Monday , August 24 2026
Ransomware

"Cyble Global Cybersecurity Report 2025"
6,000 Ransomware Attacks Show a 50% Increase in 2025

Key Ransomware Statistics:

5,967 ransomware attacks in 2025, up 50% from last year.
The manufacturing sector most affected
Construction, Professional Services, Healthcare, IT top targeted
The U.S. saw the most attacks; Australia listed the top five for the first time
31 incidents hit critical infrastructure

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
Operation CameraSwarm  A single hacker compromise 1400+ Dahua camera worldwide 

2025 will be noted for an explosion in cyber threats, with nearly 6,000 ransomware cases, 6,000 data breaches, and over 3,000 compromised corporate access sales. Companies worldwide confronted an extremely dangerous digital environment. Manufacturing processes stopped, government agencies battled leaks, and critical infrastructure was directly attacked. The Cyble Global Cybersecurity Report 2025 reveals a 50% annual increase in ransomware attacks.

The Global Cybersecurity Report 2025 revealed that data breaches reached the second-highest level ever and the market for stolen access thrived.

The Cyble Global Cybersecurity Report 2025 recorded 5,967 ransomware attacks, a 50% increase from last year. It also noted 6,046 data breaches and leaks, the second-highest level ever.

The underground market for compromised initial access flourished, with 3,013 sales boosting the global cybercrime economy.

Daksh Nakra, Senior Manager of Research and Intelligence at Cyble treated 2025 as a “Major power shift in the threat landscape,” noting that new ransomware groups quickly filled the void left by law enforcement crackdowns. The combination of supply chain attacks and rapid weaponization of zero-day vulnerabilities created what he called “a perfect storm” for enterprises worldwide.

In 2025, two groups were notable. Akira ransomware became the second-most active group after Qilin, launching persistent attacks in Construction, Manufacturing, and Professional Services. Their opportunistic approach let them target almost every major industry.

CL0P ransomware proved its expertise in zero-day attacks. In February 2025, it launched a widespread campaign targeting enterprise file transfer software, affecting hundreds of victims at once, particularly in Consumer Goods, Transportation & Logistics, and IT sectors.

Government and law enforcement agencies faced the most breaches with 998 incidents (16.5% of total). The BFSI sector had 634 incidents. Combined, they made up over a quarter of all breaches, showing that attackers target sensitive citizen data and financial information.

Sales of stolen corporate access are driving cybercrime. Cyble found 3,013 cases of access sales, with the Retail sector most affected at 594 incidents (about 20%). BFSI had 284 incidents, and Government agencies reported 175.

The Cyble Global Cybersecurity Report 2025 noted that critical vulnerabilities in common enterprise technologies were key entry points for attacks. The most exploited included:

CVE-2025-61882 (Oracle E-Business Suite RCE) – leveraged by CL0P
CVE-2025-10035 (GoAnywhere MFT RCE) – exploited by Medusa
Multiple vulnerabilities in Fortinet, Ivanti, and Cisco products with CVSS scores above 9.0

In 2025, 94 zero-day vulnerabilities were found, with 25 rated above 9.0. Over 86% of CISA’s Known Exploited Vulnerabilities had CVSS ratings of 7.0 or higher, affecting Microsoft, Fortinet, Apple, Cisco, and Oracle the most.

Geopolitical Hacktivism Surges:

Cyble’s global cybersecurity report for 2025 reveals that hacktivist activity soared, resulting in over 40,000 data leaks affecting 41,400 different domains, primarily due to geopolitical conflicts.

The Israel-Iran conflict triggered operations by 74 hacktivist groups
India-Pakistan tensions generated 1.5 million intrusion attempts
North Korea’s IT worker fraud schemes infiltrated global companies
DDoS attacks, website defacements, and breaches targeted governments and critical infrastructure

Industry-Specific Insights

Manufacturing: Most attacked sector due to reliance on OT/ICS environments and low tolerance for downtime
Construction: Heavily targeted by Akira; time-sensitive projects created maximum pressure points
Professional Services: Law firms and consultancies compromised for sensitive client data and supply chain leverage
Healthcare: Continued to face attacks from groups like BianLian, Abyss, and INC Ransom due to critical data availability needs
IT & ITES: Service providers exploited to enable cascading supply chain attacks against downstream customers

Ransomware increased by 50%, thousands of breaches occurred, and the black market for hacked access is thriving. The Cyble global cybersecurity report 2025 emphasizes the need for businesses to enhance their security as critical infrastructure, government agencies, and key industries face rising threats.

Check Also

LiteLLM

LiteLLM supply chain attack reveals 153GB of stolen credentials online

153GB record surface online stolen during the LiteLLM supply chain attack linked to thousands of …