Ransomware gangs and other financially motivated actors account for more than half of all active threat groups tracked last year, according to new data from Google’s Mandiant cyber-defence service.
Mandiant’s latest M-Trends 2025 report found that 55% of threat groups active in 2024 were financially motivated, up 2% on 2023 and 7% on 2022, with profit-driven cyber-criminals increasingly targeting more lucrative industries in search of a payout.
According to the report, the most commonly targeted sectors last year were financial services (17.4%), business and professional services (11.1%), and high-tech industries (10.6%), highlighting that threat actors are prioritising businesses with valuable data, high transaction volumes, and where financial disruption could have the most impact.
More than half of the time, organisations only noticed the hostile activity after it was pointed out by an external entity, and while 43% of the time, that was law enforcement or cybersecurity vendors, in 14% of instances, this came from the adversaries themselves, often in the form of ransom notes.
In ransomware cases specifically, Mandiant found that threat actors notified their victims of their malicious campaigns 49% of the time, with internal identification only occurring in 30% of instances.
The figures suggest that many businesses are unaware of exactly what is happening on their networks, leaving attackers to operate with impunity and cause potentially severe damage.
That idea is clearer still when looking at median dwell time, the average time an attacker spends within a system or network before being detected.
Mandiant’s research found that the global median dwell time rose to 11 days in 2024, up from 10 days in 2023, although still far from the peak of 16 days reported in 2022.
In that time, threat actors can move throughout a network, finding weak points and the most valuable data, and if left long enough, could lock up or transfer critical assets out of an organisation’s control.
A closer look at the data reveals the extent of the problem. Mandiant found that it took an average of 26 days for external entities to raise the alarm about threat activity, 10 days for organisations to discover it internally, and just five days before adversaries let their victims know of their own accord.
That means at least some threat actors are moving too fast for security teams or third-party vendors to keep up with, a concern backed up by recent research from ReliaQuest, which found that once inside networks, the average ‘breakout time’ for cyber-attack is now just forty-eight minutes.
Mandiant’s research shows that an increase in speed is just one new tactic attackers are adopting in search of more cash.
The report highlights that threat actors last year increasingly targeted Web3 technologies such as cryptocurrencies and blockchains for theft, money laundering, and financing illicit activities, which can better hide their activity from law enforcement due to complex fund flows..
Mandiant also identified more instances of ‘drainers’ and smart contracts being used by cyber-criminals, which can steal cryptocurrency from users’ wallets, with ‘drainer-as-a-service’ (DaaS) markets emerging to facilitate these attacks.
Recommended reading
- ‘Big Game’ Ransomware Tactics Drives Spike in Attacks
- Is Automation Fuelling a New Era of Cyber-crime?
- Phishing Attacks Spiked in 2024 As Other Cyber-threats Declined
“One of the ways threat actors keep up with the constantly evolving cyber defence landscape is by raising the level of sophistication of their attacks,” said Jurgen Kutscher, vice president of Mandiant Consulting, writing in the company’s blog.
“However, not all successful attacks are highly complex and technical. Many times attackers will take advantage of the opportunities that are made available to them.
“Other ways attackers are taking advantage of opportunities is by exploiting gaps and risks introduced in cloud migrations, and targeting unsecured data repositories to obtain credentials and other sensitive information.”
To protect against these threats, Mandiant recommended that firms look to implement layered security approaches that emphasise fundamentals such as vulnerability management, least privilege, and hardening, while also investing in advanced detection technologies and MFA, as well as consider threat hunting exercises to proactively search for compromise.





