Monthly Threat Report May 2026 — Hornetsecurity
Originally reported viaHornetsecurity Monthly Threat Report — May 2026Hornetsecurity's threat research lab processes more than 45 billion emails per month across its managed customer base, providing a unique macro-level view of email-borne threat trends. The May 2026 report documents a 23% month-on-month increase in business email compromise attempts, a continued rise in QR code phishing ('quishing'), and the emergence of a new infostealer family — dubbed 'LummaX' — that has rapidly displaced Redline as the dominant credential harvester in criminal markets.
QR code phishing: the detection gap widens
Quishing attacks embed malicious URLs in QR code images attached to emails or printed materials. Standard email security gateways that inspect URLs in email body text cannot parse QR code images — creating a reliable detection bypass. Hornetsecurity observed a 340% year-on-year increase in quishing attempts in May 2026, with financial services and healthcare as the primary targets.
BEC volume reaches 2026 high
Business email compromise attempts reached their highest monthly volume in 2026 in May, with a notable increase in campaigns targeting accounts payable and HR teams — the two functions with the highest financial transfer authority. AI-generated lure text now passes email security content filters with 91% success rate in A/B testing conducted by Hornetsecurity's red team.
- Deploy email security with QR code scanning capability — standard gateway URL inspection cannot detect quishing attacks.
- Implement DMARC at enforcement (p=reject) on all sending domains — still missing in 43% of organisations in Hornetsecurity's dataset.
- Brief accounts payable and HR teams specifically on BEC patterns — these teams are disproportionately targeted.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.