Law enforcement agencies worldwide achieved significant victories against cybercriminals in 2025, including the takedown of Ukrainian call centers defrauding Europeans of €10 million, the seizure of servers from the E-Note crypto exchange laundering $70 million, and the arrest of individuals aiding state-backed hacking groups. Authorities also dismantled infrastructure supporting ransomware and account takeover operations, with notable convictions such as the prison sentence for the "evil twin" WiFi hacker and the seizure of the Cryptomixer crypto mixer, which laundered €1.3 billion since 2016. These actions reflect a growing trend of international cooperation, combining legal, operational, and financial measures to disrupt cybercrime and hold perpetrators accountable.
In addition to law enforcement successes, 2025 saw a range of high-profile cyber incidents and campaigns. Notable events included a massive cyberattack on Venezuela’s oil and gas infrastructure, suspected to be linked to U.S. operations, and targeted phishing campaigns against Russian military personnel using malicious Excel files. Iranian hackers exploited known vulnerabilities to breach Israeli institutions outside the country’s critical infrastructure sector, exposing gaps in cybersecurity mandates for hospitals, universities, and government ministries. These incidents underscore the evolving tactics of both state and non-state actors and the persistent vulnerabilities in global cyber defenses.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
China's technology sector was affected by a major breach at Kuaishou. The incident was reported during the week of December 22-26, 2025.
Iranian hackers exploited known vulnerabilities to compromise Israeli institutions outside the country's critical infrastructure. The intrusions were reported during the week of December 22-26, 2025.
A phishing campaign used fake New Year concert invitations to target Russian military personnel. The activity was reported during the week of December 22-26, 2025.
Venezuela's oil and gas infrastructure was struck by a massive cyberattack that experts suspected may have been a U.S. operation. The incident was described as a possible escalation in geopolitical cyber conflict during the week of December 22-26, 2025.
The FBI expanded its global biometrics capabilities or access, according to policy and security developments reported that week. The move was noted during the week of December 22-26, 2025.
South Korea enacted a controversial 'fake news' bill amid broader cyber and information security policy changes. The development was reported during the week of December 22-26, 2025.
Japan passed or adopted an active cyber defense law as part of cybersecurity policy developments reported that week. The measure was highlighted during the week of December 22-26, 2025.
The Pakistan Consulate in the United States issued a warning about a critical phishing scam targeting visa applicants. The warning was reported during the week of December 22-26, 2025.
South Korea's Shinsegae Group experienced a data breach affecting about 80,000 employees and subcontractors. The breach was reported during the week of December 22-26, 2025.
France's postal service suffered operational disruption from a cyberattack that was claimed by the pro-Russian hacktivist group Noname057(16). The incident was reported during the week of December 22-26, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.