Site navigation

Microsoft: Data Theft Drives 80% of 2025 Cyber-Attacks

Tom Quinn

,

ransomware 2025
Identity-based attacks, social engineering, and cloud intrusion are among the key cyber trends highlighted by Microsoft’s annual defence report.

Extortion and ransomware are behind over half of all cyber-attacks, according to the latest research from Microsoft, with more than 80% of the incidents investigated by the tech giant last year involving data theft and exfiltration.

In what will be no surprise after a year of repeated, high-profile ransomware attacks in the UK, Microsoft’s latest annual Digital Defense Report found that more than half (52%) of these incidents involved financially motivated threat actors, as opposed to intelligence gathering, accounting for just 4% of attacks.

But while Microsoft found that organisations around the world remain under constant threat from a growing wave of ransomware attackers, much as in previous years, these attackers are now leveraging new tactics and technologies as they compete with each other in an increasingly fragmented criminal economy.

For example, the report found that a shift away from phishing as the go-to method for initial access, with ransomware operators increasingly turning to social engineering to steal or reset credentials—especially through vishing and tech support scams. 

This year, Microsoft observed several campaigns in which impersonated help desk staff, using platforms like Teams to message victims, and tools like Quick Assist to gain remote access to their machines.

Described by Microsoft as ‘the most sophisticated ransomware actor’, the Scattered Spider collective (aka Octo Tempest) has used ‘advanced’ social engineering, SIM swapping, and identity theft to breach privileged accounts. 

According to the report, the ransom group has shifted between Dragon Force, RansomHub, and Qilin, showing how easy it has now become for threat actors to move seamlessly across Ransomware-as-a-Service (RaaS) platforms, but more importantly, it has used these services to escalate its intrusion into hybrid environments.

Hybrid targeting is on the rise, said Microsoft, with attackers now using tools like AADInternals to move from on-premises into cloud environments, maintaining access, deleting VMs, exfiltrating data, and encrypting resources. 

Today, over 40% of ransomware attacks involve hybrid components, up from less than 5% just two years ago, while there has been an 87% increase in campaigns aimed at disrupting Azure cloud customer environments through ransomware, mass deletion, or other destructive actions.

Identity-based attacks are the gateway to cloud breaches, with Microsoft warning that the surge in non-human identities, like apps, services, and scripts, that access cloud resources and often hold elevated privileges, is leading to a growing blind spot.

This year, over 97% of identity attacks targeted passwords, and in early 2025, such attacks jumped 32%, with most malicious sign-in attempts stemming from large-scale password guessing, fueled by leaked credentials and helped along by AI.


Recommended reading


As always, AI is lurking in the background of nearly every threat actor activity. It is well known by now that hackers are not only using genAI to automate phishing, scale social engineering and scan for zero-day vulnerabilities, but to create deepfakes, build mutating malware, and conduct research into their victims.

However, Microsoft’s report shows that AI itself is also proving vulnerable to attack. Last year saw the company work with other genAI providers to disrupt a global campaign using stolen API keys to bypass safety controls on major AI platforms like Azure OpenAI. 

The resultant tools, sold and deployed by rogue developers, generated thousands of abusive images, including celebrity deepfakes and explicit, violent, or hateful synthetic content.   

“AI’s powerful capabilities extend to producing sensitive materials and enhancing skills in ways that, if misused, pose significant security risks,” warns the report. 

“As a result, it is essential for developers of AI and policymakers to establish clear guidelines to ensure appropriate use while minimising the risk of misuse. AI should be designed with strict filters and intent detections to block requests for harmful knowledge, with suspicious queries reviewed by humans.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data