Cybercrime costs are projected to reach $10.5 trillion globally. The threat landscape is defined less by new exploits and more by scale, speed, and abuse of trust.
Attackers increasingly log in rather than break in. Credential compromise accounts for roughly 30 percent of incidents, while AI-enabled attacks were involved in 16 percent of breaches reported.
The United States remains the most targeted country, accounting for 24.8 percent of global cyberattacks despite representing about 4 percent of the world’s population. Manufacturing is the most targeted sector, while healthcare suffers the highest breach costs.
Most Common Attack Types in 2025
Credential and identity attacks
Stolen credentials are the primary entry point. Infostealer malware surged 84 percent year over year, and attackers increasingly bypass MFA using fatigue and social engineering.
Ransomware and extortion: Median ransom demands reached $1.25 million in 2024,up nearly 80 percent year over year. Data theft and multi-stage extortion are now more common than pure encryption, with encryption occurring in only 50% of attacks.
Supply chain attacks
Third-party involvement rose to 30 percent of breaches. Software supply chain attacks increased, amplifying downstream impact.
Industries Most Impacted
Manufacturing
Attacks increasingly exploit OT and IT integration in manufacturing, where connected production systems create pathways from corporate networks to operational technology.
Healthcare: The average breach cost reached $7.42 million per incident in 2025—the highest among all industries for the 13th consecutive year.
Financial services: BEC attacks surged 37% month-over-month in mid-2025, with average wire transfer fraud requests increasing 97%, and growing exposure in fintech and crypto platforms. Effective wire transfer fraud prevention now requires both technical email controls and procedural safeguards, such as multi-party approval and verbal
Government and Critical Infrastructure
Attacks against critical infrastructure remain a persistent threat, with73% of OT and essential infrastructure, up from49% the previous year. Nation-state operators, particularly from the People’s Republic of China, continue targeting energy, transportation, water systems, and communications sectors.
Technology and SaaS
SaaS platforms face significant account compromise activity driven primarily by credential reuse, session token theft, and misconfigured access permissions. Third-party breaches doubled to approximately 30% of all incidents in 2025, with multi-tenant SaaS environments creating downstream exposure when single accounts are compromised. Stolen credentials were the #2 initial vector in security incidents at16%, while supply chain attacks through SaaS platforms enable attackers to harvest OAuth tokens and CRM data across multiple organizations.
Education
Educational institutions face mounting cybersecurity challenges, with the education sector’s average breach cost rising to $3.80 million in 2025, and ransomware attack rates in the education sector more than doubling to44%. High device volumes, limited IT staffing, and aging infrastructure extend recovery timelines from hours to multiple days in many districts.
What This Means for Leaders
Identity Is the Primary Attack Surface
Credential-based attacks remain the most common breach vector, with stolen credentials involved in 22% of breaches as the top initial access method, while valid account credentials are tied with exploited vulnerabilities at 30% as top initial access vectors in IBM X-Force engagements. This makes identity protection a larger risk factor than software vulnerabilities alone.
Low-Effort Attacks Declined, Targeted Abuse Increased
While 64% of ransomware victims refused to pay in 2024 (up from 50% in 2022), focused campaigns using valid credentials increased in both success rate and impact, with 88% of breaches involving system intrusion patterns that use stolen credentials.
Supply Chain Exposure Is Structural
Third-party involvement in breaches doubled to approximately30% in 2025, driven by vulnerability exploitation of vendor systems and business interruptions. Supply chain breaches add an average of $227,000 to breach costs.
Cloud Accelerates Outcomes on Both Sides
Misconfigurations enabled rapid compromise, with cloud misconfiguration accounting for23% of cloud security incidents. However, organizations using AI and automation in security cut breach response time by 80 days and saved an average of $1.76 million.
Most 2025 breaches were not caused by advanced exploits. They were caused by credential exposure, weak governance, and underestimated complexity. Organizations without dedicated security teams increasingly rely on MSP cybersecurity incident response capabilities to detect, contain, and recover from attacks they cannot prevent on their own.
FAQ
What causes most breaches in 2025?
Credential compromise and identity abuse.
Are AI-driven attacks a real concern?
Yes. AI makes phishing and impersonation faster and harder to detect.
Which industries face the highest risk?
Manufacturing, healthcare, financial services, critical infrastructure, and SaaS.
Is ransomware still the main threat?
Yes, but data theft and extortion without encryption are now equally common.
Why are supply chain attacks increasing?
Attackers use vendors to reach multiple organizations at once.
Does cloud adoption reduce risk?
Only with strong identity and configuration controls.
What should leaders prioritize first?
Identity security, vendor risk, and governance.




