A research paper from the Blekinge Institute of Technology in Sweden documented a 238% increase in attacks targeting virtual private networks (VPNs) between 2020 and 2022, coinciding with the rapid expansion of remote work during the COVID-19 pandemic. The study, which analyzed 81 reports from sources such as Google and BrightTALK, found that organizations rushed to deploy VPNs to support a growing remote workforce, often without adequate security controls or preparation. This led to widespread vulnerabilities, including exposed gateways, misconfigurations, and unpatched systems, which threat actors exploited to gain unauthorized access and move laterally within corporate networks.
Researchers concluded that many new VPN users lacked essential endpoint controls and network segmentation, making it easier for attackers to compromise entire environments. Security experts noted that while VPNs are not inherently difficult to secure, the unprecedented pace of adoption and lack of experience among organizations significantly increased the attack surface. The findings highlight the critical need for robust VPN security practices, especially in environments with rapidly changing remote access requirements.

Map this exposure pattern across your cloud, code, and identities.
4 events from the most recent confirmed update back to the earliest known activity.
Recent incidents involving SonicWall SSL VPN and Ivanti Connect Secure showed that VPNs remained a significant security risk even after the post-pandemic decline in attack volume. These cases were cited as evidence that VPN-related exposure continues to be exploited.
In 2025, researchers from the Blekinge Institute of Technology published findings highlighting how insecure VPN deployments created lasting attack surface risk. The study recommended hardening measures including strong authentication, robust encryption, secure configuration, and continuous monitoring.
A 2025 study by the Blekinge Institute of Technology found that attacks targeting VPNs increased by 238% from 2020 to 2022. The rise was linked to exposed gateways, misconfigurations, unpatched vulnerabilities, and weak network segmentation in many environments.
During the COVID-19 pandemic, organizations rapidly deployed VPNs to support large-scale remote work. Many deployments, especially in small and mid-sized businesses, were implemented without sufficient expertise or ongoing security management.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.