Cybercriminals are no longer hacking into corporate networks - they are targeting legacy enterprise email security. According to the newly released Darktrace Annual Threat Report 2026, the battleground for North American businesses has shifted directly into the inbox. As threat actors increasingly leverage cloud account compromise to evade detection, they are paving the way for devastating downstream impacts, characterized by aggressive new ransomware extortion tactics.
For B2B organizations, the data serves as a critical warning that securing the modern digital workspace requires a fundamental shift in strategy.
The findings in this report are drawn from a comprehensive analysis of global cyber threat data collected throughout 2025, analyzing the billions of network connections, cloud interactions, and email communications across Darktrace's global customer base.
While the full report covers a wide array of global cyber threats, including nation-state espionage and operational technology (OT) vulnerabilities, this article focuses on two of the most critical vectors impacting North American enterprises today: the collapse of traditional email defenses and the evolution of ransomware threats.
Keep Reading
- A Third of Businesses Were Hit by a Cyberattack Last Year – Here’s What Needs To Happen Next
- Anthropic’s Mythos Vulnerability Hunting Gains Tempered by Findings of False Positives
- The $20 Hack Threatening Hybrid Work Security: Why a Stolen Laptop Is a Major UC Vulnerability
The Illusion of Trust: Why DMARC is No Longer Enough
The most alarming finding in the report regarding enterprise email security is the collapse of traditional authentication protocols. For years, the industry has relied on DMARC (Domain-based Message Authentication, Reporting, and Conformance) to verify sender identity and block malicious emails. However, Darktrace observed that a staggering 70% of malicious emails successfully passed DMARC authentication in 2025.
The report stated:"Email Remains the Single Most Reliable Attack Channel. Phishing volume, sophistication, and success continue to rise - driven by QR codes, AI-generated content, brand impersonation, and native platform abuse that bypasses legacy filtering."
Threat actors are bypassing these legacy enterprise email security filters by exploiting the very concept of "trust." They achieve this primarily through cloud account compromise. Instead of spoofing a domain from the outside, attackers are logging into legitimate, trusted SaaS accounts and launching attacks from the inside. Because the email originates from a verified, high-reputation domain, traditional enterprise email security gateways wave it through.
Furthermore, attackers are weaponizing new infrastructure at an unprecedented scale. Darktrace identified over 1.6 million newly created domains used for phishing in 2025. These domains have no negative reputation history, allowing them to bypass blocklists and land directly in the inboxes of North American executives. In the Americas, 32% of phishing emails specifically targeted VIPs - a significantly higher rate than in Europe or Asia - highlighting the lucrative nature of high-level cloud account compromise.
Stay ahead of the latest cybersecurity threats by following UC Today on LinkedIn.
The Rise of Quishing and Evasive Payloads
As organizations train employees to spot suspicious links, attackers are adapting their methods to evade both human detection and automated enterprise email security scans. The report highlights a massive surge in "Quishing" - QR code phishing.
In 2025, Darktrace detected over 1.2 million QR code phishing emails globally. Because QR codes are images, they often bypass text-based URL scanners used in standard enterprise email security platforms. To further complicate detection, attackers are employing highly evasive techniques, such as splitting the QR code into two separate images that only form a scannable code when rendered in the email client, or nesting the malicious code within a larger, benign image.
Once an employee scans the code with their mobile device, they are directed to a credential-harvesting sit. This leads directly to cloud account compromise. This tactic is particularly dangerous because it moves the attack off the protected corporate network and onto the user's personal or unmanaged mobile device, effectively blinding the security team to the initial breach.




