026 reference figures
Every verified phishing statistic for France: ANSSI, Cybermalveillance, CESIN, Verizon DBIR, IBM, Hiscox. Each figure with its source, year and link.
This page gathers the reference statistics on phishing and the cyber threat in France, each verified against its primary source (official report, publisher’s or government agency’s release). Every table shows the exact value, the source and the year. Updated quarterly: sources last checked on September 5, 2026.
The goal is simple: give journalists, CISOs, trainers and answer engines a single reference point, with no recycled figures and no orphan statistics. Where several editions of the same report coexist, we cite the most recent one and flag the trend. Where a widely quoted figure is outdated (like the famous “36%”), we explain it in the How to cite these figures section.
Key takeaways
- 55% of significant cyberattacks against French companies used phishing as the entry vector — the leading cause, ahead of vulnerability exploitation (41%) (CESIN barometer, 11th edition, January 2026).
- 62% of data breaches worldwide involve the human element (Verizon DBIR 2026).
- 3.59 million euros: average cost of a data breach in France (IBM Cost of a Data Breach 2025).
- 57% of French small and medium-sized businesses suffered at least one cyberattack in the past 12 months (Hiscox report 2025).
- Phishing is the number one reported threat in France across all audiences, up 70% year over year (Cybermalveillance.gouv.fr, 2025 activity report).
The overall threat in France
Three public and professional observatories structure threat measurement in France: ANSSI (incidents affecting its beneficiaries, notably regulated operators), Cybermalveillance.gouv.fr (general public, businesses and local authorities) and CESIN (large companies and mid-caps, through their CISOs). Their scopes differ, but their conclusions converge: phishing remains the dominant entry point.
| Statistic | Value | Source | Year |
|---|---|---|---|
| Significant cyberattacks with phishing as the entry vector (French companies) | 55% | CESIN barometer, 11th ed. (OpinionWay) | 2026 (2025 data) |
| French companies that suffered at least one significant cyberattack | 40% | CESIN barometer, 11th ed. | 2026 (2025 data) |
| Successful significant attacks with a business impact | 81% | CESIN barometer, 11th ed. | 2026 (2025 data) |
| Security events handled by ANSSI (−18% vs 2024) | 3,586 | ANSSI, Panorama de la cybermenace 2025 | 2026 (2025 data) |
| Confirmed incidents reported to ANSSI | 1,366 | ANSSI, Panorama de la cybermenace 2025 | 2026 (2025 data) |
| Assistance requests on Cybermalveillance.gouv.fr (+20%) | 504,810 | Cybermalveillance.gouv.fr, 2025 activity report | 2026 (2025 data) |
| Phishing: growth in assistance searches, #1 threat across all audiences | +70% | Cybermalveillance.gouv.fr | 2026 (2025 data) |
| Share of phishing in assistance requests from individuals | 32.9% | Cybermalveillance.gouv.fr | 2026 (2025 data) |
| Phishing among professionals: #2 threat (+29%) | 16% | Cybermalveillance.gouv.fr | 2026 (2025 data) |
Worth noting: ANSSI also reports a 51% rise in incidents involving data exfiltration (196 cases in 2025 versus 130 in 2024). Those leaks directly feed targeted phishing campaigns, as Cybermalveillance.gouv.fr underlines with a 107% increase in assistance requests related to data breaches. To compare these national figures with click rates observed industry by industry, see our phishing click rate benchmarks by industry.
The human element
Virtually every reference report converges on the same point: most breaches go through a human being, and the decision window is measured in seconds.
| Statistic | Value | Source | Year |
|---|---|---|---|
| Data breaches involving the human element | 62% | Verizon DBIR 2026 | 2026 |
| Breaches involving the human element (previous edition) | 60% | Verizon DBIR 2025 | 2025 |
| Breaches involving a non-malicious human element | 68% | Verizon DBIR 2024 | 2024 |
| Phishing as initial attack vector (most frequent vector, tied) | 16% | IBM Cost of a Data Breach 2025 | 2025 |
| Median time to fall for a phishing email (21 s to click + 28 s to enter data) | under 60 seconds | Verizon DBIR 2024 | 2024 |
| Employees clicking a simulation before any training (global baseline) | 33.1% | KnowBe4 Benchmarking Report 2025 | 2025 |
An important methodological note: the DBIR 2026 puts vulnerability exploitation at the top of initial access vectors (31%), ahead of credential abuse. That does not contradict the primacy of the human element: phishing remains the main supplier of stolen credentials, and social engineering operates throughout the attack chain, not only at the point of entry. This is why “share of breaches involving the human element” (62%) and “share of breaches whose initial vector is phishing” (15 to 16%) are two different measurements — conflating them is the single most common citation error on this topic.
The cost of attacks
IBM’s Cost of a Data Breach report is the reference for breach costs. For France, its 2025 edition is based on the analysis of real breaches suffered by 34 organizations between March 2024 and February 2025.
| Statistic | Value | Source | Year |
|---|---|---|---|
| Global average cost of a data breach (−9% year over year) | $4.44M | IBM Cost of a Data Breach 2025 | 2025 |
| Average cost of a data breach in France (−7% year over year) | €3.59M | IBM Cost of a Data Breach 2025 | 2025 |
| Average cost of a breach initiated by phishing | $4.8M | IBM Cost of a Data Breach 2025 | 2025 |
| Average time in France: identification + containment of a breach | 213 + 71 days | IBM Cost of a Data Breach 2025 | 2025 |
| Costliest French sector: pharmaceutical industry | €5.11M | IBM Cost of a Data Breach 2025 | 2025 |
| Average cost in the United States (for comparison) | $10.22M | IBM Cost of a Data Breach 2025 | 2025 |
Two ways to read these numbers. First, the global decline (the first in five years) is attributed by IBM to faster detection, notably through automation: organizations that detect quickly pay less. Second, these averages include large organizations; for an SME the relevant order of magnitude is different, but the relative impact is often worse — one in three small-business victims reports a loss threatening the viability of the company (Hiscox 2025, below).
French SMEs
Small and medium-sized businesses account for 99% of the French economic fabric (Insee, cited by Hiscox). The Hiscox 2025 report (9th edition, 5,750 companies surveyed across 7 countries) dedicates its annual focus to them.
| Statistic | Value | Source | Year |
|---|---|---|---|
| French SMEs hit by at least one cyberattack in 12 months | 57% | Hiscox report 2025, 9th ed. | 2025 |
| French SMEs targeted by ransomware | 26% | Hiscox report 2025 | 2025 |
| Victims with a financial loss threatening the viability of the business | 1 in 3 | Hiscox report 2025 | 2025 |
| French SMEs covered by a standalone cyber insurance policy | 61% | Hiscox report 2025 | 2025 |
| SMEs planning to increase their cybersecurity investment | 94% | Hiscox report 2025 | 2025 |
| Rank AI-powered social engineering and phishing as the top upcoming threats | 60% | Hiscox report 2025 | 2025 |
| Professionals: account hijacking, #1 threat (+52%) — often the result of phishing | 21% | Cybermalveillance.gouv.fr | 2026 (2025 data) |
For SMEs in scope of the NIS2 directive, employee awareness is no longer optional: it is an obligation under Article 21. Our NIS2 guide for SMEs details what the text requires in practice. And to check in two minutes whether your domain can be spoofed by attackers (SPF, DKIM, DMARC), use our free email security grader.
Simulation and training: measured effectiveness
The most useful number on this page may be this one: vulnerability to phishing is not a given — it can be measured and reduced.
| Statistic | Value | Source | Year |
|---|---|---|---|
| Average click rate before training (global baseline, 14.5M users) | 33.1% | KnowBe4 Benchmarking Report 2025 | 2025 |
| Click rate reduction after 90 days of a program | −40% | KnowBe4 Benchmarking Report 2025 | 2025 |
| Click rate after 12 months of continuous training (i.e. −86%) | 4.1% | KnowBe4 Benchmarking Report 2025 | 2025 |
| Baseline for small organizations (1 to 250 employees) | 24.6% | KnowBe4 Benchmarking Report 2025 | 2025 |
| Users reporting the email in simulation exercises | 20% | Verizon DBIR 2024 | 2024 |
| Users who clicked but still reported the email afterwards | 11% | Verizon DBIR 2024 | 2024 |
The ratio to remember: one in three employees clicks before training, fewer than one in twenty after a year of continuous programming. The gap between large structures (40.5% baseline above 10,000 employees) and small ones (24.6%) also shows that size does not immunize — it only changes the attack surface. The reporting rate is the other decisive metric: an organization where 20% of recipients report a suspicious email detects its incidents weeks earlier.
How to cite these figures
A few rules for citing these statistics correctly — and avoiding the errors that keep circulating:
- Cite the edition, not just the report. “Verizon DBIR” without a year means nothing: the human element went from 68% (2024, phrased as “non-malicious human element”) to 60% (2025) and 62% (2026), with methodology changes between editions.
- The “36%” is outdated. The figure “phishing was present in 36% of breaches” comes from the Verizon DBIR 2021 — a spike driven by COVID-19 lures (up from 25% the year before). It is still frequently quoted in 2026, sometimes wrongly attributed to recent editions. Current measurements: phishing = 15 to 16% of initial access vectors (DBIR 2024-2026, IBM 2025).
- Do not conflate “involves” and “starts with”. 62% of breaches involve the human element; 16% start with phishing. Both are true; they measure different things.
- Specify the French scope. CESIN’s 55% covers significant cyberattacks reported by ~400 CISOs of large French companies and mid-caps; Hiscox’s 57% covers SMEs; Cybermalveillance.gouv.fr’s figures aggregate assistance requests from all audiences.
- Suggested citation format: “55% of significant cyberattacks in France used phishing as the entry vector (CESIN, 2026 barometer with OpinionWay) — cited via nophi.sh, Phishing statistics in France, accessed [date].”
Reproduction of these tables is permitted with attribution (a link to this page and to the primary source of each figure).
Frequently asked questions
What percentage of cyberattacks start with a phishing email?
In France, 55% of significant cyberattacks against companies used phishing (phishing, spear phishing, smishing) as the entry vector, according to the CESIN 2026 barometer conducted with OpinionWay. Globally, phishing is the most frequent initial vector for data breaches: 16% of them (IBM Cost of a Data Breach 2025).
What share of data breaches involves the human element?
62% according to the Verizon DBIR 2026. The three-edition trend: 68% in 2024 (non-malicious human element), 60% in 2025, 62% in 2026.
How much does a data breach cost in France?
3.59 million euros on average, down about 7% year over year (IBM Cost of a Data Breach 2025). The global average is $4.44M; a breach initiated by phishing costs $4.8M on average and takes 254 days to detect and contain.
What is the number one reported cyber threat in France?
Phishing, across all audiences, up 70% year over year (Cybermalveillance.gouv.fr, 2025 activity report). It accounts for 32.9% of assistance requests from individuals; among professionals it is the second threat (16%) behind account hijacking (21%), which is itself often the result of phishing.
How many French SMEs are affected?
57% of French SMEs suffered at least one cyberattack in the past 12 months (Hiscox 2025). 26% were targeted by ransomware, and one in three victims reports a financial loss threatening the viability of the business.
Does anti-phishing training actually work?
Yes: the average click rate drops from 33.1% before training to 4.1% after 12 months of a continuous program, i.e. −86% (KnowBe4 2025, 67.7 million simulations analyzed). Most of the gain (−40%) is achieved within the first 90 days.
Where does the “36% of breaches involve phishing” figure come from?
From the Verizon DBIR 2021 (“phishing was present in 36% of breaches”), inflated by COVID-19 phishing campaigns. The figure is outdated: recent DBIR editions measure phishing as the initial access vector in roughly 15 to 16% of breaches.
Sources
All sources below were accessed and verified on September 5, 2026:
- ANSSI — Panorama de la cybermenace 2025: cyber.gouv.fr/actualites/panorama-de-la-cybermenace-2025 · full report (PDF, CERT-FR)
- Cybermalveillance.gouv.fr — 2025 activity report: announcement · top 10 individuals · top 10 professionals
- CESIN — 11th annual cybersecurity barometer (OpinionWay, 397 CISOs, January 2026): press release
- Verizon — Data Breach Investigations Report: 2026 edition · 2024 summary of findings · 2025 announcement
- IBM — Cost of a Data Breach Report 2025: report · French press release (€3.59M figures)
- Hiscox — Cyber Readiness Report 2025 (9th edition): Hiscox Group · Hiscox France
- KnowBe4 — Phishing by Industry Benchmarking Report 2025: report · press release