A new report from Barracuda shows that a full 90 percent of all ransomware incidents in 2025 exploited firewalls, either through outdated software or through unprotected user accounts. The fastest attack trajectory recorded went from breach to full encryption in just three hours. The findings come from the Barracuda Managed XDR Global Threat Report, which highlights how cybercriminals operate and what vulnerabilities make organizations particularly vulnerable.
Based on thousands of real-world incidents, the report shows how attackers are using legitimate IT tools like remote access programs to exploit unprotected devices. It also highlights the risks of outdated encryption, disabled security features on clients, and anomalous behaviors associated with logins or access with elevated privileges.

“Organizations and their security teams, especially those with a single IT manager, face enormous challenges. With limited resources and fragmented security solutions, they must protect identities, assets and data against rapidly evolving new threats, where attacks can be carried out in a matter of hours,” says Merium Khalid, Director, SOC Offensive Security at Barracuda.
Key facts in the report
- 90 percent of ransomware incidents exploited firewalls via known vulnerabilities (CVEs) or weak accounts. Attackers can thus gain control of the network and hide their activity behind the protection of the firewall.
- The fastest attack used Akira ransomware and took three hours from intrusion to encryption, which gives defenders very limited room for maneuver.
- Every tenth discovered vulnerability had a known exploit. Cybercriminals continue to exploit vulnerabilities in software, often at the vendor level, underscoring the importance of updating systems in a timely manner.
- The most frequently discovered vulnerability was from 2013. CVE‑2013‑2566 affects an outdated encryption algorithm that is still present in older servers, embedded systems, and applications.
- 96 percent of incidents where the attacker moved laterally in the network ended in ransomware. Lateral movement is a clear indicator that an attack is developing.
- 66 percent of all incidents were related to the supply chain or third-party vendors – a clear increase from 45 percent the previous year.
– What makes a business vulnerable is often something that is easy to overlook, an unauthorized device that lacks protection, an account that has not been shut down when someone quits, an outdated application or a misconfigured security feature. Attackers only need to find a single weak point. An integrated, AI-driven and more autonomous security solution where experts take care of the operation often becomes a decisive difference, concludes Merium Khalid.
Briefly about the study
The results are based on the extensive data collected via Barracuda Managed XDR in 2025 with more than two trillion IT events, nearly 600,000 security alerts, and over 300,000 protected clients, firewalls, servers, and cloud resources.
Read the report here »








