Barracuda Networks highlights rising email threats in 2026 report

New report exposes rising AI-driven email threats and evolving attacker tactics impacting organisations globally.

  • Wednesday, 3rd June 2026 Posted 2 hours ago in by Katy Hill

Barracuda Networks has revealed its 2026 Email Threats Report. The findings shed light on evolving email threats, primarily driven by AI-powered social engineering and the growth of phishing as a service. Such advancements are facilitating adversaries to scale credential phishing operations, subsequently enhancing the success of their targeted campaigns.

The report observes a strategic shift in attacker methodologies, where threat actors migrate from file-based payloads to URL-based delivery modes. A notable tactic includes the use of QR codes embedded within trusted document formats, aimed at masking malicious destinations. Furthermore, attackers are leveraging account takeover techniques, enabling them to circumvent standard defences and deliver credible soured messages from hijacked mailboxes. These developments underscore the necessity for comprehensive, multi-layered email protection strategies.

Drawing on global telemetry data from January 2026, Barracuda Research delved into 3.1 billion email correspondences. The analysis focused on quantifying malicious, spam, or otherwise unwelcome emails, elucidating their impact on global organisations. Key discoveries from the research include the following insights:

  • 1 in 3 emails are either malicious or unwanted spam.
  • Phishing constitutes 48% of all malicious email activity.
  • Approximately 34% of firms report experiencing at least one account takeover incident each month.
  • Over 10% of HTML attachments were identified as malicious.
  • A notable 70% of malignant PDFs contained QR codes redirecting to phishing websites.
  • A staggering 90% of large-scale phishing endeavors utilise phishing-as-a-service kits.

The modern email landscape demands more than being a mere communication medium—it’s pivotal for identity, trust, and maintaining business continuity. As attackers rapidly 'industrialise' phishing utilising AI and additional services, defensive measures must evolve correspondingly. Organisations aiming to remain resilient should consider prioritising a robust, integrated email security framework, combining identity protection with automated responses, as part of their comprehensive strategy. Such synchronised efforts in rapid detection and automated incident management can significantly mitigate risks, limit account compromises and maintain continuity as emerging threats proliferate.

Boomi and ServiceNow partner to enhance AI-driven enterprises

Posted 4 minutes ago by Sophie Milburn
Boomi and ServiceNow expand their partnership to enhance data activation and workflow integration for AI-driven businesses.
Westcon-Comstor introduces OneSOC, a scalable, vendor-agnostic solution enabling partners to establish a Security Operations Centre without upfront...
WorkNest Secure unites cybersecurity, infosec, and data protection services under one roof, enhancing WorkNest's offerings in risk management.
UK CIOs face challenges in balancing AI adoption with governance, revealing fears about data exposure and inadequacies in compliance frameworks.
Assured Data Protection strengthens global operations with Alvaro Gonzalez's appointment as Senior Vice President of Product and Go-to-Market.

Cautious steps: UK SMBs and AI adoption trends

Posted 1 day ago by Sophie Milburn
IONOS report reveals UK SMBs weigh AI adoption amidst cost, time, and trust challenges, preferring investment in immediate returns.

Enhancing cybersecurity with active exploits protection

Posted 1 day ago by Sophie Milburn
Proofpoint has introduced a solution aimed at addressing cyber threats accelerated by AI, with a focus on improving real-time threat detection and...
Nebula Global Services has appointed Scott Lynn as Global Services Director to support the development of its service organisation, enhance delivery...