Cybersecurity threats in 2025 have evolved, with attackers increasingly targeting small and medium-sized businesses (SMBs) due to improved defenses and ransom resistance among larger enterprises. Research highlights that four in five SMBs have suffered recent data breaches, with attackers leveraging the relative lack of resources and security maturity in these organizations. Ransomware remains a significant threat, with 83% of successful attacks compromising identity infrastructure such as Active Directory, and most incidents occurring during periods of organizational distraction, such as holidays or major corporate events. The holiday shopping season also presents heightened risks, as cybercriminals exploit increased online transactions, new account creation, and gift card exchanges to target both consumers and retailers.
Systemic risks are amplified by the widespread outsourcing of cybersecurity functions, where a single compromised vendor can cascade risk across hundreds of organizations, as seen in high-profile supply chain breaches. The looming threat of quantum computing is also prompting urgent calls for organizations to begin migrating to post-quantum cryptography, as nation-state actors are already harvesting encrypted data for future decryption. These trends underscore the need for proactive, resilient security strategies, robust identity infrastructure protection, and a forward-looking approach to cryptographic agility to address both current and emerging threats.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
Late-2025 reporting highlighted breaches affecting Tracelo, PhoneMondo, and SkilloVilla, where stolen customer data was allegedly posted or sold on the dark web. The exposed datasets reportedly ranged from 1.4 million to 33 million records and commonly included names and contact information.
Research cited in late 2025 said small and medium-sized businesses accounted for 70.5% of identified breaches, as attackers shifted toward less-defended organizations. The report warned this trend would continue into 2026 and recommended controls such as MFA, least privilege, and dark-web monitoring.
A December 2025 analysis argued that outsourcing IT and cybersecurity functions had become a source of systemic risk, citing prior supply-chain incidents such as SolarWinds, MOVEit, and Kaseya as evidence of cascading impact. It called for stronger governance, vendor stress testing, transparency, and continuous monitoring.
During the 2025 holiday shopping season, defenders warned that increased online transactions, account creation, and gift card activity would create heightened opportunities for cybercriminals. Retailers, travel providers, and digital platforms were identified as likely targets of seasonally timed attacks.
Semperis reported in 2025 that identity infrastructure such as Active Directory and Entra ID was targeted in 83% of successful ransomware attacks. The report also found many organizations lacked tested identity recovery plans and often needed more than a day to restore operations.
The U.S. government, through NIST and CISA, issued new mandates in 2025 emphasizing the urgency of preparing for post-quantum cryptography migration. The guidance reflects concern over 'harvest now, decrypt later' collection by nation-state actors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecsoonline.com
Open sourcesemperis.com
Open sourcecio.com
Open sourcesocradar.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.