Kaspersky reports a significant 15% increase in malicious email attacks throughout 2025, with individuals and corporate users encountering over 144 million malicious and potentially unwanted email attachments. According to the cybersecurity company’s telemetry data, spam accounted for nearly half of all global email traffic at 44.99%, encompassing not only unsolicited messages but also various threats including scams, phishing attempts, and malware distribution.

Regional Distribution of Email Threats

The Asia-Pacific region experienced the highest concentration of email antivirus detections in 2025, reaching 30% of the global total. Europe followed with 21%, while Latin America accounted for 16%, and the Middle East represented 15% of detections. Russia and the Commonwealth of Independent States contributed 12%, with Africa recording 6% of email-based threats.

At the country level, China led with the highest rate of malicious and potentially unwanted email attachments at 14% of total detections. Russia ranked second with 11%, followed by Mexico and Spain each at 8%, and Turkey at 5%. Detection rates peaked moderately during June, July, and November throughout the year.

Emerging Trends in Malicious Email Attacks

Kaspersky’s annual analysis identified several persistent trends expected to continue into 2026. Attackers are increasingly combining various communication channels, luring email users to switch to messaging apps or call fraudulent phone numbers. Investment scam mailings often redirect victims to fake websites requesting contact information, after which cybercriminals follow up with phone calls.

Threat actors are employing diverse evasion techniques in phishing and malicious email attacks, frequently disguising phishing URLs through link protection services and QR codes. These QR codes are embedded directly in email bodies or PDF attachments, concealing phishing links while encouraging users to scan them on mobile devices with potentially weaker security measures than corporate computers.

Exploitation of Legitimate Platforms

Kaspersky experts discovered fraudulent tactics abusing legitimate platforms, including OpenAI’s organization creation and team invitation features to send spam emails from authentic OpenAI addresses. This technique tricks users into clicking scam links or dialing fraudulent phone numbers. Additionally, calendar-based phishing schemes that originated in the late 2010s resurfaced last year, specifically targeting corporate users.

Business email compromise attacks have become more sophisticated, with attackers incorporating fake forwarded emails into their correspondence. These messages lack thread-index headers or other identifying markers, making verification of legitimacy within email conversations extremely difficult.

Expert Insights and Security Recommendations

“Email phishing shouldn’t be underestimated. Our report reveals that one in ten business attacks starts with phishing, with a significant proportion being Advanced Persistent Threats. In 2025, we saw an increase in the sophistication of targeted email attacks. The commodification of generative AI has significantly amplified this threat, enabling attackers to craft convincing, personalized phishing messages at scale with minimal effort.”

Roman Dedenok, Anti-spam Expert at Kaspersky

To protect against these evolving threats, Kaspersky recommends treating unsolicited invitations from any platform with suspicion, even from apparently trusted sources. Users should carefully inspect URLs before clicking and avoid calling phone numbers indicated in suspicious emails. For corporate environments, Kaspersky Security for Mail Server offers multi-layered defense mechanisms powered by machine learning algorithms. Organizations should ensure all employee devices, including smartphones, are equipped with robust security software and conduct regular training on modern phishing tactics.