• About
  • Subscribe
  • Contact
Thursday, August 14, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home Technology Data Protection

Social engineering takes centre stage in ransomware surge

FutureCISO Editors by FutureCISO Editors
August 14, 2025
IDC projects double-digit growth for security products

Photo by Sora Shimazaki: https://www.pexels.com/photo/crop-cyber-spy-hacking-system-while-typing-on-laptop-5935794/

Share on FacebookShare on Twitter

The cybersecurity landscape is facing a dramatic shift as highlighted in Coveware by Veeam's Q2 2025 ransomware report. The report reveals a notable increase in targeted social engineering attacks, with sophisticated data exfiltration techniques driving record ransom payments.

Bill Siegel, CEO of Coveware, remarked that this quarter marks a turning point in the ransomware narrative, indicating a need for organisations to enhance their security measures.

Key findings from the report illustrate the evolving tactics of ransomware groups. Major players such as Scattered Spider, Silent Ransom, and Shiny Hunters have moved away from opportunistic attacks, opting instead for highly targeted strategies.

This shift involves novel impersonation tactics aimed at help desks, employees, and third-party service providers, significantly increasing the efficacy of their attacks.

The financial implications are stark, with the average ransom payment rising to $1.13 million, a staggering 104% increase from Q1 2025. The median payment also surged to $400,000, reflecting a growing trend where larger organisations are willing to pay hefty ransoms to recover stolen data.

Remarkably, data exfiltration is now the primary extortion method, involved in 74% of all cases, signalling a shift away from traditional system encryption.

Industry-specific vulnerabilities have also come to light, with professional services (19.7%), healthcare (13.7%), and consumer services (13.7%) facing the highest attack rates.

Mid-sized companies, particularly those with 11 to 1,000 employees, accounted for 64% of victims, suggesting that attackers are targeting organisations with less mature security defences.

Moreover, the report indicates that human factors remain a significant vulnerability. Attack techniques such as credential compromise and phishing continue to dominate initial access points. Many attackers have adeptly bypassed technical controls through social engineering, exploiting well-known vulnerabilities in platforms like Ivanti and Fortinet.

Related:  Sophos finds ‘junk gun’ ransomware infiltrates the dark web

The report also reveals that new ransomware variants are reshaping the threat landscape, with Akira, Qilin, and Lone Wolf making notable entries into the top rankings. As these trends unfold, organisations must prioritise employee awareness and bolster identity controls to mitigate risks effectively.

With social engineering and data exfiltration becoming dominant tactics, enhancing data resilience and employee training is more critical than ever.

Tags: Covewareransomwaresocial engineeringVeeam
FutureCISO Editors

FutureCISO Editors

No Result
View All Result

Recent Posts

  • Social engineering takes centre stage in ransomware surge
  • AI security: Asia's new CISO battleground
  • Complex ransomware attacks rising amid fragmented security in Asia
  • Cybersecurity risks rise with data sovereignty demands
  • Cybersecurity risks skyrocket amid ransomware evolution

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl