The phishing email that landed in your team’s inbox this morning probably didn’t have a typo. The grammar was flawless. The sender’s name matched someone they correspond with, and the request sounded reasonable in context. That is the actual problem. The advice we’ve spent years teaching people to spot – broken English, urgency, and a slightly off sender address – has been engineered out of modern phishing. The attackers caught up.
In January 2026, Barracuda Research analyzed more than 3.1 billion emails for its 2026 Email Threats Report. The headline numbers are sobering on their own. One in three of those messages was malicious, spam, or unwanted, and 48% of the malicious activity was phishing. The more important finding, though, is what drives that volume. Phishing-as-a-Service kits now power around 90% of high-volume phishing campaigns.
Phishing as a subscription product
Phishing-as-a-Service, or PhaaS, is what it sounds like. Criminal operators sell ready-made phishing infrastructure as a subscription product. The kits come with email templates, convincing fake login pages, hosting, automation, and analytics dashboards so a buyer can see which targets clicked and which credentials were captured.
The skill barrier to running a phishing campaign has collapsed. Whoever wants to target your business no longer needs to know how to code, write convincing English, or set up infrastructure. They subscribe. Barracuda’s analysts describe this as the industrialization of credential phishing, with nine in ten high-volume campaigns running on these kits.
Now add AI to the same equation. Generative models handle the part that used to expose amateur attackers, which was the writing. A model can draft an email in the tone of a busy CFO or a frustrated supplier. It can scrape a target’s LinkedIn profile, reference a real project, and mirror how that person’s actual colleagues write. Personalization at scale used to be expensive, but now it’s simply a prompt.
The trusted-sender problem
The same Barracuda report found that 34% of organizations experience at least one account takeover incident every month. Once an attacker is inside a real mailbox, the phishing they send comes from a real sender, with the right signature, sometimes dropped into an existing email thread.
This is where the standard advice runs out of road. Checking the sender doesn’t help when the sender is genuine but the account has been hijacked. There are no typos to spot when an AI drafted the message. Hovering over a link doesn’t help when the URL routes through a legitimate domain that has been quietly compromised, or through a QR code buried inside a PDF, a tactic Barracuda flagged as growing fast across the dataset. Common-sense defenses assume the attacker is sloppy. Today’s attackers are paying for tools designed to make sure they aren’t.
Four things that matter more now
If detection cannot reliably sit with the end user, it has to sit further up the stack. A few things matter more than they did even a year ago.
The first is layered email security that reads behavior, not just content. Modern detection has to ask whether a sender’s account is behaving normally, whether the links point at infrastructure already linked to abuse, and whether an attachment is hiding a QR code that leads somewhere unusual. That is a different job from older filters built to spot bad attachments and known-bad domains.
The second is identity. Multi-factor authentication on its own is no longer the finish line it once was. Adversary-in-the-middle kits, which Barracuda’s report calls out specifically, intercept authentication sessions in real time. Conditional access, device trust, sign-in risk monitoring, and a fast response when a token is compromised all matter more now. Account takeover detection in particular is a control most businesses have not configured beyond default settings.
The third is awareness training that has caught up to the threat. If your training material still relies on obviously suspicious examples, it is preparing employees for the phishing of five years ago, not the phishing being sent out today. They need realistic scenarios drawn from their own industry, their own supply chain, and the kinds of messages they would see, plus a simple way to flag something that feels off.
The fourth, and the most overlooked, is what happens after an attack lands. A share of phishing attempts will succeed no matter how well-trained your people are. The question is whether your environment is set up to detect a compromised account quickly, contain it, and recover the affected inbox before money moves or data leaves. This is the work that detection and response services, including the Barracuda XDR offering we run for clients, are designed to do.
A practical takeaway
If your email security and awareness program was built for threats in 2020, it was built for a different problem. The Barracuda data is a clear indication that the attacker economy has shifted, and the controls that once kept smaller businesses below the line of attention are no longer doing that job on their own.
If it has been more than 12 months since anyone reviewed your environment, get in touch for an informal review of your current email security posture, or request our Barracuda XDR Cybersecurity Evaluation for a deeper assessment.
Frequently Asked Questions
What is a scalable backup strategy?
A scalable backup strategy is a data protection approach designed to grow alongside your business. It includes automated backups, clearly defined recovery objectives, hybrid or cloud-first storage, and regular testing to confirm data is always restorable as your data volumes and infrastructure increase.
Why is business continuity planning important for growing SMBs?
Business continuity for growing SMBs goes beyond backup. It ensures your people, processes, and technology can continue operating during and after a disruption. Without a continuity plan, even a recoverable data loss event can result in significant downtime, financial impact, and reputational damage.
What are cloud-first backup solutions, and are they right for my business?
Cloud-first backup solutions store your data off-site in secure cloud environments, often in combination with local backup for faster recovery. They are particularly well-suited to businesses with remote teams, distributed offices, or growing reliance on platforms like Microsoft 365.
What does disaster recovery planning in Illinois look like with KKworx?
KKworx provides tailored disaster recovery planning for Illinois businesses, covering risk assessment, recovery objective setting, backup configuration, and ongoing testing. Plans are built around the specific needs of each client rather than a one-size-fits-all model.
How do KKworx data protection services support long-term business resilience?
KKworx combines backup, disaster recovery, and continuity planning into a cohesive service. Regular testing, infrastructure monitoring, and partner-backed solutions like Barracuda Data Protection mean your strategy stays effective as your business scales, rather than becoming outdated.

