logo

Key findings from the 2026 Sublime Email Threat Research Report · Blog · Sublime Security

ID: f54f57ba-f19c-51cc-928c-8c36b0d2c813

STIX ID: report--f54f57ba-f19c-51cc-928c-8c36b0d2c813

Feed Name: Sublime Security Blog

Date Published: 2026-02-10

Date Updated: 2026-05-01

...
...

The report analyzes 2025 email threat trends and finds attackers shifting toward context-driven, highly targeted tactics: business email compromise (32% of threats) with 28.1% of BEC using thread hijacking, a 282.7% surge in QR-code phishing in H2, increasing use of calendar invites for callback phishing, rising AI-generated attacks (19.29% in Q4), widespread LOTS/service-abuse on niche platforms, and extensive evasion stacking (34.7% of attacks used multiple evasion techniques). It concludes organizations must move beyond static rules to adaptive, behavioral, and agentic AI defenses to detect social-engineering patterns regardless of delivery method.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.