Key Findings
Docker environments accounted for 54.3% of honeypot targeting when measured by unique malicious IP addresses.
Registered software vulnerabilities rose 20% in 2025.
70% of phishing emails pass DMARC authentication.
Large-text, long-form phishing messages increased from 27% to 33% year-over-year.
QR code-based phishing attacks increased 28%, rising from 940,000 in 2024 to over 1.2 million in 2025.
More than 1.6 million phishing emails rely on newly created domains for malicious activity.
More than 8.2 million phishing emails targeted VIPs in 2025, representing over a quarter of all phishing activity that year.
Novel social engineering phishing techniques increased from 32% to 38% year-over-year.
Across cloud providers, Azure draws 43.5% of observed malware samples, Google Cloud Platform draws 33.2%, and Amazon Web Services draws 23.2%.
94% of organizations worldwide rely on cloud computing.
32 million phishing emails were detected globally in 2025.
Nearly 70% of incidents in the Americas began with stolen or misused accounts.