Site navigation

Report: Cyber-attackers Seeking Chaos To Get More Cash

Staff Writer

,

financially motivated cyber attacks
Threat actors are changing their tactics to include disruption in a bid to squeeze bigger payouts from their victims.

Financially motivated cyber-attackers have changed their tactics, and now aim for deliberate disruption and sabotage to inflict maximum damage, hoping to coerce organisations into paying ever higher ransom demands. 

That’s according to new research from Palo Alto Networks Unit 42 threat research team, which revealed that 86% of major cyber incidents in 2024 resulted in operational downtime, reputational damage or financial loss.

The cybersecurity firm’s 2025 Global Incident Response Report, based on 500 major cyber incidents from across thirty-eight countries, shows that AI-assisted threats and multipronged intrusions have helped attackers increase the speed, sophistication and scale of their assaults, resulting in median initial extortion demands increasing by nearly 80% to $1.25 million (£984k) in 2024.

According to Unit 42’s data, attackers managed to exfiltrate data in less than five hours in 25% of incidents, three times faster than in 2021, while even more alarming is that in one in five cases, data theft occurred in under an hour.

In one instance, Unit 42 tracked operatives of RansomHub as they accessed a municipal government network through an unsecured VPN, and within seven hours were able to steal 500 GB of data, however even more alarming was Scattered Spider’s social engineering of a service provider’s helpdesk, which resulted in the group retrieving credentials and compromising a domain-privileged account — all within forty minutes.

Expanding attack surfaces are also proving to be a problem, with 70% of incidents involving the exploitation of three or more points of exposure, forcing security teams to defend endpoints, networks, cloud environments and the human factor all at once.

Threat actors are becoming bolder in their attacks against supply chains and cloud infrastructure, frequently being found to use compromised cloud resources to exploit other unrelated targets. 

The data shows that nearly a third (29%) of financially motivated cyber-attacks last year involved cloud environments, with 21% causing operational damage to cloud environments and assets.

Added to that, the study found attackers are now more often observed disguising themselves within misconfigured environments to scan vast networks. In just one campaign, the Unit 42 researchers found that attackers had managed to scan 230 million unique targets to find sensitive data.

The report underscores three primary reasons behind the success of these adversaries.

First is the difficulty in managing overly complex security environments, with silos preventing detection, despite 75% of incidents having evidence already in logs.

Another issue is that gaps in visibility are allowing attacks to go undetected, with 40% of cloud incidents stemming from unmonitored cloud assets and shadow IT, which makes lateral movement easier for attackers.

Finally, the report stresses that excessive trust is making attacks more problematic, evidenced by the 41% of attacks which leveraged excessive privileges, allowing lateral movement and privileged escalation.


Recommended reading


“Attackers have rewritten their playbooks leveraging AI, automation and multipronged attack strategies to bypass traditional defences,” concludes the report.

“The time between initial compromise and full-scale impact is shrinking, making rapid detection, response and remediation critical.

“The key to staying ahead in 2025 is to proactively secure networks, applications and cloud, as well as empower security operations with AI-driven detection and response for full visibility and faster threat mitigation.”

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data