New Delhi: Ransomware continues to be the leading threat to large and medium-sized businesses worldwide, with cybercriminal groups increasingly leveraging artificial intelligence (AI) to automate their activities, according to the Acronis Cyberthreats Report H1 2025.
The biannual report from Acronis, a global cybersecurity leader, reveals that phishing accounted for 25% of all cyberattacks and 52% of attacks targeting Managed Service Providers (MSPs), marking a 22% rise compared to the first half of 2024. The use of AI has enabled attackers to conduct more sophisticated, low-effort, high-reward campaigns, including AI-powered phishing and impersonation attacks.
Based on signals from over 1,000,000 unique endpoints distributed around the world, the report also incorporates statistics focused on threats targeting Windows operating systems, given their prevalence as compared to macOS and Linux,
Data gathered from over one million Windows endpoints worldwide shows that ransomware victim numbers increased by nearly 70% compared to previous years. Prominent ransomware groups such as Cl0p, Akira and Qlin remain highly active.
The report also highlights a surge in AI-powered social engineering attacks. Between January and May 2025, social engineering and business email compromise (BEC) attacks rose from 20% to 25.6%, reflecting the growing use of AI to craft convincing impersonations. AI-generated deepfakes and automated exploits accounted for nearly a quarter of attacks on collaboration platforms.
Manufacturing was the most targeted sector, representing 15% of ransomware cases in the first quarter of 2025, followed by retail, food and drink and telecommunications.
“Even the least sophisticated attackers today have access to advanced AI capabilities,” said Gerald Beuchelt, CISO – Acronis.
“This exposes organisations to increasingly advanced attacks, including deepfakes, where just one mistake can jeopardise their future. A comprehensive cyber protection strategy is essential to defend against ransomware and evolving threats,” added Beuchelt.
The report underscores the growing importance of AI-aware cybersecurity frameworks as cybercriminals continue to exploit AI to scale and refine their attacks.
