Looking for a Shorter Overview?
AI Summary
Key Moments
AI accelerates cyberattacks
Attackers are using AI to automate and streamline the entire attack chain in phishing and ransomware.Email attacks are increasing sharply
Email-based attacks have increased by 16% per organization, with phishing being the most common entry point.Ransomware dominates the threat landscape
Ransomware continues to be the biggest cyber threat with thousands of victims globally and new players in the market.High-risk targets are MSPs and supply chains
MSPs and supply chains are particularly vulnerable, with attacks exploiting RMM tools like AnyDesk and TeamViewer.AI Phishing ransomware is the fastest growing threat in cybersecurity according to Acronis Cyberthreats Report H2 2025. The report is based on global telemetry data from Acronis Threat Research Unit TRU and the company's global sensor network and clearly shows how cyber threats have escalated significantly in 2025, with a particular focus on the second half of the year.
The analysis points to a clear shift where attackers are no longer simply refining established methods such as phishing and ransomware but increasingly use AI as an operational tool throughout the attack chain. The result is faster, more scalable, and more sophisticated attacks that challenge traditional defense strategies.
Sharp increase in email-based attacks and new attack methods
According to the report, email-based attacks increased by 16 percent per organization and 20 percent per user compared to the previous year. Phishing remains the most common entry point, accounting for 52 percent of all attacks against managed service providers (MSPs).
At the same time, advanced attacks against collaboration platforms have increased dramatically from 12 percent in 2024 to 31 percent in 2025. The development shows a clear shift towards secondary attack vectors with high impact, where attackers leverage established business tools for lateral spread and hacking.
The report's key findings
• PowerShell is the most abused legitimate tool globally with a particularly high prevalence in Germany USA and Brazil
• Phishing accounted for 83 percent of all email threats in H2 2025
• All identified vulnerabilities in MSP platforms in 2025 were classified as high risk or critical
• AI is used operationally in reconnaissance, ransomware negotiations, and social engineering
• India, the US and the Netherlands had the highest frequency of mass infections and lateral spread
• South Korea was the most malware-affected country with 12 percent of users affected
• Manufacturing technology and healthcare were the most vulnerable sectors
AI is changing the rules of the cybercrime game
In 2025, there was a dramatic increase in AI-assisted cybercrime. Attackers are using AI to automate reconnaissance, scale attacks, and optimize extortion strategies. A clear example is how GLOBAL GROUP used AI-powered systems to handle ransomware negotiations against multiple victims in parallel, while GTG 2002 applied AI-assisted reconnaissance and data exfiltration to maximize impact.
Social engineering attacks have also developed rapidly. Virtual kidnapping scams use AI to generate convincing life-sign images, greatly increasing the psychological pressure on victims and making the scams harder to detect.
“As cyber threats accelerate, 2025 has shown that attackers are not only scaling up traditional methods like phishing and ransomware, but are also using AI to act faster, more effectively and at scale,” said Gerald Beuchelt. “Organizations must therefore anticipate threats, automate their defenses and build resilient systems that can withstand both traditional and AI-driven attacks.”

Ransomware continues to dominate the threat landscape
Ransomware continued to dominate the threat landscape in H2 2025. Nearly 150 MSPs and telecom organizations were directly attacked and over 7,600 victims were publicly disclosed globally. The most active ransomware groups were Qilin with 962 victims, Akira with 726, and Cl0p with 517.
The United States recorded the most victims with 3,243 reported cases. During the period, new ransomware groups including Sinobi TheGentlemen and CoinbaseCartel also emerged, further increasing the pressure on organizations globally.
Supply chains and MSPs remain high-risk targets
Attacks on supply chains and MSP environments continue to pose a serious threat. Attackers exploit RMM tools like AnyDesk and TeamViewer and has affected over 1,200 third-party companies worldwide. The US was the most exposed with 574 affected organizations.
Akira and Cl0p were also dominant players here, which underlines the structural risk for MSPs and their customers in an increasingly interconnected IT landscape.
Read more and download the report
Read more about the report on the Acronis blog
Download the full Acronis Cyberthreats Report H2 2025
