¸£Àû¼§ÊÓÆµ

This is a paid press release. Contact the press release distributor directly with any inquiries.

Cybercriminals' Key Attack Vector is 'Trust', VIPRE's Q4 2025 Email Threat Report Reveals

Callback phishing jumps 500%, cybercriminals turn trust and legitimacy against organizations

LONDON, Feb. 4, 2026 /PRNewswire/ -- , a global leader and award-winning cybersecurity, privacy, and data protection company, releases its Q4 2025 Email Threat Trends Report. Processing and analyzing 1.5 billion emails and half a million spam messages, this report spotlights the major email security threats that surfaced in Q4 2025. Predicting the threat trends that will be dominant in 2026, the report's findings intend to assist organizations in fortifying their email defenses against the ever-evolving techniques used by cybercriminals to bypass conventional security systems.

Callback phishing jumps 500%

During Q4 2025, callback phishing scams experienced a resurgence, rising from just 3% to a substantial 18% of all phishing incidents. This represents a remarkable 500% spike and underscores a notable shift back toward leveraging direct human interaction as a key tool for manipulation.

Work fraud delivers success

Business Email Compromise (BEC) consistently remains a powerhouse for cybercriminals across the broader phishing threat landscape. Accounting for 51% of all email fraud cases, BEC's ongoing prevalence highlights that corporate environments often lack robust protection.

Security measures backfire

Cyber attackers are weaponizing the very security features designed to protect organizations. Q4 2025 saw a noticeable uptick in the use of tools like CAPTCHAs and 'I am not a robot' checks to block automated security scanners. Cybercriminals are pairing these tactics with sophisticated fake login screens to steal credentials, evade detection, and trick users into believing they're interacting with secure, legitimate sites.

Trusted brands becoming a risk factor

Attackers are playing the trust game strategically. In Q4 2025, compromised accounts were the number one source of spam emails. Cyber criminals take over legitimate sites, such as Microsoft, to distribute malicious emails under the guise of trusted domains. Likewise, in Q4 2025, attackers increasingly relied on trusted cloud and developer platforms, including Dropbox, Amazon Web Services, and Bitbucket, to host and deliver malicious files.

Well-known brands don't arouse suspicions, but maybe they should.

Impersonation is the dominant BEC email type

Impersonation continues to be the leading form of BEC emails, making up 82% of all BEC incidents for yet another quarter. The remaining 18% are attributed to diversion tactics, such as fraudulent invoices or fake payroll requests.