Report by Paubox

2025 mid-year email breach data reveals there's no slowing down

15 FINDINGSPublished Sep 5, 2025
View Original Report →

Key Findings

The largest single email breach, affecting United Seating and Mobility, exposed over half a million records.

HealthcareEmail

More than 1.6 million patient records were compromised across all analysed email-related healthcare incidents that occurred in the first half of 2025.

HealthcareEmail

Incidents involving Mimecast email customers accounted for 8% in healthcare.

HealthcareEmailMimecast

Incidents involving Barracuda email customers accounted for 5% in healthcare.

HealthcareEmailBarracuda

79% of breached healthcare organizations have ineffective DMARC protection. This is up dramatically from 65% in 2024.

HealthcareEmailDMARC

Incidents involving Proofpoint email customers accounted for 6% in healthcare.

HealthcareEmailProofpoint

Business associates (including billing vendors, imaging firms, and outsourced IT providers) were involved in 17 of the 107 email-related breaches in healthcare. This represents 16% of all incidents.

HealthcareEmailThird-party risk

41% of healthcare organizations are now classified as high-risk. This compares to just 31% last year.

HealthcareEmail

Cyberattacks are cited as the leading cause of critical workflow disruptions by 50% of healthcare organizations.

HealthcareEmail

IT leaders estimate that only 5% of known phishing attacks in healthcare are actually reported by employees to security teams.

HealthcareEmailPhishingSecurity awareness training

The sharp rise in Microsoft 365 email breaches in healthcare represents a 21% increase year-over-year.

HealthcareEmailMicrosoft

The Episource breach affected 5.4 million individuals

HealthcareEmail

81% of healthcare email breaches were classified as hacking or IT incidents.

HealthcareEmail

Microsoft 365 environments now account for 52% of all healthcare email breaches. This represents a dramatic surge from 43% just one year ago.

HealthcareEmailMicrosoft

The average healthcare email breach exposed nearly 16,000 individual records in the first half of 2025.

HealthcareEmail