Skip to main content
Mallory
Mallory

Major Data Breaches and Attack Trends in 2025

automated intrusionthreat intelligencecredential theftbreachcredential compromisehealth dataidentity protectionsecurity measurescloud misconfigurationphishingincident responsecredential resetfinancial impact
Updated December 25, 2025 at 06:01 PM2 sources

Get Ahead of Threats Like This

Know if you're exposed — before adversaries strike.

The year 2025 saw a significant escalation in the scale and sophistication of data breaches worldwide, with attackers leveraging advanced tools such as AI-driven phishing, deepfakes, and automated intrusions. High-profile incidents included the compromise of billions of credentials from tech giants, targeted attacks on airlines and telecoms, and the exposure of sensitive customer data from major insurance companies like Aflac. Attack vectors evolved, with phishing, social engineering, supply-chain breaches, and cloud misconfigurations becoming increasingly prevalent. The financial impact of these breaches was substantial, with average costs per incident rising and global cybercrime losses projected to exceed $10 trillion. Notably, the Aflac breach in June 2025 exposed personal and health data of over 22 million individuals, attributed to the Scattered Spider group, prompting the company to enhance security measures and offer extended identity protection services to affected parties.

Industry analysis highlighted the dual use of AI by both attackers and defenders, the growing threat of supply-chain and cloud-based attacks, and the persistent challenge of credential theft. The insurance sector, in particular, faced coordinated campaigns, with similar breaches reported at other firms. Organizations responded by resetting credentials, increasing monitoring, and providing support to victims, while regulatory scrutiny and legal actions intensified. The events of 2025 underscored the urgent need for robust security practices, rapid incident response, and proactive threat intelligence to mitigate the evolving risks posed by increasingly resourceful adversaries.

Related Entities

Threat Actors

Sources

December 25, 2025 at 12:00 AM

Related Stories

Major Cybersecurity Trends and Incidents in 2025

Major Cybersecurity Trends and Incidents in 2025

The cybersecurity landscape in 2025 was marked by a series of high-impact incidents and evolving threat trends, with identity-driven intrusions, large-scale breaches, and record-breaking DDoS attacks dominating the year. Notable breaches at organizations such as Ingram Micro, Conduent, and Kettering Health resulted in hundreds of millions of dollars in losses, with regulatory filings and industry analyses highlighting the significant operational and financial impacts. Attackers increasingly exploited known vulnerabilities, with the CISA Known Exploited Vulnerabilities (KEV) catalog serving as a critical indicator of attacker intent, and legacy flaws resurfacing as major risk factors. The year also saw a strategic shift in security operations, with organizations prioritizing risk-based decision-making over exhaustive control coverage, and automation and real-time intelligence becoming essential for defense. DDoS attacks reached unprecedented scales, with Cloudflare reporting attacks peaking at 31 Tbps and the emergence of massive botnets like Aisuru. These attacks were often used as smokescreens for deeper intrusions, and the growing sophistication and speed of DDoS campaigns rendered traditional scrubbing-center defenses increasingly obsolete. Geopolitical tensions further shaped the threat landscape, with critical infrastructure and sectors such as gaming and gambling frequently targeted. The industry’s response emphasized the need for adaptive, globally distributed mitigation strategies and highlighted the importance of governance, consent management, and just-in-time administration to separate resilient organizations from those more vulnerable to systemic risk.

2 months ago
Major Cybersecurity Incidents and Threat Trends of 2025

Major Cybersecurity Incidents and Threat Trends of 2025

The cybersecurity landscape in 2025 was marked by a series of high-profile breaches, advanced persistent threat (APT) campaigns, and evolving tactics by both cybercriminals and state-linked actors. Notable incidents included the PornHub data breach, where the ShinyHunters group exfiltrated and extorted sensitive user activity data, and the Knownsec leak, which exposed the espionage tools and global targeting strategies of a major Chinese cybersecurity firm. Supply-chain attacks continued to proliferate, with attackers compromising widely used software libraries and cloud services, impacting thousands of organizations and individuals. The year also saw a surge in sophisticated social engineering campaigns, such as ClickFix attacks, and a significant number of APT operations targeting government and military institutions, particularly in South and East Asia. Cloud service outages, such as the prolonged AWS disruption, highlighted the dependency of IoT and critical infrastructure on cloud reliability, causing widespread operational impacts. The threat actor ecosystem became more industrialized, leveraging AI, ransomware-as-a-service, and multi-stage attacks to increase scale and efficiency. Cryptocurrency platforms suffered major heists, and new vulnerabilities like MongoBleed were rapidly exploited in the wild. The cumulative effect of these incidents underscored the need for robust supply-chain security, improved cloud resilience, and enhanced detection and response capabilities against both opportunistic and targeted attacks.

2 months ago

Trends and Challenges in Cybersecurity for 2025-2026

Cybersecurity experts and industry reports highlight evolving threats and persistent challenges as organizations prepare for 2026. Attackers are increasingly exploiting misconfigurations, leveraging AI-driven social engineering, and taking advantage of complex, rapidly changing cloud environments. Despite technological advancements, human error and configuration drift remain leading causes of breaches, with automation and policy enforcement recommended as key mitigations. The financial services sector, while showing improved prevention effectiveness due to regulatory pressure and investment, still faces critical weaknesses at specific attack stages, underscoring the need for continuous validation and adaptive controls. Industry commentary and newsletters reflect on the rapid pace of change, with significant M&A activity, the growing impact of AI on cybersecurity strategies, and ongoing struggles with vulnerability management and software supply chain security. The sector is urged to address these systemic issues by adopting risk-based approaches, improving transparency, and integrating new frameworks such as the OWASP Agentic AI Top 10. As organizations look ahead, the consensus is that while progress is being made, the threat landscape is becoming more sophisticated, requiring ongoing vigilance and innovation.

2 months ago

Get Ahead of Threats Like This

Mallory continuously monitors global threat intelligence and correlates it with your attack surface. Know if you're exposed — before adversaries strike.