A message lands that looks like a shipping notice, or a bank alert, or a newsletter you meant to leave months ago. Most of it you delete without a second thought. A small slice of it is engineered to take your money or your password, and in 2024 that slice added up to numbers with ten digits.
In 2024 the FBI’s Internet Crime Complaint Center logged $16.6 billion in reported losses, up 33 percent from 2023, across 859,532 complaints. Phishing and spoofing were the single most-reported crime, at 193,407 complaints. Business email compromise alone cost $2.77 billion. Most of that fraud arrives by email.
This is a sourced roundup of what spam and phishing actually cost in 2026, from the billions lost to fraud down to the minutes you personally spend deleting junk. Every figure carries a named source and a year. Where a number is old but still the benchmark researchers cite, the note says so.
What did spam and phishing cost in 2024?
The headline number is $16.6 billion, and it is a floor, not a ceiling. According to the FBI’s Internet Crime Complaint Center 2024 Annual Report, released in April 2025, Americans reported 859,532 internet-crime complaints in 2024 with total losses of $16.6 billion, a 33 percent increase over 2023. The IC3 only counts crimes people bothered to report to it, so the true cost runs higher.
Phishing and spoofing sat at the top of the complaint pile. The IC3 recorded 193,407 phishing and spoofing complaints, more than any other crime type by volume. Those two tactics, a fake email that impersonates a trusted sender and a forged address that hides who really sent it, are how a huge share of the fraud below starts.
Why is phishing the most-reported crime but not the biggest dollar line?
Because phishing is the doorway, and the money leaves through other rooms. The losses filed directly under phishing and spoofing in the 2024 IC3 report came to about $70 million, a small figure next to the multi-billion totals elsewhere. That gap is not a contradiction. A phishing email rarely takes your money on the spot. It hands the attacker a password, a hijacked mailbox, or your trust, and the payout shows up later under a different label.
Here is where the dollars actually landed in 2024, per the same IC3 report:
| Crime category (IC3, 2024) | Reported losses |
|---|---|
| Investment fraud (mostly crypto) | $6.57 billion |
| Business email compromise | $2.77 billion |
| Tech support fraud | $1.46 billion |
| Phishing / spoofing (direct) | $70 million |
Business email compromise is the clearest example of the doorway effect. An attacker spoofs or takes over a real email account, usually reached through an earlier phishing message, then sends a convincing request to wire money or change payment details. That single tactic cost $2.77 billion across 21,442 complaints in 2024, the second-highest of any category. The email is cheap. The consequence is not. If you want the mechanics of how a fake message disguises itself, our post on how phishing hides behind opt-out pages walks through one common disguise.
How much does a phishing breach cost a business?
An average of $4.8 million, and phishing is the most common way attackers get in. According to IBM’s Cost of a Data Breach 2025 report, phishing caused 16 percent of the breaches studied, more than any other initial attack vector, at an average cost of $4.8 million per breach. The global average across all breach types was $4.44 million, the first year-over-year decline in five years.
The report flags a shift that makes the next few years harder. IBM found that generative AI cut the time to write a convincing phishing email from as long as 16 hours down to about 5 minutes. Faster production means more volume and more personalized lures, a cost multiplier baked into the tools rather than the crime itself.
What does spam cost you in time?
Even the junk that never scams anyone bills you in minutes. The most-cited estimate here is old but durable: a 2004 Nucleus Research study, Spam: The Silent ROI Killer, put the productivity cost of spam at about $874 per employee per year, based on workers spending roughly 6.5 minutes a day managing it. Treat that as a historical benchmark, not a fresh reading, but the underlying math has not improved. Kaspersky’s Spam and Phishing Report for 2025 found that close to half of all email sent worldwide is still spam, and its filters blocked over 554 million attempts to follow phishing links across the year.
Your personal inbox pays a version of that tax. A few minutes a morning sorting promos from real mail is a small number that compounds over a year, and every unfamiliar message is one more chance to misread a fake as real. The broader picture of how much mail we all wade through sits in our email overload statistics roundup.
Does spam have an environmental cost?
It does, and the classic study on it is worth knowing even though it is dated. In 2009, ICF International produced The Carbon Footprint of Email Spam Report, sponsored by McAfee. It estimated that an average spam message generates about 0.3 grams of CO2, and that the roughly 62 trillion spam emails sent in 2008 consumed 33 billion kilowatt-hours, comparable to the annual electricity use of 2.4 million homes.
The counterintuitive finding is where that energy went. The report attributed nearly 80 percent of spam’s emissions not to sending it, but to people viewing and deleting it and to searching for real mail wrongly caught in spam filters. The energy cost of spam is mostly your energy, spent cleaning up after it. The hardware has grown more efficient since 2009, so read the figure as a scale marker rather than a live measurement.
What does this cost you personally?
For most people the cost is time and exposure, and for some it is far worse. The 2024 IC3 report found that victims aged 60 and over filed 147,127 complaints and lost nearly $4.8 billion, more than any other age group. Scams that begin with a spoofed email or a fake alert do the most damage to the people least likely to spot them.
For everyone else, the everyday cost is quieter. It is the minutes triaging junk, the low-grade uncertainty about which links are safe, and the fact that a fuller inbox is a larger target. The same address that scammers phish is also the one marketers pay to reach, which is why your email address is worth two very different numbers depending on who holds it. The more places it lands, the more of both kinds of mail you get.
How do you cut your own exposure?
Shrink the surface. Fewer senders in your inbox means fewer messages to misjudge and fewer minutes lost sorting them. Three habits do most of the work:
- Never authenticate from an email link. No real unsubscribe or account page asks for your password or payment details. If one does, close the tab. When you are unsure a link is genuine, our 30-second check for unsubscribe links sorts the real ones from the traps.
- Report, do not just delete. Marking a hostile message as phishing teaches your provider to catch the next one. Deleting it silently teaches it nothing.
- Get off the lists you no longer want. Every legitimate sender you remove is one less message to scan and one less footer link to second-guess.
Doing that last step by hand across years of accumulated senders is slow, and not every unsubscribe tool deserves the inbox access it asks for. Email Unsubscriber scans your Gmail or Outlook in your own browser, lists every subscription sender, and fires the real one-click opt-out wherever the sender supports it. The scan runs on your device, and we never read, analyze, or monetize your email content. You can run it on your own inbox and clear the backlog in one sitting instead of one message at a time.
The takeaway
Spam and phishing cost more than the annoyance suggests. In 2024 alone, reported losses hit $16.6 billion, business email compromise took $2.77 billion of it, and a single phishing breach cost a business $4.8 million on average. Underneath the fraud sits a steadier tax the rest of us pay in deleted junk, wasted minutes, and wasted energy. You cannot fix the global number, but you can shrink your own share of it. Give out fewer real addresses, treat every login-from-a-link as a trap, and clear the senders you never wanted. A smaller inbox is a smaller target.
