Organizations using on-premises VPN devices, particularly from vendors such as Citrix, Cisco, SonicWall, Palo Alto, and Fortinet, face a significantly higher risk of ransomware attacks compared to those using cloud-based VPNs or no VPNs at all. According to At-Bay’s 2025 InsurSec Report, 83% of ransomware incidents involved VPNs, and 80% began with a remote access compromise, with a notable 300% increase in Akira ransomware attacks targeting SonicWall devices in Q3 2025, often exploiting vulnerabilities like CVE-2024-40766. The complexity and maintenance requirements of on-premises VPNs, combined with outdated configurations and missed patches, contribute to this elevated risk, prompting security leaders to recommend transitioning to modern cloud-based remote access solutions.
Cyber insurance data further highlights that 90% of claims stem from email and VPN-related incidents, with larger organizations being disproportionately targeted. Email remains the top entry vector, accounting for 43% of all incidents in 2024, and the frequency of such claims continues to rise. Attackers are leveraging both traditional and advanced techniques, including generative AI, to bypass defenses, resulting in substantial financial losses. The convergence of these trends underscores the urgent need for organizations to reassess their remote access infrastructure and email security posture to mitigate the risk of ransomware and other cyber threats.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
The same report said Citrix and Cisco VPN products were most strongly associated with ransomware victimization, followed by SonicWall, Palo Alto Global Protect, and Fortinet. The analysis was published as part of broader reporting on cyber claims tied to email and remote access exposures.
A report found that 80% of ransomware incidents began with a remote access compromise and that 83% involved VPNs, highlighting remote access infrastructure as a major initial access vector. The findings also associated on-premises VPN devices and routers with significantly higher ransomware risk than cloud-based VPNs or no VPN use.
The report noted a 300% increase in Akira ransomware attacks targeting SonicWall devices during Q3 2025. The activity was linked to exploitation of CVE-2024-40766.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.