2026 Spam and Phishing Report Reveals AI Surge and QR Code Quishing Boom
The 2025 Spam and Phishing Report shows a massive rise in AI-driven phishing attacks. Click-through rates hit 54% for AI-crafted emails, four times higher than human ones. QR code quishing also exploded as attackers hide malware in scam links.
Phishing caused $17,700 in losses every minute last year. AI tools boosted success by 400% in some cases. Attackers used large language models for natural text that beats spam filters. Traditional defenses struggle against these smart fakes.
Voice phishing grew too, with deepfakes up 15%. HTTPS phishing sites jumped 47%, now at 80% of cases. Google blocks 15 billion bad emails daily, but threats keep scaling. New phishing sites launch every 20 seconds worldwide.
Keepnet Labs reports: “AI is dramatically increasing success rates, with click rates up to 4x higher than traditional methods. A 2025 report noted a 400% rise in successful phishing scams due to AI tools.”
Hunto AI states: “AI-generated phishing emails have a 54% click-through rate, compared to just 12% for human-written phishing messages.”
Key 2025 Statistics
| Trend | Stat | Impact |
|---|---|---|
| AI Phishing CTR | 54% vs 12% human | 4x success rate |
| Phishing Growth | 4,151% since ChatGPT | Billions blocked daily |
| Quishing Rise | New QR scams every day | Bypasses mobile filters |
| Vishing/Deepfakes | 30% orgs hit, +15% | Exec impersonation |
| HTTPS Phishing | 80% of sites | Looks legitimate |
Attack Tactics
- AI crafts perfect grammar and context.
- Spear-phishing matches human experts at 56% CTR.
- QR codes lead to fake login pages.
- Polymorphic emails change to dodge rules.
Training cuts clicks to 1.5%. Reporting jumps 28% with drills. New hires face 44% higher risk in first 90 days.

Protection Steps
- Use AI email filters with human review.
- Train staff on QR code checks.
- Block suspicious domains fast.
- Watch for brand spoofs like Microsoft (51.7%).
| Defense Layer | Action | Tools |
|---|---|---|
| Email Gateway | AI + behavioral rules | Proofpoint |
| User Training | Sims, reporting | KnowBe4 |
| MFA Everywhere | Adaptive checks | Okta |
| Mobile Scans | QR validators | Yubico |
FAQ
AI tools spiked emails 4,000%+ with 54% click rates.
QR codes hide links that beat mobile security checks.
Training drops clicks to 1.5%; AI filters block 99.9% spam.
All, but 35% ransomware starts with phishing emails.
Expect more deepfakes, polymorphic attacks, multi-channel hits.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages