Site navigation

SMBs Under Siege | Cyber-Attacks Surge in Latest Findings

Graham Turner

,

SonicWall Cyber Threat Report
A new report reveals a relentless rise in ransomware, IoT breaches, and Business Email Compromise (BEC) attacks

SonicWall has released the its 2025 iteration of its Annual Cyber Threat Report, revealing a continued onslaught of cyber-attacks on small and mid-sized businesses (SMBs).

Once exclusively targeting large enterprises, threat actors now use more efficient targeting and AI-driven attacks making it clear that SMBs and organisations of all sizes can’t fight this battle alone – relying on the expertise of a trusted Managed Service Provider (MSP) to defend at-risk revenue and protect the integrity of brands and organisations.

With 61% of new exploit code used within just 48 hours of discovery, the report reveals that the window for response is shrinking, leaving many businesses exposed.

IoT attacks surged by 124%, while encrypted threats climbed 93%, demonstrating the expanding attack surface. Without dedicated cybersecurity expertise or the support of a Managed Service Provider (MSP), many SMBs struggle to keep pace with rapidly evolving threats.

“Threat actors are moving at an unprecedented pace, exploiting new vulnerabilities within days, while we’re observing that it takes some organisations 120 to 150 days to apply a critical patch,” said SonicWall president and CEO Bob VanKirk.

“Now more than ever, businesses need the expertise of an MSP/MSSP backed by with real-time threat monitoring and SOC capabilities. Legacy security solutions are no longer enough, businesses must adopt a new mindset to stay ahead of modern cyber threats.”

With that in mind, we’ll go through some of the key stats and data from SonicWall’s report.

The Unrelenting Rise of Ransomware

Ransomware attacks remained one of the most destructive threats in 2024, with North America seeing an 8% rise in incidents, while Latin America experienced a staggering 259% surge.

The average ransom payment hit $850,700 (£673,000), but when factoring in downtime and recovery costs, the total financial impact often exceeded $4.91 million (£3.88m).

Healthcare emerged as a primary target, with ransomware implicated in 95% of all breaches in the sector. The Change Healthcare breach alone impacted over 100 million people, contributing to the total 198 million Americans affected by healthcare-related cyber-attacks.

Threat actors increasingly employed double and triple extortion tactics. These methods not only encrypt critical data but also threaten to leak or sell sensitive information unless payments are made. In some cases, attackers even directly contacted patients, adding another layer of pressure to organisations already grappling with catastrophic breaches.

The healthcare sector, already burdened with legacy systems and delayed patching practices, was hit particularly hard. Recovery times stretched longer as organisations struggled to restore systems, driving up costs and leaving patients vulnerable.

Meanwhile, human error remained a persistent issue across industries, contributing to data breaches and unauthorised access. Social engineering, phishing campaigns, and malicious file-based attacks — especially through PDFs and HTML files — all exploited human vulnerabilities to devastating effect.

The Growing Complexity of Threat Tactics

Attackers are evolving their methods to bypass traditional defences. Ransomware-as-a-Service (RaaS) models have made sophisticated tools accessible to less experienced cyber-criminals, while Living Off the Land Binaries (LOLBins) – legitimate system tools exploited for malicious purposes – have become a favoured method of attack.

According to SonicWall, tools like PowerShell, schtasks.exe, and cmd.exe accounted for over 80% of all LOLBin abuse cases, enabling attackers to move laterally through networks and escalate privileges undetected.

Notably, 75% of vulnerabilities were exploited within four days of public disclosure, underscoring the need for real-time patch management. High-profile vulnerabilities, such as those in Microsoft Exchange Server and MOVEit, were repeatedly exploited, with ransomware groups like LockBit and BlackCat launching attacks within 24 hours of vulnerability disclosures.

The Surge of Business Email Compromise

According to the report, BEC attacks also saw a dramatic rise, accounting for 33% of all reported cyber insurance events – up from just 9% in 2023. These attacks, which often involve impersonating trusted contacts to manipulate victims, were exacerbated by AI tools that made deception even more convincing.

Vendor Email Compromise (VEC) attacks spiked by 68% in construction and engineering, and 70% in retail and consumer goods. In these cases, attackers infiltrated vendor systems to gather information on payment schedules and decision-makers, later striking with highly convincing, fraudulent payment requests.

Strengthening Defences in an Escalating Threat Landscape

Despite the rising complexity of cyber-attacks, SonicWall’s report emphasises that many threats can be mitigated with proactive measures.

The report states that real-time patch management, Zero Trust security models, and 24/7 Security Operation Centre (SOC) services are critical for minimising exposure to rapidly evolving threats.

Beyond this, the report recommends regular backups, network segmentation, and endpoint detection and response (EDR) solutions to bolster ransomware preparedness. For IoT devices, changing default credentials, applying firmware updates, and restricting network access can mitigate attack vectors.


Recommended reading


Meanwhile, conducting regular employee cybersecurity training can reduce the risk of falling victim to phishing and social engineering scams.

“The data in this year’s threat report underscores a disturbing reality: threat actors are exploiting vulnerabilities at lightning speed, while organisations take far too long to respond,” said SonicWall executive director of Threat Research Douglas McKee.

“Our findings indicate that organisations struggle to keep their businesses safe from the ever-present cyber threats, and the data that we gather paints a clear picture of the growing challenges they face. From ransomware surges to the rapid rise in IoT and encrypted threats, businesses are increasingly at risk.”

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data