AI Phishing ransomware is the fastest growing threat in cybersecurity according to Acronis Cyberthreats Report H2 2025. The report is based on global telemetry data from Acronis Threat Research Unit TRU and the company's global sensor network and clearly shows how cyber threats have escalated significantly in 2025, with a particular focus on the second half of the year.
The analysis points to a clear shift where attackers are no longer simply refining established methods such as phishing and ransomware but increasingly use AI as an operational tool throughout the attack chain. The result is faster, more scalable, and more sophisticated attacks that challenge traditional defense strategies.
Sharp increase in email-based attacks and new attack methods
According to the report, email-based attacks increased by 16 percent per organization and 20 percent per user compared to the previous year. Phishing remains the most common entry point, accounting for 52 percent of all attacks against managed service providers (MSPs).
At the same time, advanced attacks against collaboration platforms have increased dramatically from 12 percent in 2024 to 31 percent in 2025. The development shows a clear shift towards secondary attack vectors with high impact, where attackers leverage established business tools for lateral spread and hacking.
The report's key findings
• PowerShell is the most abused legitimate tool globally with a particularly high prevalence in Germany USA and Brazil
• Phishing accounted for 83 percent of all email threats in H2 2025
• All identified vulnerabilities in MSP platforms in 2025 were classified as high risk or critical
• AI is used operationally in reconnaissance, ransomware negotiations, and social engineering
• India, the US and the Netherlands had the highest frequency of mass infections and lateral spread
• South Korea was the most malware-affected country with 12 percent of users affected
• Manufacturing technology and healthcare were the most vulnerable sectors
AI is changing the rules of the cybercrime game
In 2025, there was a dramatic increase in AI-assisted cybercrime. Attackers are using AI to automate reconnaissance, scale attacks, and optimize extortion strategies. A clear example is how GLOBAL GROUP used AI-powered systems to handle ransomware negotiations against multiple victims in parallel, while GTG 2002 applied AI-assisted reconnaissance and data exfiltration to maximize impact.
Social engineering attacks have also developed rapidly. Virtual kidnapping scams use AI to generate convincing life-sign images, greatly increasing the psychological pressure on victims and making the scams harder to detect.
“As cyber threats accelerate, 2025 has shown that attackers are not only scaling up traditional methods like phishing and ransomware, but are also using AI to act faster, more effectively and at scale,” said Gerald Beuchelt. “Organizations must therefore anticipate threats, automate their defenses and build resilient systems that can withstand both traditional and AI-driven attacks.”

Ransomware continues to dominate the threat landscape
Ransomware continued to dominate the threat landscape in H2 2025. Nearly 150 MSPs and telecom organizations were directly attacked and over 7,600 victims were publicly disclosed globally. The most active ransomware groups were Qilin with 962 victims, Akira with 726, and Cl0p with 517.
The United States recorded the most victims with 3,243 reported cases. During the period, new ransomware groups including Sinobi TheGentlemen and CoinbaseCartel also emerged, further increasing the pressure on organizations globally.
Supply chains and MSPs remain high-risk targets
Attacks on supply chains and MSP environments continue to pose a serious threat. Attackers exploit RMM tools like AnyDesk and TeamViewer and has affected over 1,200 third-party companies worldwide. The US was the most exposed with 574 affected organizations.
Akira and Cl0p were also dominant players here, which underlines the structural risk for MSPs and their customers in an increasingly interconnected IT landscape.








