Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesNot as a current, universal measurement. The often-repeated “91%” figure comes from a 2016 PhishMe report, as reported by Dark Reading. The available account does not define a denominator for all cyberattacks, so it should be treated as a historical, vendor-reported claim—not a settled rate today. A separate 91% statistic from the UK Information Commissioner’s Office describes something different: 91% of UK companies responding to a Proofpoint survey said they had experienced at least one successful email-based phishing attack in 2022.
What is firmly established is the practical risk. Phishing impersonates a trusted organization or person to induce a click, password disclosure, payment, sensitive-data submission, or file download. The safest response is to pause, verify unexpected requests through a known channel, avoid unverified links and attachments, and protect important accounts with unique passwords and multifactor authentication (MFA).
What the 91% claim actually means
The headline statistic is commonly attributed to PhishMe and was reported by Dark Reading in 2016. Because the report’s denominator and definition of “all cyberattacks” are not established in the available source, the number cannot support a claim that 91% of attacks worldwide currently begin with email phishing.
The Information Commissioner’s Office reported a separate 2022 Proofpoint survey result: 91% of responding UK companies said they had suffered at least one successful email-based phishing attack. That is a company-experience measure, not the percentage of all attacks that started with email.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Figure | What it measures | How to interpret it |
|---|---|---|
| 91% (PhishMe, reported in 2016) | Claim about attacks beginning with phishing | Historical vendor-reported estimate; universal denominator and current applicability are not established |
| 91% (Proofpoint survey, 2022) | UK-company respondents reporting at least one successful email-phishing incident | Survey experience, not the share of all cyberattacks |
How phishing works
The Federal Trade Commission describes phishing as an online scam in which a message appears to come from a familiar organization and asks for personal information. Stolen information can be used to open accounts or access existing ones.
Phishing is broader than ordinary email. CISA guidance covers malicious websites, targeted spearphishing, executive-targeted whaling, telephone-based vishing, and text-message smishing. The delivery method changes, but the manipulation is similar: create enough trust or urgency to make the recipient act before checking.
How can I tell if an email is phishing?
No single clue proves that a message is legitimate or fraudulent. A polished message can be malicious, and a genuine message can contain a typo. Look for a combination of warning signs:
Rank #2
- FIDO2 + FIDO U2F certified and supported USB security key
- Secured by NXP semiconductors
- Works in every browser and application without installing any drivers
- Supports desktops, laptops, tablets via USB-A and/or NFC, and supports iOS/Android Phones via NFC
- Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
- A sender address or domain that is subtly different from the expected one.
- A displayed link whose destination does not match the text or the organization you expected.
- An unexpected attachment or a request to download a file.
- Urgent pressure to pay, reset a password, confirm an account, or provide sensitive information.
- An account-warning message you did not initiate, especially when it demands immediate action.
- A reward or opportunity that seems implausible.
A familiar logo, signature, or branding is not authentication. For a payment, password, or sensitive-data request, do not use the message’s phone number, link, or reply address. Open the organization’s known app or type a familiar website address yourself, or call a number you already trust.
Recommended Free Tools
What to do when a suspicious message arrives
- Pause. Do not let urgency determine your next action.
- Do not open unexpected attachments or follow unsolicited links. Navigate independently to the known service instead.
- Verify independently. Contact the supposed sender through a phone number, bookmark, or official app/site you already know.
- Report it. Use your mail service’s phishing or junk control, or follow your workplace reporting procedure. Do not forward sensitive content to an unverified address.
- Keep protections current. Install software and security updates as recommended by CISA.
As CISA’s 2021 guidance puts it: “When in doubt, report it out.”
What if I clicked a phishing link?
Stop interacting with the message and report the incident promptly. If you entered a password or other information, go to the account’s official site independently, change the password, and enable MFA where available. Use a different, unique password rather than one reused elsewhere. If the account is managed by an employer, contact the organization’s security or IT team using its established channel so it can assess the account and device.
Rank #3
- FIDO2 + FIDO U2F certified and supported USB security key
- Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port and/or NFC
- Works without downloading any drivers. Supported OS: Android, Chrome OS, Windows, MacOS, Linux
- Durable design made to last for a long time with everyday use. Water-resistant (IP67)
- Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
Does MFA protect me if my password is stolen?
MFA adds a second sign-in requirement, so a stolen password alone may not be enough to access an account. Protection varies by method and by how an attacker obtained the credentials. For business accounts, CISA recommends phishing-resistant MFA based on FIDO or PKI. Availability and setup depend on the provider, account, and devices.
When evaluating an MFA method, check:
- Whether the account provider supports it.
- How resistant it is to phishing.
- How you recover access if a phone or security device is lost.
- Whether it works across your devices.
- Whether setup and recovery are controlled by you or by an organization.
A USB security key can be an option where the account and device support a compatible FIDO standard. Confirm compatibility before buying; there is no universal model that works with every service.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Account practices that limit damage
Use unique passwords
Long, unique passwords prevent one exposed password from becoming a key to multiple accounts. CISA recommends using a password manager to help create and maintain them. A password manager does not, by itself, prove that an email is genuine or stop every phishing attempt.
Rank #4
- FIDO2 SECURITY KEY: A versatile, tamper-evident USB-C authentication device with sensitive presence detection for online security. FIDO 2.0 level 1 and U2F certified
- PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
- BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
- ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
- THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
Prioritize important accounts
Enable MFA on email, banking, health, social, work, and other accounts that would cause serious harm if taken over. Protecting the email account is especially important because it may be used to reset other accounts.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What organizations should do
Train and provide a reporting path
Training should teach users to recognize suspicious messages and report interactions with lures. Employees need a clear, simple route for reporting, plus a process for responding when someone clicks or submits information.
Verify high-impact requests
The FTC recommends internal verification policies for sensitive requests. For example, confirm a wire-transfer request by telephone using a known number, not contact details supplied in the request. Apply the same principle to password resets, payroll changes, confidential-data requests, and new payment instructions.
Best Value
- SECURITY KEY FOR ENTERPRISE ACCESS: Supports FIDO2 passkeys and U2F for secure authentication across enterprise IT systems.
- PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure on-device credential storage and PIN-based user verification.
- COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, and U2F across enterprise, cloud, and modern IT environments.
- DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. No drivers required.
- USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries required.
Authenticate organizational email
CISA’s joint-agency guidance discusses SPF, DKIM, and DMARC for checking sending domains. Organizations should consider a DMARC policy that rejects unauthenticated mail claiming to use their domain, while monitoring and tuning legitimate senders first. These controls reduce spoofing risk but do not guarantee that every malicious message is blocked.
Use phishing-resistant MFA for business accounts
FIDO- or PKI-based MFA can provide stronger protection than methods that depend on codes or approval prompts. Select a method that the organization’s identity provider, applications, and users’ devices actually support, and document recovery for lost devices.
Bottom line: treat the statistic cautiously, the threat seriously
The 91% headline is not a verified current share of every cyberattack. One source is a historical vendor estimate with an unclear universal denominator; the other is a 2022 survey of UK companies’ reported experience. The actionable lesson does not depend on either number: unexpected messages deserve independent verification, and layered defenses—unique passwords, MFA, user reporting, verification procedures, and properly configured email authentication—make phishing less likely to succeed and limit the damage when it does.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

