The global technology supply chain suffered a surge in cyber-attacks last year compared to 2023, according to the latest annual report from Check Point.
The cybersecurity firm’s State of Global Cyber Security 2025 report revealed a 179% surge in weekly cyber-attacks on the hardware and semiconductor industries alone, with Check Point linking the rise to the increasing demand for AI making tech supply chains prime targets for cyber-criminals.
An analysis of cybersecurity data from across 180 countries shows that overall cyber-attacks against almost every sector grew over the last year, with the average number of weekly attacks per organisation reaching 1,673 – 44% higher than 2023.
The software industry was among the worst affected, with a 109% rise in weekly attacks, however the education sector remained the most targeted industry, experiencing 3,574 weekly attacks, a 75% year-on-year increase.
Check Point’s analysis also highlights a change in attack vectors over the past few years, with the use of email as a delivery system falling to 68% (vs 84% in 2021), and a rise in instances of web-based protocols, going from 16% in 2021 to 32% last year.
According to the study, the increase in web-based tactics can be primarily attributed to the dominance of infected-website-based malware distribution frameworks such as ‘FakeUpdates’, a newer tactic of cyber-criminals following the dismantling of botnets over the course of last year.
FakeUpdates attacks rely on a network of compromised websites distributing malware disguised as fake browser or software update prompts, accounting for 40% of the most prevalent multipurpose malware globally last year.
The research also drew data and insights from more than 140 ransomware data leak sites, operated by 90 ransomware groups. Check Point found that the details of more 5,200 companies have been published on data leak sites by cyber-criminals, with 50% of the companies affected in the US, followed by the UK at 6%, Canada at 5%, and Germany and Italy at 3% each.
Although the education, government and health sectors saw the highest number of weekly cyber-attacks, manufacturing was the most impacted by ransomware specific instances, with a 22% share of ransomware victim organisations compared to healthcare, the next most targeted sector, with just 10%.
For those working in security, it might be comforting to know that 2024 also marked the first time security alerts became the leading trigger for incidents (35%), followed by service disruption (26%), proactive security activities (13%), and user reports (8%).
Check Point said that by focusing on early detection through such security alerts and proactive measures, organisations can respond more effectively to threats and reduce the impact of cyber-incidents.
Recommended reading
- 75% of Organisations Hit by Ransomware More Than Once
- Ransomware Crisis Escalating Globally, New Report Shows
- Over Half of Hacked UK Firms Pay Ransom
Among the company’s other recommendations for the coming year is the prioritisation of advanced cloud security solutions, particularly in regard to API security, identity management, and a zero-trust architecture to address cloud vulnerabilities.
Firms should also look to leverage more AI for prevention and detection measures, adopt a multi-layered approach within security stacks, and develop customer-trust programmes to ensure compliance.
“As we reflect on the incidents of 2024, it’s essential to focus on the key elements that led to attackers’ success and the strategic mitigations defenders can employ to thwart such threats,” said Jonathan Fischbein, Check Point Software global CISO.
“These guidelines serve as a practical framework to enhance defenses and prevent severe incidents outlined in this report by addressing common systemic issues and mistakes that have historically contributed to cyber-attacks.”





