Trends in Spam, Phishing, Spoofing, Malware & DNS Abuse
By vSpam.org Independent Research, vSpam Researcher Team
Abstract
May 2026 monthly research brief. Three flagship datasets published in sixteen days and disagreed: Barracuda found one in three messages malicious across 3.1 billion emails, the Verizon DBIR placed vulnerability exploitation ahead of social engineering, and APWG recorded 971,181 phishing attacks with telecom rocketing from 5.9% to 33% of all attacks. The issue reconciles the divergence as a window-alignment artefact and reports the vSpam.org collector corpus.
Key Findings
- 1APWG recorded 971,181 phishing attacks in Q1 2026, up 13.8%, with telecom rising from 5.9% of attacks in Q3 2025 to 33%
- 2The Verizon DBIR and Cisco Talos reach opposite conclusions on the leading initial-access vector because their observation windows do not overlap
- 3Ransomware fell 16% to 646 victims — the first month of 2026 below the 2025 pace — while three groups entered the top ten simultaneously
- 4Only about 9% of domains combine DMARC enforcement with reporting, against a 52.1% headline adoption figure
- 5vSpam.org corpus recorded 38.1% of May's domain indicators concentrated in four novelty gTLDs, a bulk-registration signature with no precedent in our data
Topics
Cite this report
vspam.org Research Team. "Trends in Spam, Phishing, Spoofing, Malware & DNS Abuse." 2026-VSPAM-005, vspam.org, June 12, 2026. https://vspam.org/research/trends-spam-phishing-spoofing-malware-dns-abuse-may-2026
Licensed under CC BY 4.0. You may share and adapt this work with attribution.