France’s ANSSI/CERT-FR published its Panorama de la cybermenace 2025, reporting continued blurring between state-linked and cybercriminal activity, including broader misuse of legitimate tools/services and evolving social engineering beyond traditional fake IT support. The report notes ongoing opportunistic and targeted exploitation of vulnerabilities, with internet-exposed edge devices and perimeter solutions often exploited rapidly, and highlights sustained state interest—particularly actors assessed as linked to Russian and Chinese intelligence services—in compromising diplomatic networks for strategic intelligence collection.
Separately, analysis cited from Orange Cyberdefense’s Security Navigator 2026 indicates that individuals identified in publicly disclosed cybercrime law-enforcement actions are frequently mid-career adults, challenging the stereotype of predominantly very young offenders. Based on 418 publicly announced actions (2021 to mid-2025) and age data for 193 offenders, the 35–44 cohort represented 37% of identified offenders, followed by 25–34 (30%) and 18–24 (21%); the authors caution the dataset reflects disclosure and jurisdictional reporting biases rather than the full universe of cybercrime activity.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
France's Gendarmerie nationale and UNC warned that organized crime is becoming deeply cyber-enabled, with attacks increasingly focused on aggregating stolen data to support large-scale social engineering and coercive operations. Officials also said they were expanding cyber capabilities, including embedding expertise in elite units and deploying 1,000 high-end cyber investigators to counter the trend.
Recorded Future's Insikt Group published an assessment of cybercrime in Latin America and the Caribbean during 2025, finding financially motivated activity dominant and documenting 452 ransomware incidents across the region. The report identified Brazil, Mexico, and Argentina as the most targeted countries, highlighted healthcare, finance, and government as frequent targets, and described growing abuse of mobile malware and infostealers.
InterCert France published an incident-response report based on 366 cyber incidents reported by roughly half of its 130-plus member organizations. The report said attacks were detected after an average of 15 days, lasted 17 days on average, and were dominated by opportunistic activity, with about one-third involving data exfiltration and a similar share involving ransomware.
CERT-FR published its 2025 threat and incident report, summarizing trends including blurred state-crime boundaries, evolving social-engineering techniques, growing but non-transformative attacker interest in AI tools, and fast exploitation of exposed systems. The report framed these developments in the context of heightened geopolitical tensions and ongoing compromises of diplomatic networks for intelligence collection.
On publication of Security Navigator 2026, Orange Cyberdefense said identified cyber extortion and malware offenders frequently fell into the 35–44 age bracket, with younger cohorts more associated with broad hacking and skill-building. The report also noted that the dataset covered offenders of 64 nationalities, while cautioning that public disclosures introduce reporting bias.
In its 2026 threat and incident report, CERT-FR said that during 2025 it observed reduced use of ransomware and a marked increase in operations focused solely on data exfiltration. The report also highlighted rapid exploitation of internet-exposed and edge-device vulnerabilities and continued espionage activity linked to Russian- or Chinese-attributed tradecraft.
CERT-FR reported that in 2025 ANSSI benefited from data leaks affecting malicious actors, which improved understanding of how those actors operate. The agency also observed that attribution was becoming more complex as boundaries between state and criminal actors continued to blur.
Orange Cyberdefense's Security Navigator 2026 report reviewed publicly announced cybercrime law-enforcement actions spanning 2021 through mid-2025. The analysis found that identified cyber offenders were often older than common stereotypes suggest, with the 35–44 age group the largest cohort in cases where age data was available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
cert.ssi.gouv.fr
Open sourcezdnet.fr
Open sourcezdnet.fr
Open sourcerecordedfuture.com
Open sourcerecordedfuture.com
Open sourcecert.ssi.gouv.fr
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.