Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Not as a current, universal measurement. The often-repeated “91%” figure comes from a 2016 PhishMe report, as reported by Dark Reading. The available account does not define a denominator for all cyberattacks, so it should be treated as a historical, vendor-reported claim—not a settled rate today. A separate 91% statistic from the UK Information Commissioner’s Office describes something different: 91% of UK companies responding to a Proofpoint survey said they had experienced at least one successful email-based phishing attack in 2022.

What is firmly established is the practical risk. Phishing impersonates a trusted organization or person to induce a click, password disclosure, payment, sensitive-data submission, or file download. The safest response is to pause, verify unexpected requests through a known channel, avoid unverified links and attachments, and protect important accounts with unique passwords and multifactor authentication (MFA).

What the 91% claim actually means

The headline statistic is commonly attributed to PhishMe and was reported by Dark Reading in 2016. Because the report’s denominator and definition of “all cyberattacks” are not established in the available source, the number cannot support a claim that 91% of attacks worldwide currently begin with email phishing.

The Information Commissioner’s Office reported a separate 2022 Proofpoint survey result: 91% of responding UK companies said they had suffered at least one successful email-based phishing attack. That is a company-experience measure, not the percentage of all attacks that started with email.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Figure What it measures How to interpret it
91% (PhishMe, reported in 2016) Claim about attacks beginning with phishing Historical vendor-reported estimate; universal denominator and current applicability are not established
91% (Proofpoint survey, 2022) UK-company respondents reporting at least one successful email-phishing incident Survey experience, not the share of all cyberattacks

How phishing works

The Federal Trade Commission describes phishing as an online scam in which a message appears to come from a familiar organization and asks for personal information. Stolen information can be used to open accounts or access existing ones.

Phishing is broader than ordinary email. CISA guidance covers malicious websites, targeted spearphishing, executive-targeted whaling, telephone-based vishing, and text-message smishing. The delivery method changes, but the manipulation is similar: create enough trust or urgency to make the recipient act before checking.

How can I tell if an email is phishing?

No single clue proves that a message is legitimate or fraudulent. A polished message can be malicious, and a genuine message can contain a typo. Look for a combination of warning signs:

Rank #2
FEITIAN K9 USB A NFC - Two Factor Authenticator (2FA) - Multi-Factor Authentication (MFA) - Device Security Key + FIDO2 - Achieve Advanced Account Protection
  • FIDO2 + FIDO U2F certified and supported USB security key
  • Secured by NXP semiconductors
  • Works in every browser and application without installing any drivers
  • Supports desktops, laptops, tablets via USB-A and/or NFC, and supports iOS/Android Phones via NFC
  • Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
  • A sender address or domain that is subtly different from the expected one.
  • A displayed link whose destination does not match the text or the organization you expected.
  • An unexpected attachment or a request to download a file.
  • Urgent pressure to pay, reset a password, confirm an account, or provide sensitive information.
  • An account-warning message you did not initiate, especially when it demands immediate action.
  • A reward or opportunity that seems implausible.

A familiar logo, signature, or branding is not authentication. For a payment, password, or sensitive-data request, do not use the message’s phone number, link, or reply address. Open the organization’s known app or type a familiar website address yourself, or call a number you already trust.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do when a suspicious message arrives

  1. Pause. Do not let urgency determine your next action.
  2. Do not open unexpected attachments or follow unsolicited links. Navigate independently to the known service instead.
  3. Verify independently. Contact the supposed sender through a phone number, bookmark, or official app/site you already know.
  4. Report it. Use your mail service’s phishing or junk control, or follow your workplace reporting procedure. Do not forward sensitive content to an unverified address.
  5. Keep protections current. Install software and security updates as recommended by CISA.

As CISA’s 2021 guidance puts it: “When in doubt, report it out.”

What if I clicked a phishing link?

Stop interacting with the message and report the incident promptly. If you entered a password or other information, go to the account’s official site independently, change the password, and enable MFA where available. Use a different, unique password rather than one reused elsewhere. If the account is managed by an employer, contact the organization’s security or IT team using its established channel so it can assess the account and device.

Rank #3
FEITIAN K40 USB Security Key - Two Factor Authenticator - USB-C with NFC, FIDO2 - Help Prevent Account Takeovers
  • FIDO2 + FIDO U2F certified and supported USB security key
  • Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port and/or NFC
  • Works without downloading any drivers. Supported OS: Android, Chrome OS, Windows, MacOS, Linux
  • Durable design made to last for a long time with everyday use. Water-resistant (IP67)
  • Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.

Does MFA protect me if my password is stolen?

MFA adds a second sign-in requirement, so a stolen password alone may not be enough to access an account. Protection varies by method and by how an attacker obtained the credentials. For business accounts, CISA recommends phishing-resistant MFA based on FIDO or PKI. Availability and setup depend on the provider, account, and devices.

When evaluating an MFA method, check:

  • Whether the account provider supports it.
  • How resistant it is to phishing.
  • How you recover access if a phone or security device is lost.
  • Whether it works across your devices.
  • Whether setup and recovery are controlled by you or by an organization.

A USB security key can be an option where the account and device support a compatible FIDO standard. Confirm compatibility before buying; there is no universal model that works with every service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Account practices that limit damage

Use unique passwords

Long, unique passwords prevent one exposed password from becoming a key to multiple accounts. CISA recommends using a password manager to help create and maintain them. A password manager does not, by itself, prove that an email is genuine or stop every phishing attempt.

Rank #4
Thales - SafeNet eToken FIDO - FIDO2 Certified Security Key - Passwordless Phishing-Resistant Authentication for Web Apps, Devices & Desktops - USB-C - Pack of 1
  • FIDO2 SECURITY KEY: A versatile, tamper-evident USB-C authentication device with sensitive presence detection for online security. FIDO 2.0 level 1 and U2F certified
  • PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
  • BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
  • ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
  • THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts

Prioritize important accounts

Enable MFA on email, banking, health, social, work, and other accounts that would cause serious harm if taken over. Protecting the email account is especially important because it may be used to reset other accounts.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What organizations should do

Train and provide a reporting path

Training should teach users to recognize suspicious messages and report interactions with lures. Employees need a clear, simple route for reporting, plus a process for responding when someone clicks or submits information.

Verify high-impact requests

The FTC recommends internal verification policies for sensitive requests. For example, confirm a wire-transfer request by telephone using a known number, not contact details supplied in the request. Apply the same principle to password resets, payroll changes, confidential-data requests, and new payment instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Swissbit iShield Key 2 FIDO2 USB-C Security Key with NFC – FIDO Certified, Passwordless Authentication, Passkey & U2F, Phishing-Resistant Security for Enterprise
  • SECURITY KEY FOR ENTERPRISE ACCESS: Supports FIDO2 passkeys and U2F for secure authentication across enterprise IT systems.
  • PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure on-device credential storage and PIN-based user verification.
  • COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, and U2F across enterprise, cloud, and modern IT environments.
  • DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. No drivers required.
  • USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries required.

Authenticate organizational email

CISA’s joint-agency guidance discusses SPF, DKIM, and DMARC for checking sending domains. Organizations should consider a DMARC policy that rejects unauthenticated mail claiming to use their domain, while monitoring and tuning legitimate senders first. These controls reduce spoofing risk but do not guarantee that every malicious message is blocked.

Use phishing-resistant MFA for business accounts

FIDO- or PKI-based MFA can provide stronger protection than methods that depend on codes or approval prompts. Select a method that the organization’s identity provider, applications, and users’ devices actually support, and document recovery for lost devices.

Bottom line: treat the statistic cautiously, the threat seriously

The 91% headline is not a verified current share of every cyberattack. One source is a historical vendor estimate with an unclear universal denominator; the other is a 2022 survey of UK companies’ reported experience. The actionable lesson does not depend on either number: unexpected messages deserve independent verification, and layered defenses—unique passwords, MFA, user reporting, verification procedures, and properly configured email authentication—make phishing less likely to succeed and limit the damage when it does.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.