Barracuda

35 STATS4 REPORTS

All Statistics

90% of ransomware incidents exploit firewalls through a CVE or a vulnerable account.

RansomwareFirewallCVEVulnerable Account

The fastest ransomware case observed, involving Akira ransomware, takes just three hours from breach to encryption.

RansomwareBreachEncryptionAkira

11% of detected vulnerabilities have a known exploit.

VulnerabilitiesKnown ExploitExploit Risk

The most widely detected vulnerability is CVE-2013-2566, which dates to 2013.

VulnerabilitiesCVE-2013-2566

66% of incidents involve the supply chain or a third party, up from 45% in 2024.

Supply ChainThird-Party Risk

96% of incidents involving lateral movement end with the release of ransomware.

RansomwareLateral Movement

In 2025, attacks bypassing multifactor authentication (MFA) were reported in 48% of phishing attacks.

PhishingMFAMFA BypassPhishing Techniques

In 2025, malicious QR codes were observed in 19% of phishing attacks.

PhishingQR CodesPhishing Techniques

In 2025, obfuscations to hide URLs from detection were seen in 48% of phishing attacks.

PhishingPhishing TechniquesObfuscationPhishind Detection

The number of known phishing kits doubled during 2025, reaching a significant increase in active use.

PhishingPhishing Kits

In 2025, 'ClickFix' social engineering techniques were used in 1% of phishing attacks.

PhishingPhishing TechniquesSocial EngineeringClickFix

In 2025, 90% of high-volume phishing campaigns utilized Phishing-as-a-Service (PhaaS) kits.

PhishingPhishing KitsPhishing-as-a-Service

In late 2025, there were 10 million Mamba 2FA phishing attacks recorded.

Phishing2FA

In 2025, malicious attachments were present in 18% of phishing attacks.

PhishingMalwarePhishing Techniques

In 2025, the abuse of trusted, legitimate online platforms was noted in 10% of phishing attacks.

PhishingPhishing Techniques

In 2025, the use of 'Blob URIs' was noted in 2% of phishing attacks.

PhishingPhishing Techniques

In 2025, attacks leveraging generative AI were reported in 10% of phishing attacks.

PhishingGenerative AI

In 2025, CAPTCHA was leveraged for added authenticity in 43% of phishing attacks.

PhishingPhishing TechniquesCAPTCHA

In 2025, 'polymorphic' attacks that varied the email header, body, and destination were seen in 20% of phishing attacks.

PhishingPhishing TechniquesPolymorphic

78% of organizations worldwide experienced an email security breach in the previous 12 months.

Email

41% of organizations cited brand and reputational damage as the most common consequence of an email security breach.

Email

50% of organizations detected an email security breach within one hour.

Email

36% of organizations lost sensitive data due to an email security breach.

Email

25% of organizations lost customers due to an email security breach.

Email

38% of organizations reported operational impact, including downtime and business disruption, as a consequence of an email security breach.

Email

27% of organizations lost new business as a result of an email security breach.

Email

47% of organizations identified advanced evasion techniques as the main obstacle to rapid incident response.

Email

71% of organizations that experienced an email security breach were also hit with ransomware during the year.

Email

24% of email messages overall are now malicious or unwanted spam.

Barracuda2025 Email Threats Report·1y ago
EmailSpam

Bitcoin sextortion scams account for 12% of malicious PDF attachments.

Barracuda2025 Email Threats Report·1y ago
ScamSextortionPDFEmail

83% of malicious Microsoft documents contain QR codes designed to take users to phishing websites.

Barracuda2025 Email Threats Report·1y ago
EmailMicrosoftQR

As many as 20% of organizations experienced at least one attempted or successful account takeover (ATO) incident per month.

Barracuda2025 Email Threats Report·1y ago
ATOEmail

47% of email domains do not have Domain-based Message Authentication, Reporting and Conformance (DMARC) configured to protect against unauthorized use, including spoofing and impersonation attacks.

Barracuda2025 Email Threats Report·1y ago
EmailDMARC

23% of HTML email attachments are malicious, making them the most weaponized text file type detected. More than three-quarters of the malicious files detected overall were HTML files.

Barracuda2025 Email Threats Report·1y ago
EmailHTML

68% of malicious PDF attachments contain QR codes designed to take users to phishing websites.

Barracuda2025 Email Threats Report·1y ago
EmailPDFQR