This video is a decorative animation with no sound.
This chart is based on data from Barracuda AI.
Barracuda Research delivers actionable insights from trillions of IT events, AI-powered threat detection and real-world security incidents. Our advanced threat intelligence empowers IT security professionals with the knowledge to identify emerging threats, recognize the warning signs and implement effective protection strategies for their businesses.
The number of known Phishing‑as‑a‑Service (PhaaS) kits doubled last year, with newcomers becoming increasingly sophisticated, evasive and stealthy — bypassing MFA, hiding links and more.
See the details and the action to take to protect against the attacks:
GhostFrame is a new phishing kit that has already launched over a million attacks. It uses a simple, harmless-looking HTML file, with all the malicious activity taking place inside an iframe.
See the details and the action to take to protect against the attacks:
Attackers are leveraging recent enhancements, including different types of CAPTCHA tests, more realistic URLs, compressed code, and more.
See the details and the action to take to protect against the attacks:
Attackers are using an uncommon obfuscation technique: creating random invisible characters in the source code to help evade anti-phishing scanners and obstruct signature-based YARA rules.
See the details and the action to take to protect against the attacks:
See the crucial steps to help strengthen cyber resilience and stay ahead of ever-evolving threats:
Attackers are trying to connect endpoints to unpatched ScreenConnect deployments – or installing ScreenConnect themselves – for unauthorized access to and control of victim systems.
See the details and the action to take to protect against the attacks:
Cybercriminals are stealing or buying usernames and passwords (credentials) and using them to break into systems. Once inside, they launch ransomware attacks or steal sensitive data.
See the details and the action to take to protect against the attacks:
Cybercriminals are accelerating their use of vulnerability exploits, social engineering, stolen credentials, and AI‑powered phishing — making rapid detection and layered defenses more critical than ever.
The Qilin ransomware group is accelerating this year, rapidly increasing its victim count with attacks across a wide variety of sectors.
The harm inflicted on identity crime victims, including financial losses and emotional trauma, has reached crisis levels.
The Office of the CTO comprises Barracuda’s leading threat researchers and technical experts who can provide authoritative insight on a wide variety of cybersecurity topics.
These include:
Connect with Barracuda’s Office of the CTO
“An agentic AI operator will run cyberattacks end-to-end, gathering what it needs, crafting convincing lures, trying a path, watching how the target’s protection or defense reacts, then quietly shifting tactics and timing until it gets what it wants.”
Yaz Bekkar
Principal Consulting Architect – XDR, EMEA
Frontline security predictions 2026: The battle for reality and control in a world of agentic AI
“In 2026, attackers will shift from static tactics to dynamic, context-aware approaches with payloads that are tailored based on device, user activity or timing to evade automated detection.”
Ashok Sakthivel
Director – Engineering, Email Protection
Frontline security predictions 2026: The phishing techniques to prepare for
Barracuda provides a wide range of cyberthreat and cybersecurity insights, tools and support to help organizations and security researchers better understand the rapidly evolving threat landscape and how to manage risk.
Company Information
Our Websites