Every third email is now unwanted or malicious, according to a new report from Barracuda Networks. At the same time, AI and phishing-as-a-service are driving a sharp increase in advanced phishing attacks and account hijackings.
In the report 2026 Email Threat Report shows how both the scope and accuracy of phishing attacks are increasing. A key explanation is ”phishing-as-a-service”, which is currently used in 90 percent of large-scale campaigns. Together with AI-driven social manipulation, this allows attackers to work more systematically and at the same time increase the likelihood of success.
Attackers change tactics
At the same time, attack methods are changing. Instead of traditional attachments, attackers are increasingly using links, often embedded in documents or presented via QR codes that lead to malicious websites. According to the report, 70 percent of malicious PDF files contain QR codes with links to phishing sites.
The report also shows that attackers are increasingly exploiting hijacked email accounts. By sending messages from legitimate senders, they can bypass many security checks and increase the likelihood that the recipient will trust the content.
At the same time, 34 percent of organizations report that they experience at least one account hijacking each month.
The analysis is based on global data from January 2026 and includes over 3.1 billion emails. It shows, among other things, that:
• 1 in 3 emails are malicious or unwanted spam
• 48 percent of all malicious email is phishing
• 34 percent of organizations experience at least one account hijacking each month
• Over 10 percent of HTML attachments are malicious
• 70 percent of malicious PDF files contain QR codes that lead to phishing sites
• 90 percent of large-scale phishing campaigns use phishing-as-a-service
Email remains a key tool
– Email is no longer just a communication channel but crucial to how identities are managed, trust is built and businesses are run, says Merium Khalid, Director of SOC Offensive Security, Office of the CTO at Barracuda Networks.
“As attackers industrialize phishing using AI and service-based tools, defenses must evolve at the same pace. Organizations that stay ahead are prioritizing integrated email security alongside identity protection and automated measures as part of a broader strategy to resist attacks.”.
– When preventative measures, rapid detection and automated incident management work together, companies can reduce risk, limit the impact of compromised accounts and maintain operations even as threats increase.
AI and phishing-as-a-service are changing the threat landscape
The increasing use of AI in cybercrime means that phishing attacks are becoming more credible, automated and harder to detect. Previously, typos, generic wording and poor language handling could reveal attacks. With generative AI, attackers can now create professional and tailored emails in multiple languages with high precision.
At the same time, phishing-as-a-service has made it possible for even less technically advanced actors to carry out sophisticated attacks. Ready-made platforms are sold via criminal forums where attackers gain access to phishing kits, automated campaigns, fake login pages and tools to bypass security filters.
This development means that companies need to strengthen protections around identities, cloud services and email platforms such as Microsoft 365 and Google Workspace. At the same time, security experts point out that Zero Trust strategies, multi-factor authentication and AI-based threat detection are becoming increasingly important to reduce risks.
What does this mean for Swedish companies?
For Swedish businesses, this development means that email security can no longer be handled as an isolated IT issue. As AI is used to automate social engineering and phishing, the need for integrated security platforms, continuous monitoring and user education increases.
Particularly vulnerable are organizations in the public sector, finance, education and healthcare where large amounts of identity data and business-critical information are handled daily.
What does this mean for MSPs in the Nordics?
For MSPs and security partners in the Nordics, demand for managed detection and response, SOC services, identity protection and automated incident management is increasing. Businesses are increasingly looking for end-to-end solutions that combine email security, AI-driven analytics and account hijacking protection.
It also creates new business opportunities for cybersecurity suppliers and managed services.
Risks and opportunities
Risks include increased cyber incidents, identity theft, business downtime and financial fraud. At the same time, these developments create opportunities for organizations that invest in modern cybersecurity, automation and AI-based defense solutions.
Companies that work proactively with security strategies and identity protection will likely be significantly stronger as the threat landscape continues to evolve.








