Site navigation

Brute Force & Stolen Credentials Driving Surge in Ransom Attacks

Tom Quinn

,

ransomware tactics 2025
Ransomware attackers are relying on tried and tested methods to find entry points, with stolen credentials, brute force and the exploitation of remote desktop tools their main tactics.

Over half of ransomware incidents last year started with threat actors compromising perimeter security appliances like virtual private networks (VPNs) and firewalls, according to a new report from insurance and cybersecurity company Coalition.

According to the firm’s Cyber Threat Index 2025, vulnerabilities in these perimeter defence systems accounted for 58% of attacks over 2024, far ahead of the exploitation of remote desktop products, coming in second place with 18%.

Across all ransomware claims dealt with by Coalition, the most common initial access vectors (IAVs) were stolen credentials (47%) and software exploits (29%), however, despite ransomware attackers developing ever more sophisticated techniques to harvest credentials and find access, researchers observed brute-force password guessing in just under half (42%) of incidents.

Exposed logins were also found to be a key driver of ransomware risk, with Coalition detecting over 5 million internet-exposed remote management solutions, along with tens of thousands of exposed login panels across the internet. 

The study found that most businesses (65%) have at least one internet-exposed web login interface, also known as panels, with seven businesses found to have at least 100 exposed web login panels, a level of exposure that helps explain how stolen credentials represent 47% of known ransomware initial access vectors.

Coalition claims that for businesses to reduce their exposure to ransomware, they should focus on the riskiest of these exposed logins, with ransomware events far more likely to begin with compromised credentials used to access remote desktop protocol (RDP) or perimeter security appliances, typically VPNs.

Admin panels, for example, were among the fifteen most commonly exposed high-risk interfaces, accounting for a fifth of observed cases where network devices were configured.

Perhaps even more worrying, however, is the sharp increase in the number of publicly known vulnerabilities the report predicts for the coming year.

Coalition forecast that the total number of published software vulnerabilities will rise to over 45,000 in 2025, a rate of nearly 4,000 per month and a 15% jump over the first ten months of 2024.


Recommended reading


The report urges businesses to be more aware of the increasing use of zero-day vulnerabilities, as well as those requiring no user interaction or authentication to gain remote code execution, elevate privileges, or extract data, but notes that only a fraction of these are being exploited in the wild, meaning defenders should focus on the highest-risk software vulnerabilities.

“While ransomware is a serious concern for all businesses, these insights demonstrate that threat actors’ ransomware playbook hasn’t evolved all that much—they’re still going after the same tried and true technologies with many of the same methods,” said Alok Ojha, Coalition’s head of products security. 

“This means that businesses can have a reliable playbook, too, and should focus on mitigating the riskiest security issues first to reduce the likelihood of ransomware or another cyber-attack. 

“Continuous attack surface monitoring to detect these technologies and mitigate possible vulnerabilities could mean the difference between a threat and an incident.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data