New research from Barracuda Research shows how quickly modern email attacks can escalate into full-scale security incidents. In a controlled simulation conducted by Barracuda’s Red Team, a single phishing email led to identity theft, multi-factor authentication (MFA) bypass, persistent access, and device compromise—all in just five minutes.
The results are presented in conjunction with the launch of Barracuda's AI-powered Integrated Email Protection solution, which is designed to provide effective protection against a rapidly changing threat landscape.
“This research shows how AI is increasing both the speed and complexity of cyberattacks. By combining AI-generated phishing, session hijacking, and social engineering techniques, attackers can go from a persuasive email to compromising an account in just minutes,”, says Kristian Lundstrom, solutions architect at Barracuda Networks.
“Organizations need to assume that some phishing emails will reach users and therefore focus on layered protection, continuous monitoring and rapid response to stop attacks before they escalate,” he continues.
This is how the attack went:
- Barracuda's Red Team used generative AI to create a believable phishing email with an urgent request for a document.
- The email was delivered to the recipient, who opened it 21 minutes later and clicked on a link to a fake login page that mimicked Microsoft.
- Within 60 seconds, the user had entered their login credentials. The attackers had redirected the login flow to capture the information exchanged between the user and Microsoft.
- When Microsoft sent an MFA request, it took another minute for the user to complete the verification. This information was also captured by the attackers.
- Within two minutes of the click, the attackers had access to usernames and passwords, session data, and authentication cookies.
- Using the stolen session, the attackers gained access to the user's email account. They were able to read and send emails in the user's name, access SharePoint and OneDrive, create rules in the inbox to hide their activity, and authorize malicious apps to maintain access even after the session expired.
- In a so-called ClickFix scam, the user was prompted to complete an additional verification step. When a code was pasted, a malicious script was activated and used to gain an initial foothold in the environment.
- Within five minutes of the initial click, the attackers had secured persistent access to the environment, allowing them to return, expand access, and install additional malware.
- The attack can then quickly evolve further, for example through increased permissions, data theft, encryption or sabotage, all made possible by the initial phishing email.
“Attackers are using widely available AI and advanced methods to bypass traditional protections and execute their attacks. Our simulation shows how quickly they can gain a foothold in an environment and maintain access. This underscores the urgent need for continuous, real-time, and automated email security that can detect and stop threats even after they reach the inbox,”, says Merium Khalid, Director, AI and Automation, Office of the CTO at Barracuda.
How organizations can strengthen their protection
Standalone security measures are not enough to stop modern, AI-powered, multi-stage email attacks. Organizations need layered protection that operates continuously throughout the attack flow.
Important measures include:
- Phishing-resistant MFA solutions, such as security keys
- Advanced email security protection with real-time detection
- Strong email authentication, such as DMARC
- Educating users about changing methods of social manipulation
- Restricting access to tools often exploited by attackers
Security teams should also monitor for anomalous logins, such as unusual location, device, or time, suspicious behavior after login, and signs of continued unauthorized access such as new inbox rules or scheduled activities.
For more information, read more at Barracuda's blog.








