Email fraudsters are changing tactics. Instead of millions of identical emails, they are increasingly launching small, targeted mailings, stretched out over time. Such messages are less like ordinary spam, do not create sharp bursts of activity, and can remain unnoticed by security systems for longer.

In the first half of 2026, "Yandex 360" services processed 50 billion emails – 12% more than a year earlier. At the same time, the number of malicious messages blocked before reaching the inbox increased by 73%. Another 5.7 billion emails were automatically sent to the "Spam" folder.

The main goal of attackers remains personal data. Almost every second unwanted email attempted to extract logins, passwords, bank details, or other confidential information. The number of phishing attacks increased by 45% over the year.

To make the email look more convincing, fraudsters fake the sender's address and impersonate government agencies, banks, and large companies. The number of such impersonations increased by 50% and approached 20 million. At the same time, the share of messages with attachments – fake documents, archives, and other potentially dangerous files – increased by a third.

To find new schemes, filters are no longer sufficient to check only text and links. The system analyzes images, attachments, addresses, sender behavior, and thousands of other signs. Emails continue to be checked even after delivery: if a new threat is later discovered, the message may be marked or blocked already in the inbox.

Read more on the topic: