Email threats are becoming more dangerous than ever — so keep an eye on your inbox

A shocked girl sitting on sofa at home looking on laptop screen
(Image credit: Shutterstock)

Cyberattacks spread via email are still rising, and with generative artificial intelligence (AI), they have gotten even more dangerous, a new report from Barracuda Networks has claimed. 

After analyzing 69 million attacks across 4.5 million mailboxes over the past 12 months, Barracuda said business email compromise (BEC), conversation hijacking, and QR code attacks were all growing.

In fact, BEC attacks now make up a tenth (10.6%) of all email-based social engineering attacks, up from 8% in 2022, and up from 9% in 2021. At the same time, conversation hijacking made up 0.5% of all social engineering attacks in the past year, which is an increase of some 70%, compared to the 0.3% back in 2022.

Gmail and bit.ly

This method’s overall share is relatively small since it requires a lot of effort to execute, but the payout can still be significant, Barracuda warns. 

With conversation hijacking, a threat actor will compromise a person’s email account, and look for conversations with potential targets. They will then “hijack” the conversation, and reply to the latest email, continuing the chain of communication. That way, the victim has no reason not to trust the contents of the email, making distributing malware and stealing sensitive data that much easier.

Finally, around 1 in 20 mailboxes were targeted with QR code attacks, which are relatively successful since they mostly bypass traditional email filtering solutions. Furthermore, they make the victims use a personal device to scan the QR code, which is usually not protected by corporate security software.

The attackers will usually go for Gmail users, Barracuda added, since Gmail accounted for 22% of the domains used for social engineering. What’s more, bit.ly is the go-to tool for URL shortening, used in almost 40% of social engineering attacks. 

“IT and security professionals need to stay focused on the evolution of email threats and what this means for security measures and incident response,” said Sheila Hara, Sr. Director of Product Management at Barracuda. 

“This involves understanding how attackers can leverage generative AI to advance and scale their activities, and the latest tactics they’re using to make it past security controls. The best defense is AI-powered cloud email security technology that can adapt quickly to a changing landscape and doesn’t solely rely on looking for malicious links or attachments.”

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Phishing
Corporate executives are being increasingly targeted by AI phishing scams
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Cartoon Phishing
Hackers use GenAI to attack more frequently and effectively
A padlock resting on a keyboard.
AI-powered cyber threats demand enhanced security awareness for SMEs and supply chains
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Help! We're drowning in email spam, it's about to get worse and there's nothing we can do to stop it
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection