Spam emails accounted for 47.27% of total global email traffic in 2024, per Kaspersky’s annual spam and phishing report, reversing a seven-year decline from the 2017 peak of approximately 56.6%. The shift matters because spam is no longer just a productivity tax. AI-driven phishing kits and Business Email Compromise turn a fraction of those messages into more than $16 billion in reported cybercrime losses in the United States alone, the FBI’s Internet Crime Complaint Center says.
The data below covers volume, share trends, top originating countries, BEC and phishing losses, AI’s impact on attacker production cost, and what actually works at the filter layer. It pulls primary numbers from Kaspersky, the FBI, IBM, the Anti-Phishing Working Group, Proofpoint, and the 2026 Verizon DBIR. Every figure traces to a named source so the cybersecurity cost story is verifiable.
Key Takeaways
- Spam accounted for 47.27% of total global email traffic in 2024, a 1.27 p.p. increase over the previous year.
- Kaspersky security solutions blocked over 893 million phishing link attempts in 2024, a 26% increase from 2023 across global telemetry.
- The FBI’s Internet Crime Complaint Center logged 193,407 phishing and spoofing complaints in 2024, more than double the next-most-reported category.
- Business Email Compromise produced close to $2.8 billion in losses across 21,442 IC3 complaints in 2024, the second-largest loss category overall.
- Per IBM’s 2025 Cost of a Data Breach study, Generative AI cut the time to craft a convincing phishing email from 16 hours to 5 minutes.
- Phishing emails overtook stolen credentials as the most common breach initial access vector, responsible for 16% of breaches at an average cost of $4.8 million per IBM.
- APWG observed 989,123 phishing attacks in Q4 2024, up from Q2 and Q3 of the same year.
Editor’s Choice
- Russia originated 36.18% of global spam in 2024, the single-largest country share, followed by China and the United States.
- Web services were the most-imitated phishing target in 2024 at 15.75% of attempts, ahead of internet portals at 13.88% and banks at 12.86%.
- Kaspersky detected 125,521,794 attempts to open malicious email attachments in 2024, reflecting sustained pressure on the attachment-delivered malware channel.
- Proofpoint’s State of the Phish 2025 found that 71% of surveyed organizations confirmed at least one successful phishing attack in the prior 12 months.
- Older adults aged 60 and over reported $4.885 billion in losses to internet crime in 2024, up 43% year over year, with an average reported loss per victim of approximately $83,000.
- The 2026 Verizon DBIR analyzed more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries.
- APWG and Fortra found that the average BEC wire transfer request was $128,980 in Q4 2024, nearly double the third quarter’s average of $67,145.
Recent Developments
- 2025-10 (Q4 2024 release): APWG reported 989,123 phishing attacks observed in Q4 2024, up from 932,923 in Q3.
- April 2025: The FBI’s IC3 unit published its 2024 Annual Report showing losses exceeding $16 billion across 859,532 complaints, a 33% year-over-year increase.
- July 2025: IBM released its 2025 Cost of a Data Breach report finding that phishing overtook stolen credentials as the most common initial access vector at 16% of breaches.
- March 2025: Kaspersky’s 2024 spam and phishing report documented a 26% year-over-year increase in blocked phishing link attempts, totaling 893,216,170 attempts.
- May 2026: The 2026 Verizon DBIR found that phishing accounted for 44% of AI-assisted initial access vectors, the single largest category.
- May 2026: The DBIR also reported a median phone-centric phishing-simulation click rate of 2%, compared with 1.4% for email simulations, a 40% gap.
Global Email Spam Volume
- Spam reached 47.27% of total global email traffic in 2024 per Kaspersky’s annual report, the most-cited primary measurement of share.
- Kaspersky blocked over 893 million phishing link attempts in 2024 across its global telemetry network.
- The company also detected 125,521,794 malicious attachment attempts throughout the year.
- Proofpoint, which protects a large slice of enterprise email globally, blocked 3.4 billion phishing emails per day at peak, according to its 2025 telemetry.
- APWG, an industry consortium aggregating reports across members, observed 989,123 phishing attacks in the fourth quarter of 2024 alone.
- Email continues to dominate the attack surface: 91% of all cyberattacks begin with an email, a figure that has remained consistent since Proofpoint first reported it in 2019.
| Metric (2024) | Value | Source |
|---|---|---|
| Spam share of global email traffic | 47.27% | Kaspersky |
| Phishing link attempts blocked (Kaspersky) | 893,216,170 | Kaspersky |
| Malicious email attachments detected | 125,521,794 | Kaspersky |
| Phishing attacks observed (APWG Q4 2024) | 989,123 | APWG |
| Share of cyberattacks beginning with email | 91% | Proofpoint |
Source: Kaspersky Securelist 2024, APWG Q4 2024, Proofpoint State of the Phish 2025
Spam Share of Global Email Traffic Over Time
The series shows the 2024 share at 47.27%, sitting above the 2023 floor of 45.6% while staying below the 2017 peak of approximately 56.6%.
The reversal is the part that matters. Share peaked in 2017, then fell for most of a decade. The 2024 uptick is small in absolute terms but breaks the post-2017 trajectory and lines up with the AI-driven production-cost collapse described later.
Top Spam-Originating Countries
| Country | Share of global spam (2024) |
|---|---|
| Russia | 36.18% |
| China | 17.11% |
| United States | 8.40% |
| Kazakhstan | 3.82% |
| Japan | 2.93% |
| Germany | 2.10% |
| Hong Kong | 1.75% |
| Brazil | 1.44% |
| Netherlands | 1.25% |
Source: Kaspersky Securelist Spam and Phishing in 2024
- Russia led as the primary source of spam, originating 36.18% of unsolicited messages in 2024, more than twice the second-place share.
- China followed at 17.11% of global spam, slightly down from prior-year levels.
- The United States held the third spot at 8.40%, the largest single share among Western economies.
- Kazakhstan jumped into the top four at 3.82%, displacing the prior rank held by smaller European contributors.
- Japan, Germany, India, Hong Kong, Brazil, and the Netherlands rounded out the top ten, each contributing between 1.25% and 2.93%.
- The figures reflect originating mail-server IP location and may understate jurisdictions where attackers route through hosting providers in third countries.
Phishing Email Volume
| Metric | Value |
|---|---|
| Phishing attempts blocked by Kaspersky in 2024 | 893,216,170 |
| Change versus 2023 | +26% |
Source: Kaspersky Securelist 2024
- Kaspersky blocked over 893 million phishing link attempts in 2024, up from approximately 710 million in 2023.
- Proofpoint reported a daily peak block volume of 3.4 billion phishing emails per day at peak across its protected enterprises.
- APWG observed 989,123 phishing attacks in Q4 2024 alone, up from 932,923 in Q3 and 877,536 in Q2.
- Spear-phishing remains the preferred entry method for targeted attacks: 65% of attackers selected it as their primary vector, and 71% of targeted attacks were spear-phishing.
- The threat surface is essentially universal: 96% of organizations received phishing emails at some volume, according to Proofpoint’s State of the Phish 2025.
Most Common Phishing Categories Imitated
- Web services were the most-imitated phishing category at 15.75% of attempts in 2024, surpassing internet portals.
- Internet portals held the second spot at 13.88% after holding the top position the prior year.
- Banks moved up to third at 12.86%, overtaking online stores at 11.52%.
- Social media and messengers together rank below banks and online stores in Kaspersky’s category-level breakdown of 2024 phishing attempts, but they remain a steady share of impersonation traffic.
- The Kaspersky breakdown reflects link-imitation pages, not BEC text-only impersonation, which APWG tracks separately.
Most Targeted Industries and Sectors
- The SAAS / Webmail category was the most-attacked sector in Q4 2024, per OpSec Security’s contribution to the APWG dataset.
- Phishing against the Financial Institution segment continued to fall, accounting for 11.9% of all attacks in Q4 2024, down from 24.9% in Q3 2023.
- Across simulated-phishing tests, the energy and utilities sector had the lowest user failure rate at 3.6%, while the legal sector had the highest at 8.9%.
- The average user failure rate across all sectors was 4.93%, per Proofpoint’s State of the Phish 2025.
- E-commerce retailers remain heavily targeted through fake order-confirmation and shipping-update lures, although the share dipped to 11.52% in Kaspersky’s category data.
- Account takeover pressure is essentially universal across industries: 99% of organizations were regularly targeted for account takeovers, and nearly 62% were impacted by at least one successful takeover.
Losses Caused by Spam and Email Fraud
| Category | 2024 figure | Source |
|---|---|---|
| Total IC3 cybercrime losses | $16.6 billion | FBI IC3 |
| Phishing and spoofing complaints | 193,407 | FBI IC3 |
| Phishing-related losses (IC3) | over $70 million | FBI IC3 |
| BEC complaints | 21,442 | FBI IC3 |
| BEC losses | close to $2.8 billion | FBI IC3 |
| Older adults (60+) losses | $4.885 billion | FBI IC3 |
Source: FBI Internet Crime Complaint Center 2024 Annual Report
- The FBI’s 2024 Internet Crime Report combined 859,532 complaints with reported losses exceeding $16 billion, a 33% increase in losses from 2023.
- Phishing and spoofing were the most-reported crime by volume at 193,407 complaints, more than double the next-most-numerous category.
- Direct phishing-related dollar losses were in excess of $70 million in 2024, far below BEC because phishing often acts as the entry point rather than the final theft.
- BEC ranked seventh by complaint count but second by losses, with 21,442 complaints and close to $2.8 billion in losses.
- Investment fraud topped the loss leaderboard at $6.57 billion in 2024, much of it initiated via email or messaging-app contact.
- Older adults bore disproportionate damage, with adults aged 60 and over losing $4.885 billion in 2024 and reporting an average loss per victim of approximately $83,000.
By the numbers: Per the FBI’s IC3 unit, 193,407 phishing complaints produced over $70 million in direct losses in 2024, while just 21,442 BEC complaints accounted for nearly $2.8 billion. Spam’s damage compounds at the executive layer where one successful wire-fraud message can dwarf thousands of consumer-facing phishing hits.
Phishing as a Breach Initial Access Vector
- The 2026 Verizon DBIR analyzed more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries.
- Phishing accounted for 16% of identity-related initial access, the single-largest category, with credential abuse at 13% and pretexting at 6%.
- IBM’s 2025 Cost of a Data Breach found phishing overtook stolen credentials as the most common initial vector, responsible for 16% of breaches at an average cost of $4.8 million.
- 62% of breaches involve the human element per the DBIR, with credential and click-based pathways dominating.
- Of the AI-assisted initial access vectors the DBIR identified, phishing accounted for 44%, the single-largest category.
- The DBIR’s phone-centric phishing simulations produced a median 2% click rate compared with 1.4% for email simulations, a 40% gap that shows users are still less hardened to voice-channel lures than to email-channel ones.
Why it matters: Phishing now sits at the same 16% share for breach initial access in two independent datasets (IBM and Verizon), with the typical phishing-initiated breach costing roughly $4.8 million. The signal helps reduce the temptation to treat spam as a low-priority filter problem when it is, in fact, the most common entry point for the most expensive incidents.
AI’s Impact on Spam and Phishing
- Generative AI has reduced the time needed to craft a convincing phishing email from 16 hours to 5 minutes, per IBM’s 2025 study.
- 1 in 6 breaches involved attackers using AI, most commonly for phishing at 37% and deepfake impersonation at 35%.
- Verizon’s 2026 DBIR found phishing accounted for 44% of AI-assisted initial access vectors.
- Shadow AI is amplifying breach cost: organizations experiencing breaches linked to unauthorized AI tools paid an average of $670,000 more per incident in IBM’s dataset.
- Pre-built AI phishing kits have lowered the technical bar; kits like CoGUI and Darcula reduced the technical barrier for low-skill attackers, according to Proofpoint telemetry.
The headline shift is production economics. At two working days per lure, attackers had to be picky about targets; at five minutes per draft, any inbox is worth a try, and customization bakes into the first send. That is why AI’s effect on spam looks small in share-of-traffic terms but large in successful-attack terms.
Spam Filter Effectiveness
- Across simulated-phishing tests, the average user failure rate was 4.93%, with sector variation from 3.6% (energy and utilities) to 8.9% (legal).
- Despite filter improvements, 71% of organizations still confirmed at least one successful phishing attack in the prior 12 months per Proofpoint.
- 96% of organizations received phishing emails at some volume, meaning the question is detection coverage, not whether attempts happen.
- The 2026 Verizon DBIR’s phone-centric simulations produced a median 2% click rate, compared with 1.4% for email, a scam detection gap that suggests filter-only investment misses voice-channel risk.
- Multi-factor authentication helps reduce account-takeover risk, but nearly 62% of organizations were still impacted by at least one successful account takeover, showing that MFA alone does not block phishing-driven credential theft.
The takeaway: Filters at the inbox layer block the majority of unwanted email, but with 47.27% of traffic still classified as spam and 71% of organizations confirming a successful phishing attack in the past year, the residual risk lands squarely on user behavior. Layered defenses (DMARC, FIDO2 hardware keys, simulation training) help reduce risk, but they do not eliminate it.
Spam Attack Methods Beyond Email
- Cybercriminals dispatch substantial volumes through phishing across email, SMS, and voice, making it the most widespread form of cybercrime by complaint count per IC3 data.
- Smishing (SMS phishing) and other URL-based threats continue to climb, with the DBIR’s phone-centric simulations showing higher click rates (median 2%) than email (1.4%).
- BEC remains the dominant high-dollar email scam: Fortra’s Q4 2024 analysis showed an average wire-transfer request of $128,980, nearly double the third quarter’s $67,145 average.
- Free-webmail abuse dominates BEC origin: Gmail accounted for 81% of free webmail accounts used in Q4 2024 BEC scams, with Microsoft webmail at 10%.
- Malware delivery via spam continues, with Kaspersky’s 2024 telemetry recording 125,521,794 malicious attachment attempts, even as attackers increasingly shift toward URL-based payloads.
- The DBIR found phishing accounts for 16% of identity-related initial access vectors, the largest single category, reinforcing email’s role as the primary attack channel for breaches that include ransomware and other intrusion types.
What percentage of email traffic is spam?
The most-cited 2024 figure is 47.27% of total global email traffic, per Kaspersky’s annual spam and phishing report. Verizon, Proofpoint, and APWG do not publish a directly equivalent traffic-share number because they measure different things (incidents, blocked emails, observed campaigns). Kaspersky’s figure represents a 1.27 p.p. increase over 2023 and reverses a multi-year decline from the 2017 peak of approximately 56.6%. For practical planning, treating spam as roughly 45% to 48% of inbound is the right band.
Why am I getting 20 spam emails a day?
Average inbox volume is driven by exposure surface (how many lists your address sits on) and address age, not by global trends. Even so, the global volume is the backdrop: Kaspersky blocked over 893 million phishing link attempts in 2024 alone, and Proofpoint blocked 3.4 billion phishing emails per day at peak. If twenty a day reaches your inbox, that is the residual after filtering. Reducing it generally means moving to an address less exposed in past breaches and enabling strong sender authentication (SPF, DKIM, DMARC) on any domain you receive mail at.
What is the 60 40 rule for email?
The sixty-forty rule is a marketing-industry guideline for outbound email mix. It does not appear in Kaspersky, FBI IC3, IBM, or Verizon datasets. Spam classification by inbox providers is driven by sender reputation, DMARC alignment, content heuristics, and engagement metrics, not a fixed mix.
Conclusion
Spam is no longer a static problem. Share has ticked back up to 47.27% of global email traffic per Kaspersky’s 2024 telemetry, phishing is now the most common breach initial access vector at 16% of all breaches per IBM’s 2025 Cost of a Data Breach (and a matching 16% of identity-related initial access vectors in Verizon’s 2026 DBIR), and AI has compressed convincing-phishing-email production from 16 hours to 5 minutes. The damage is concentrating: 193,407 IC3 phishing complaints produced over $70 million in direct losses, while 21,442 BEC complaints drove close to $2.8 billion, and older adults aged 60 and over absorbed approximately $4.885 billion in age-skewed losses.
Filters and MFA help reduce risk; they do not eliminate it. With 71% of organizations confirming at least one successful phishing attack in the prior 12 months and 96% receiving phishing email at some volume, the residual surface is the user, the executive, and the older relative. Watching the share trend, the AI-cost trajectory, and the BEC dollar-per-incident curve over 2026-2027 will be the cleanest read on whether layered defenses can keep pace with the new production economics.