AI and Phishing-as-a-Service Are Industrialising Email Attacks — Barracuda's 2026 Email Threats Report Reveals the New Front Line
Email has always been the path of least resistance for adversaries seeking to compromise enterprise environments — and for years, the security industry has made measurable progress in reducing that risk through improved detection, better spam filtering, and user awareness training. That progress is now being systematically eroded. Barracuda Networks, a leading global cybersecurity company, has published its 2026 Email Threats Report — drawing on analysis of more than 3.1 billion emails collected in January 2026 by Barracuda Research, the company's threat intelligence arm. The findings are stark: one in three email messages is now either malicious or unwanted spam, up from one in four the previous year, and nearly half of all malicious activity comes from phishing attacks.
The report identifies two structural forces driving this deterioration: AI-driven social engineering that enables attackers to generate convincing, personalised phishing content at unprecedented scale, and Phishing-as-a-Service (PhaaS) — a criminal subscription model that industrialises credential phishing by providing templates, fake login pages, hosting, and automation that makes sophisticated campaigns easy to launch and iterate without specialist expertise. Together, they are reshaping the email threat landscape in ways that fundamentally challenge the adequacy of conventional, single-layer defences.
"Email is no longer just a communication channel — it's the front line of identity, trust and business continuity. As attackers industrialise phishing with AI and phishing-as-a-service, the future of defence must evolve just as quickly. Organisations that stay ahead will prioritise integrated email security layered with identity protection and automated response as part of a broader, resilience-driven strategy. When prevention, rapid detection and automated incident response work together, businesses can reduce risk, limit the impact of account compromise and maintain continuity even as threats accelerate."
— Merium Khalid, Director of SOC Offensive Security, Office of the CTO, Barracuda
The Two Forces Reshaping the Email Threat Landscape
The report identifies AI-driven social engineering and Phishing-as-a-Service as the twin engines of the current escalation — and the interaction between them is what makes the current threat environment qualitatively different from previous cycles of email attack growth. Historically, more sophisticated phishing required more skilled attackers. AI and PhaaS have broken that relationship: high-quality, personalised, multi-stage phishing campaigns can now be launched by operators with minimal technical expertise, at volumes and velocities that were previously impossible.
AI-Driven Social Engineering — Personalisation at Scale, Defences at Risk
AI is enabling attackers to generate highly convincing, contextually personalised phishing content at a scale and speed that was previously impossible with human-authored campaigns. Messages can now be crafted to mirror writing styles, reference real business context, and adapt to individual targets in ways that bypass both technical filters and user awareness. The result is a phishing campaign quality ceiling that has risen dramatically — while the cost and skill required to reach that ceiling has fallen just as sharply.
Phishing-as-a-Service (PhaaS) — Industrialising Credential Theft for the Mass Market
PhaaS is a criminal subscription model that provides ready-made phishing templates, fake login pages, hosting infrastructure, and automation that makes credential phishing easy to launch and iterate without specialist expertise. Adversary-in-the-middle-style kits raise risk even in MFA environments by intercepting session tokens in real time — meaning that the MFA protections many organisations consider adequate are increasingly being bypassed at the point of authentication itself. Higher email attack volume driven by PhaaS also increases alert fatigue and the likelihood of missed detections, particularly for small and mid-size businesses.
URL-Based & QR Code Delivery — Bypassing Conventional Scanning at the Point of Attack
Since the start of 2026, Barracuda Research analysts have witnessed a notable surge in URL-driven attack tactics compared to previous years. Attackers are shifting away from file-based payloads — which are well understood by traditional scanning tools — toward malicious URLs embedded in messages and QR codes embedded in trusted document formats like PDFs. Even though only around one in every 200 links is malicious, the impact of a single successful click — credential theft, account takeover, follow-on fraud — is severe enough to make this a priority defensive concern regardless of the low per-link rate.
Account Takeover — The Long-Tail Attack That Compounds Every Other Threat
With 34% of companies experiencing at least one account takeover incident per month, ATO has become a baseline operational risk rather than an exceptional event. Attackers that obtain valid login credentials gain long-term, often undetected access to business environments — with the ability to move laterally, escalate privileges, and send highly convincing phishing messages from legitimate, trusted inboxes. The combination of PhaaS-driven credential harvesting and ATO-enabled internal delivery creates a compounding risk that conventional perimeter defences are fundamentally unsuited to address.
What the Data Signals for Defenders — Five Actionable Priorities
The 2026 Email Threats Report translates its findings into a set of practical defensive priorities — designed for CISOs, security leaders, SecOps teams, IT administrators, and managed service providers who need to close the gaps that AI-driven phishing and PhaaS are actively exploiting.
Implement stronger user verification, anti-impersonation controls, and continuous security awareness training tailored to current attacker tactics — including URL-based lures, QR code-embedded attacks, and HTML-based content delivery that bypasses traditional attachment scanning.
Enforce MFA where possible, but recognise that PhaaS adversary-in-the-middle kits are actively bypassing MFA in real time. Complement MFA with continuous monitoring for suspicious sign-ins, tighter access policies, and session token controls that limit the impact of stolen credentials even after authentication has been compromised.
Increase scrutiny of embedded links and QR codes in both messages and documents. More than 10% of HTML attachments are now malicious — highlighting that HTML-based content requires the same level of active inspection previously reserved for executable file types. Security tooling configured primarily around attachment scanning needs to extend its coverage model.
With 34% of companies experiencing a monthly ATO incident, account takeover response needs a dedicated playbook — including rapid credential resets, token and session revocation, and clear escalation paths that minimise dwell time between compromise detection and containment. The longer a compromised account remains active, the greater the lateral movement and trust exploitation risk.
Automate the quarantine of suspicious messages and the response to detected account compromise to reduce the window between a successful attack and containment. Email security must be paired with identity and endpoint controls to address the full attack chain — from initial credential phishing through to lateral movement and follow-on exploitation. Integrated, multilayered email protection is no longer a best practice; it is the baseline requirement.
The BarracudaONE Platform — Integrated Cyber Resilience Across Email, Identity and Beyond
Barracuda's intelligent BarracudaONE platform provides the integrated, multilayered cyber resilience that the 2026 Email Threats Report identifies as the requirement for staying ahead of AI-driven email threats. Spanning email security, data protection, application security, network protection, and managed XDR within an open ecosystem, BarracudaONE ensures that the defensive response to email threats is not isolated within a single security layer but extends across the identity and endpoint controls that determine whether a successful phishing attempt escalates into a full-scale incident.
More than 10% of HTML attachments analysed in the dataset are malicious — highlighting a delivery method that conventional attachment-focused scanning was not designed to cover at this level of prevalence.
Approximately one in every 200 links is malicious — a low rate that masks a severe per-click consequence, as a single successful click can lead to credential theft, account takeover, and extended lateral access.
Adversary-in-the-middle PhaaS kits intercept MFA session tokens in real time — rendering standard MFA an insufficient protection when facing Tycoon 2FA, Saiga 2FA, and similar advanced phishing kits now in wide criminal use.
Key Takeaways
Barracuda's 2026 Email Threats Report, based on analysis of 3.1 billion emails, finds that 1 in 3 email messages is now malicious or unwanted spam — up from 1 in 4 the previous year — with 48% of malicious activity from phishing and 34% of companies experiencing at least one account takeover incident every month.
AI-driven social engineering and Phishing-as-a-Service (PhaaS) are jointly industrialising email attacks — PhaaS provides templates, hosting, and automation that lower attacker skill requirements, while adversary-in-the-middle kits now bypass MFA in real time, invalidating MFA-alone defences across enterprises of all sizes.
Attackers are shifting to stealthier delivery methods — URL-based payloads surging since early 2026, QR codes embedded in trusted document formats, and HTML attachments (10%+ of which are malicious) — all specifically designed to bypass conventional attachment-scanning defences and evade detection before damage occurs.
Effective defence requires integrated, multilayered email protection paired with identity security and automated response — covering anti-impersonation, ATO playbooks, expanded link and QR inspection, and continuous automated detection. Read the full findings at barracuda.com/reports/2026-email-threats-report.
The data in Barracuda's 2026 Email Threats Report tells a story about structural change, not incremental escalation. When one in three emails is malicious or spam, when PhaaS kits bypass MFA in real time, and when account takeover is a monthly occurrence for a third of organisations, the email threat landscape has moved into a fundamentally different register — one where conventional perimeter-focused defences are not simply insufficient but actively misleading organisations about the level of risk they face. The response has to match the threat: integrated, identity-aware, automated, and resilience-designed for the reality that some attacks will get through, and what determines business continuity is how fast and how completely organisations can detect, contain, and recover.
To read the full report and access Barracuda's complete email threat analysis and defensive recommendations, visit barracuda.com/reports/2026-email-threats-report.
