Report by Barracuda

2025 Email Threats Report

7 FINDINGSPublished Apr 28, 2025
View Original Report →

Key Findings

24% of email messages overall are now malicious or unwanted spam.

Barracuda2025 Email Threats Report·1y ago
EmailSpam

Bitcoin sextortion scams account for 12% of malicious PDF attachments.

Barracuda2025 Email Threats Report·1y ago
ScamSextortionPDFEmail

83% of malicious Microsoft documents contain QR codes designed to take users to phishing websites.

Barracuda2025 Email Threats Report·1y ago
EmailMicrosoftQR

As many as 20% of organizations experienced at least one attempted or successful account takeover (ATO) incident per month.

Barracuda2025 Email Threats Report·1y ago
ATOEmail

47% of email domains do not have Domain-based Message Authentication, Reporting and Conformance (DMARC) configured to protect against unauthorized use, including spoofing and impersonation attacks.

Barracuda2025 Email Threats Report·1y ago
EmailDMARC

23% of HTML email attachments are malicious, making them the most weaponized text file type detected. More than three-quarters of the malicious files detected overall were HTML files.

Barracuda2025 Email Threats Report·1y ago
EmailHTML

68% of malicious PDF attachments contain QR codes designed to take users to phishing websites.

Barracuda2025 Email Threats Report·1y ago
EmailPDFQR