A review of the most common cyberattacks in 2025

Cyberattacks reached record levels of sophistication and impact in 2025, with silent intrusions, exploitation of legitimate identities, compromised supply chains and social manipulation using artificial intelligence.
It is no longer enough to simply “protect” perimeters: it is necessary to predict, detect quickly and respond precisely to avoid operational, financial and reputational damage.
Recent data show sharp growth in attacks on corporate and government environments, as well as incidents that affected millions of users worldwide. Understanding the vectors, real examples and impacts of these attacks is essential to strengthen effective defence strategies.
Most common cyberattacks in 2025: techniques, examples and lessons for IT
Below we detail the main types of attack that stood out through 2025, with real examples that happened in large companies and organizations.
1. Ransomware attacks with double and triple extortion
Ransomware remains one of the most prevalent and lucrative attack vectors for criminals. In 2025 the tactic evolved to include double and even triple extortion. That means data is not only encrypted, but also exfiltrated for use in blackmail or leaking if the ransom is not paid.
A significant example was the incident with the early childhood education company Kido International. Hackers accessed and leaked data on around 8,000 children and employees, including names and addresses, as part of a ransomware attack with data exfiltration and public threats against the victim.
2. Cyberattacks based on credential theft and legitimate use
Attacks that start with compromised legitimate credentials became one of the most effective tactics in 2025. Criminals use sophisticated phishing or buy credentials in underground markets to access systems without triggering traditional defence alerts.
A recent example of this kind of activity involves hacker groups linked to Russian intelligence, which employed phishing, credential harvesting and lateral movement techniques. With those, they compromised critical cloud infrastructure and strategic sectors.
3. Cyberattacks on digital supply chains
Supply chain attacks became extremely dangerous because they hit multiple organizations at once through a compromised supplier or software component. In 2025 this vector appeared with high frequency and impact.
An emblematic case was the attack on the British carmaker Jaguar Land Rover, which interrupted global production for weeks after critical systems were compromised. On top of that, the attack also affected suppliers, causing a domino effect across the production chain.
Another example was the leak of data on more than 5.6 million people after an attack on a third-party partner of the credit checking company 700Credit. That cyberattack demonstrated once again how a vulnerable supplier can expose sensitive consumer data.
4. Exploitation of vulnerabilities in cloud and hybrid environments
The massive adoption of cloud services and hybrid infrastructure brought with it an increase in attacks exploiting inadequate configuration, exposed APIs and governance gaps.
Among the most emblematic episodes of the year is the incident recorded in July 2025. It affected services hosted on Amazon Web Services (AWS) and impacted critical operations in Brazil, including the temporary unavailability of the PIX system operated by the Central Bank of Brazil. The case highlighted how excessive dependency on cloud environments, combined with resilience and contingency gaps, can create cascading effects on services essential to the population.
Another notable episode involved Salesforce, which had sensitive data exposed after the exploitation of improper permissions and badly configured integrations in its cloud environments. The incident reignited the debate about identity and access management (IAM) and the risks tied to accounts with excessive privileges on SaaS platforms widely used by companies of every size.
These cases reinforce a trend already pointed out by security reports. Attacks based on compromised credentials, poor cloud service configuration and inadequate governance remain among the main vectors of data leaks and operational interruptions.
In hybrid environments, where on-premises and cloud infrastructure coexist, complexity increases, demanding more robust strategies for monitoring, access control and incident response to mitigate systemic risk.
5. Advanced social engineering using AI
Attacks combining social engineering with artificial intelligence tools have been growing. Scams using voice and video deepfakes to bypass authentication systems or induce employees to hand over sensitive information became a reality in 2025.
Although many of these attacks are not widely reported for legal reasons, security research indicates significant growth in this type of threat. In the education sector, for example, phishing rose more than 224%, exploiting academic calendars and deadlines to lead users into credential theft.
Impacts of cyberattacks on IT operations and strategy
The effects of attacks vary with the technique used, but the most common impacts observed in 2025 include:
- Interruption of critical operations: companies were inoperative for days or weeks, as in the Jaguar Land Rover case;
- Exfiltration and leakage of sensitive data: personal and corporate data were compromised, as in the 700Credit case;
- Regulatory and legal pressure: leaks expose companies to fines and lawsuits under data protection laws;
- Reputational damage: public incidents affect the trust of clients, investors and partners.
These consequences become even more dangerous when we know that a recent survey indicated 21% growth in global cyberattacks in the second quarter of 2025. Among the most targeted sectors are education, government and telecommunications.
How to reduce risk in a scenario of persistent threats
Faced with this diversity of vectors, fragmented or reactive strategies are no longer enough. Modern organizations need to invest in capabilities that unite continuous visibility, intelligent event correlation and orchestrated response.
Critical elements include:
- Behaviour-based detection and anomaly analysis;
- Automated, coordinated response across endpoints, network and identity;
- 24x7 monitoring with real-time threat correlation;
- Up-to-date threat intelligence, including feeds on emerging attacks.
This kind of approach lets IT teams detect the threat earlier, acting precisely before the impact spreads.
How AKEN mitigates the risks of cyberattacks
AKEN offers an integrated platform to face the 2025 scenario with real effectiveness:
- 24x7 SOC (Security Operations Center): a specialized team monitors events in real time, correlates attack indicators and identifies malicious behaviour before it causes significant damage;
- EDR (Endpoint Detection and Response): advanced security on endpoints detects intrusion attempts, lateral movement and execution of malicious payloads, even after an initial compromise;
- Continuous monitoring: constant visibility across physical, virtual and cloud infrastructure, making sure threats do not slip by during low-activity windows;
- Up-to-date threat intelligence: insight into new vectors and ongoing campaigns, contextualized for the client environment.
These layers work in a coordinated way, reducing mean time to detect (MTTD) and mean time to respond (MTTR), two critical indicators for limiting the impact of a real attack.
Talk to AKEN specialists and find out how to strengthen your defence strategy to face the most advanced cyberattacks of 2025.
Talk to AKEN specialists