Cyberthreat News 2025
Several of 2025’s most damaging incidents started with compromised vendors or shared platforms. Attacks on UNFI, U.S. Treasury, Ticketmaster and Snowflake customers, and the UK Ministry of Defense show how leveraging third-party vulnerabilities can lead to data breaches. Attacks involving stolen credentials and phishing also demonstrate how easy it is for attackers to gain access without triggering alarms or raising suspicions.
Health and aviation security also were disrupted this year. A ransomware attack impacted Heathrow and other European airports, forcing flight diversions and manual operations. The incident highlighted the importance of strengthening security practices for supply chains and air travel.
Cyber attacks aimed at individuals, small and midsize businesses and SLTTs, as well as public-sector systems, gained in intensity and frequency. Many incidents shook customer trust and brand reputation.
The year’s most damaging cyber incidents were caused by sophisticated nation-states and criminal groups, who exploited flaws to steal information and money, as well as develop capabilities to disrupt, destroy or threaten the delivery of essential services. Attacks on government agencies, large businesses, financial institutions and a range of public-sector agencies demonstrated how serious the threat is to national security and economic stability.