Phishing Landscape 2025:
Key Statistics May 1, 2024 - April 30, 2025

We analyzed URLs, domain names, and IP addresses that have been reported for phishing. These and other metadata — e.g., registration data, DNS zone data, attack type and targeted brand — allow us to determine where phishers are acquiring resources for their criminal activities. Indicators of compromise allow us to distinguish hostnames delegated from domains that were purposely registered for phishing campaigns from hostnames assigned to compromised web sites that were delegated from domain names for legitimate purposes.

During this period, we measured phishing reports, phishing attacks, and the number of unique domain names reported for use in phishing attacks. We also measured famous brands that were targeted by phishers.

Measurement Count
Total number of phishing reports collected from feeds this year 3,916,242
Phishing attacks reported 1,963,390
Unique domain names reported for phishing 1,542,922
Maliciously registered domains reported for phishing 1,192,794
Top-level Domains (TLDs) where we observed phishing 790
gTLD Registrars that had domains under management reported for phishing 2,033
All Registrars that had domains under management reported for phishing 3,125
Hosting Networks (ASNs) where phishing web sites were reported 4,065
Brands targeted in phishing attacks 2,694
Number of phishing attacks using a subdomain reseller 256,026

Yearly Update:
Key Statistics
Yearly Update:
Top Level Domains
Yearly Update:
Registrars
Yearly Update:
Hosting Networks
Year over Year:
Key Statistics