The Hornetsecurity annual Cybersecurity Report highlights a year marked by rapid development in cyber threats, with attackers leveraging automation, artificial intelligence, and social engineering. In response, defenders have been quick to adapt their governance and resilience strategies.
The report, which examines over six billion emails monthly (totaling 72 billion annually), confirms that emails remain a prevalent vector for cyberattacks in 2025. Notably, emails containing malware surged by 131% compared to the previous year, accompanied by a rise in email fraud attempts by 34.7% and phishing incidents by 21%.
Email Vector in Cyber Threats
Advancements in generative AI have made phishing attacks more convincing, with over 77% of Chief Information Security Officers (CISOs) now considering AI-generated phishing a significant and escalating threat. Concurrently, defense strategies are improving, with 68% of organizations expected to invest in AI-based detection and protection systems by 2025.
Daniel Hofmann, CEO of Hornetsecurity, remarked that "AI is both a tool and a target," emphasizing the rapid spread of attack vectors and the ensuing machine learning-driven arms race.
AI's Role in Cybersecurity Threats
Attackers have increasingly utilized generative AI and automation to pinpoint vulnerabilities
Attackers have increasingly utilized generative AI and automation to pinpoint vulnerabilities, craft compelling phishing lures, and execute complex multi-stage attacks with minimal human intervention.
The influence of AI misuse on the threat landscape is evident, with 61% of CISOs acknowledging AI's role in heightening ransomware risks. Concerns are mounting over synthetic identity fraud, involving AI-generated credentials; voice cloning and deepfake videos to impersonate individuals; model poisoning that corrupts internal AI systems; and the improper use of publicly accessible AI tools by employees.
Challenges with Traditional Security Controls
The integration of new technologies blurs the line between legitimate and malicious actions, reducing the effectiveness of traditional security measures.
Cybercriminals now prefer undermining trust rather than direct breaches. Despite strengthened recovery capabilities, many companies still face the risk of protecting obsolete targets. Future attacks are expected to target less tangible yet more influential aspects, such as institutional trust.
AI-Related Risk Awareness
This year, CISOs identified a significant variance in executive understanding of AI-related risks
This year, CISOs identified a significant variance in executive understanding of AI-related risks. Responses ranged from "deep awareness" to "limited understanding" of AI's impact on such attacks.
Generally, it was found that awareness varied widely among companies. Looking forward to 2026, successful cybersecurity is expected to focus on resilience, characterized by a cultural shift rather than just prevention.
Importance of Cyber Crisis Preparedness
Hofmann continued: “Our latest cybersecurity report shows that companies are learning to recover from attacks without paying ransom." However, the pace of internal security awareness efforts must match AI advancements.
Currently, few executive boards conduct cyber crisis simulations, and comprehensive playbooks remain rare. As AI-driven misinformation and deepfake extortion grow more frequent, fostering a security-centric culture with a strong understanding of AI's risks and opportunities will be crucial by 2026.
Hornetsecurity's annual Cybersecurity Report reveals that in a year of great dynamism, attackers deployed automation, artificial intelligence and social engineering at an unprecedented pace, while defenders rapidly adapted governance, resilience and awareness programs to keep up.
The analysis of over six billion emails processed monthly (72 billion annually) confirms that emails were a constant vector for cyberattacks in 2025. Compared to the previous year, the number of emails containing malware increased by 131%. This increase was accompanied by both email fraud attempts (+34.7%) and phishing (+21%).
AI-generated phishing
The use of generative AI has enabled attackers to make their fraudulent content even more convincing. More than three-quarters (77%) of CISOs rated AI-generated phishing as a serious and growing threat. Nevertheless, defense teams are catching up: 68% of organizations will have invested in AI-powered detection and protection against such threats by 2025.
Daniel Hofmann, CEO of Hornetsecurity, puts the findings into perspective: “AI is both a tool and a target. Furthermore, attack vectors are spreading faster than many realize. The result is an arms race in which both sides rely on machine learning: one side to deceive, the other to defend and prevent attacks.”
Publicly available AI tools
Attackers are increasingly using generative AI and automation to identify vulnerabilities, develop more convincing phishing lures, and orchestrate multi-stage attacks with a minimum of human effort.
The potential for AI misuse is increasingly impacting the threat landscape. 61% of CISOs believe that AI has directly increased the risk of ransomware. Among the most pressing concerns for CISOs are synthetic identity fraud, where AI is used to create documents and credentials; voice cloning and deepfake videos to impersonate users; model poisoning, where malicious data corrupts internal AI systems; and the misuse of publicly available AI tools by employees.
Traditional security controls
These new technologies blur the line between legitimate and malicious activities, making traditional security controls less effective. This is because cybercriminals are more likely to try to undermine trust than to gain access through violence.
Although companies are strengthening their recovery capabilities, many still risk protecting outdated targets. The target of the next wave of attacks will be far less tangible, but all the more powerful: trust.
AI-related risks
CISOs also noted a significant discrepancy this year regarding the understanding of AI-related risks among executives. Some reported that their leaders had anywhere from a "deep awareness" to "no real understanding" of AI's role in such attacks. However, the average response was that while some awareness existed, progress was uneven and varied considerably from company to company.
Looking ahead to 2026, successful cybersecurity will be defined by resilience. This will be characterized less by pure prevention and more by a cultural shift.
Cyber crisis simulations
Hofmann continued: “Our latest cybersecurity report shows that companies are learning to recover from attacks without paying ransom. Nevertheless, internal efforts to raise awareness of security issues must keep pace with the introduction of AI.”
However, only a few executive or supervisory boards conduct cyber crisis simulations, and cross-functional playbooks are the exception rather than the rule. As AI-driven misinformation and deepfake extortion become increasingly common, a security culture based on a high level of preparedness and a clear awareness of AI, its opportunities, and its risks must be central by 2026.