Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Scams & Phishing Security Education Videos Mobile Security Your Security Education Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
New Report Finds Email Phishing is Out of Control—Are You Prepared?
Facebook   X   LinkedIn   Email

New Report Finds Email Phishing is Out of Control—Are You Prepared?

November 3, 2025

A recent study of email phishing finds we have an even bigger target on our backs than we thought. Thanks to Barracuda’s 2025 Email Threats Report, we find out just how huge a security problem phishing is today. The cringe-worthy report spotlights how out of control email phishing has become, so if you have an email account, and who doesn’t, keep reading.

30 Malicious Emails Every Day

The report finds one out of four emails today are malicious or spam. Getting hammered by attackers is now an everyday reality since the average user gets about 121 emails a day. But among the 121 messages, about 30 are sent with bad intent. Overall, that’s a 24% malicious slice of your inbox, and Barracuda’s findings don’t stop there.

  • Nearly 25% of all HTML attachments are malicious and overall are the most weaponized files
  • 83% of malicious Microsoft 365 documents have QR codes linked to phishing websites
  • 68% of PDF attachments are malicious, also having QR codes linked to phishing sites

Be prepared

Since the report finds email phishing is blowing up, we all need to be ready for the “Battle Of The Inbox.” So much is at stake when our passwords and 2FA codes are stolen. Cyber crooks also hide malware and malicious links in the emails. Also at risk is our PII (personally identifiable information), financial account details, account takeovers, our identities, and so much more. 

Microsoft’s Outlook and Google’s Gmail are getting tough about email security and hopefully others will follow suit. Remember, no one is immune from this new surge in email phishing. If it’s one thing we can take away from Barracuda’s report, be prepared because the bad guys are coming for us all.


QR Code Phishing Scams Spike 587%

Scams & Phishing

QR Code Phishing Scams Spike 587%

It’s the latest form of email phishing to hit the headlines. Researchers at Check Point find QR code phishing scams, called “Quishing” were up a whopping 587% in just two months. Quishing is a phishing attack using emails to send a malicious QR code. And now this credential-stealing scam has grown into epic proportions. In our growing desire for instant information, QR codes and Quishing present a uniquely tempting challenge. Here’s what you need to know to help avoid Quishing. READ FULL STORY

Online Security Tips From The BBB

Your Security

Online Security Tips From The BBB

Champions of consumers that they are, the Better Business Bureau (BBB) posted a warning reminder on their website about some of the risky online scenario’s consumers face every day. Keeping cyber safety in the forefront of our online activities isn’t always easy, but it’s always possible to do. The BBB knows this and wants consumers to be aware of some of the latest cyber scams and just how truly slippery they can be. It’s well-worth heeding what the BBB has to say about cybercrime and how to avoid the pitfalls that every hacker hopes we fall into. READ FULL STORY

Phony Voicemail Links Steal Employee Credentials From Office 365 And Outlook Users

Scams & Phishing

Phony Voicemail Links Steal Employee Credentials From Office 365 And Outlook Users

Most of us know phishing emails and fake texts are a hacker’s calling card for stealing valuable PII. But recently, researchers at Zscaler cloud security sounded the alarm about an unusual malware campaign using voicemail-themed email phishing as the primary hook for cyberattacks. It’s only after Zscaler fell victim to this campaign that the company felt compelled to study it further. Zscaler finds this cybercrime targets employees in the U.S. using Microsoft Office 365 and the Outlook email service. READ FULL STORY

Credential Phishing Targets Hospital IT Desks

Corporate Security

Credential Phishing Targets Hospital IT Desks

Socially engineered attacks end with nothing social about them. In fact, some say a better name would be "anti-social attacks." Names aside, the attacks aim to exploit human trust while tricking people into divulging their personal identifiable information (PII) in ways that benefit an attacker. These tactics are posing a significant threat to data security and privacy. The American Hospital Association (AHA) shares its knowledge about how these social engineering attacks are making the rounds at hospital IT help desks. READ FULL STORY

Top Phishing Scams Continue To Improve And Grow

Education

Top Phishing Scams Continue To Improve And Grow

Much to our dismay, cybercrooks keep finding ways to better the phishing tools they have and find other ways to include new and sneakier methods of thievery. Organizations and individuals are targets and money, identities, credentials, and more are stolen from both every day. Even cyber-savvy users can get caught in phishing scams if they don’t pay close attention to the signs and signals that something isn’t quite right. Reviewing the most pervasive phishing scams is always recommended. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...