GlobeNewswire by notified

Acronis H2 2025 Cyberthreats Report: Cyberattacks Surge as Phishing, Ransomware, and AI-Driven Threats Escalate

18.2.2026 14:00:00 CET | GlobeNewswire by notified | Press release

Share

Global organizations face AI-enhanced cybercrime, record ransomware incidents, and an uptick in phishing attacks, highlighting the need for strong cyber defenses

SCHAFFHAUSEN, Switzerland, Feb. 18, 2026 (GLOBE NEWSWIRE) -- Acronis, a global leader in cybersecurity and data protection, released its biannual report, “Acronis Cyberthreats Report H2 2025: From exploits to malicious AI”, analyzing global threat activity based on telemetry collected by the Acronis Threat Research Unit (TRU) and Acronis sensors. The report highlights key trends observed throughout 2025, with a focus on the second half of the year.

The findings reveal a continued surge in cyberattacks. Email-based attacks increased 16% per organization and 20% per user year-over-year, while phishing remained the leading entry point, responsible for 52% of attacks targeting managed service providers (MSPs). Advanced attacks on collaboration platforms jumped from 12% in 2024 to 31% in 2025, signaling a shift toward high-impact secondary attack channels.

Key cybersecurity trends in 2025 include:

  • PowerShell abuse dominates: The most abused legitimate tool globally, particularly in Germany, the U.S., and Brazil.
  • Phishing remains rampant: In H2 2025, phishing accounted for 83% of all email threats.
  • High-risk MSP vulnerabilities: All MSP-platform CVEs disclosed in 2025 were rated High or Critical, despite overall low numbers.
  • AI goes operational: Cybercriminals increasingly integrated AI into day-to-day attack workflows, including reconnaissance, ransomware negotiation, and social engineering.
  • Geographic hotspots: India, the U.S., and the Netherlands saw the highest mass infection and lateral movement rates, while South Korea was the most malware-affected country, with 12% of users impacted.
  • Sector pressure points: Manufacturing, technology, and healthcare were the top ransomware targets due to uptime pressure and complex, distributed environments.

2025 also saw a dramatic rise in AI-assisted cybercrime. Threat actors leveraged AI to scale attacks, automate reconnaissance, and optimize extortion strategies. For example, GLOBAL GROUP used AI-driven systems to manage ransomware negotiations efficiently across multiple victims, while GTG-2002 employed AI-assisted reconnaissance and data exfiltration to maximize impact. Even social-engineering attacks evolved: virtual kidnapping scams used AI to generate convincing “proof of life” images, deceiving victims and amplifying psychological pressure. These innovations highlight a new era of cybercrime, where speed, sophistication, and scale challenge traditional defenses.

“As cyber threats evolve at an accelerated pace, 2025 has shown that attackers are not only scaling traditional methods like phishing and ransomware, but are leveraging AI to act faster, more efficiently, and at greater scale,” said Gerald Beuchelt, CISO at Acronis. “Attackers are increasingly integrating AI into their operations, so the cybersecurity landscape is entering a new era. This shift requires organizations to anticipate threats, automate defenses, and build resilient systems capable of withstanding both traditional and AI-driven attacks.”

Ransomware continued to dominate the threat landscape. Nearly 150 MSP and telecom organizations were directly targeted, while over 7,600 victims were publicly disclosed globally. The most active ransomware groups included Qilin (962 victims), Akira (726), and Cl0p (517). Manufacturing, technology, and healthcare sectors were disproportionately affected, with the United States recording the highest number of victims at 3,243. New ransomware groups also emerged in H2 2025, including Sinobi, TheGentlemen, and CoinbaseCartel.

Supply chain and MSP-targeted attacks remain a significant concern. Attackers exploited RMM tools such as AnyDesk and TeamViewer, impacting over 1,200 third-party and supply chain victims, with the U.S. seeing the greatest exposure at 574 victims. Akira and Cl0p were the dominant actors in these attacks, underscoring the persistent risk to MSPs and their clients.

To learn more about the report and its findings, visit the Acronis blog here: https://www.acronis.com/en/blog/posts/acronis-cyberthreats-report-h2-2025-cybercriminals-are-now-scaling-attacks-with-ai

For more information, download a copy of the full Acronis H2 2025 Cyberthreats Report here: https://www.acronis.com/en/resource-center/resource/acronis-cyberthreats-report-h2-2025

About Acronis:
Acronis is a global cyber protection company that provides natively integrated cybersecurity, data protection, and endpoint management for managed service providers (MSPs), small and medium businesses (SMBs), and enterprise IT departments. Acronis solutions are highly efficient and designed to identify, prevent, detect, respond, remediate, and recover from modern cyberthreats with minimal downtime, ensuring data integrity and business continuity. Acronis offers the most comprehensive security solution on the market for MSPs with its unique ability to meet the needs of diverse and distributed IT environments.

A Swiss company founded in Singapore in 2003, Acronis has 15 offices worldwide and employees in 50+ countries. Acronis Cyber Protect is available in 26 languages in 150 countries and is used by over 21,000 service providers to protect over 750,000 businesses. Learn more at www.acronis.com.

Acronis Press Contact:
Julia Carfagno
Senior Global Communications Manager
Julia.Carfagno@acronis.com

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/d810206d-1a25-4f15-a968-cfd51b812f09

Subscribe to releases from GlobeNewswire by notified

Subscribe to all the latest releases from GlobeNewswire by notified by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from GlobeNewswire by notified

Iveco Group signs a 150 million euro term loan facility with Cassa Depositi e Prestiti to support investments in research, development and innovation11.6.2024 12:00:00 CEST | Press release

Turin, 11th June 2024. Iveco Group N.V. (EXM: IVG), a global automotive leader active in the Commercial & Specialty Vehicles, Powertrain and related Financial Services arenas, has successfully signed a term loan facility of 150 million euros with Cassa Depositi e Prestiti (CDP), for the creation of new projects in Italy dedicated to research, development and innovation. In detail, through the resources made available by CDP, Iveco Group will develop innovative technologies and architectures in the field of electric propulsion and further develop solutions for autonomous driving, digitalisation and vehicle connectivity aimed at increasing efficiency, safety, driving comfort and productivity. The financed investments, which will have a 5-year amortising profile, will be made by Iveco Group in Italy by the end of 2025. Iveco Group N.V. (EXM: IVG) is the home of unique people and brands that power your business and mission to advance a more sustainable society. The eight brands are each a

DSV, 1115 - SHARE BUYBACK IN DSV A/S11.6.2024 11:22:17 CEST | Press release

Company Announcement No. 1115 On 24 April 2024, we initiated a share buyback programme, as described in Company Announcement No. 1104. According to the programme, the company will in the period from 24 April 2024 until 23 July 2024 purchase own shares up to a maximum value of DKK 1,000 million, and no more than 1,700,000 shares, corresponding to 0.79% of the share capital at commencement of the programme. The programme has been implemented in accordance with Regulation No. 596/2014 of the European Parliament and Council of 16 April 2014 (“MAR”) (save for the rules on share buyback programmes set out in MAR article 5) and the Commission Delegated Regulation (EU) 2016/1052, also referred to as the Safe Harbour rules. Trading dayNumber of shares bought backAverage transaction priceAmount DKKAccumulated trading for days 1-25478,1001,023.01489,100,86026:3 June 20247,0001,050.597,354,13027:4 June 20245,0001,055.705,278,50028:6 June20243,0001,096.273,288,81029:7 June 20244,0001,106.174,424,68

Landsbankinn hf.: Offering of covered bonds11.6.2024 11:16:36 CEST | Press release

Landsbankinn will offer covered bonds for sale via auction held on Thursday 13 June at 15:00. An inflation-linked series, LBANK CBI 30, will be offered for sale. In connection with the auction, a covered bond exchange offering will take place, where holders of the inflation-linked series LBANK CBI 24 can sell the covered bonds in the series against covered bonds bought in the above-mentioned auction. The clean price of the bonds is predefined at 99,594. Expected settlement date is 20 June 2024. Covered bonds issued by Landsbankinn are rated A+ with stable outlook by S&P Global Ratings. Landsbankinn Capital Markets will manage the auction. For further information, please call +354 410 7330 or email verdbrefamidlun@landsbankinn.is.

Relay42 unlocks customer intelligence with a new insights and reporting module, powered by Amazon QuickSight11.6.2024 11:00:00 CEST | Press release

AMSTERDAM, June 11, 2024 (GLOBE NEWSWIRE) -- Relay42, a leading European Customer Data Platform (CDP), is leveraging Amazon QuickSight to power its new real-time customer intelligence, reporting, and dashboard module. Harnessing the breadth and quality of customer data, the new Insights module empowers marketing teams to dive deep into customer behaviors and gain invaluable insights into the performance of their marketing programs across all online, offline, paid, and owned marketing channels. Preview of the Relay42 Insights module, in pre-beta version Key capabilities of the Relay42 Insights module include: Deep insights into customer behaviors: With the Relay42 Insights module, marketers can ask unlimited questions about their data and gain a deeper understanding of how to serve their customers more effectively. Simplicity with AI-powered querying: Marketers can use artificial intelligence to query their data using natural language search, reducing the reliance on data scientists. Us

Metasphere Labs Announces X Spaces Event on the Topic of Green Bitcoin Mining and Sound Money for Sustainability11.6.2024 10:30:00 CEST | Press release

VANCOUVER, British Columbia, June 11, 2024 (GLOBE NEWSWIRE) -- Metasphere Labs Inc. (formerly Looking Glass Labs Ltd., "Metasphere Labs" or the "Company") (Cboe Canada: LABZ) (OTC: LABZF) (FRA: H1N) is thrilled to announce an engaging Twitter Spaces event on Green Bitcoin mining, energy markets, and sustainability on July 3, 2024 at 2 p.m. ET. Follow us on X at MetasphereLabs for updates and to join the event. What We'll Discuss Bitcoin Mining Basics: Understand the fundamentals of Bitcoin mining.Energy Market Dynamics: Explore how Bitcoin mining interacts with energy markets.Sustainable Innovations: Learn about our efforts to promote sustainability in Bitcoin mining.Sound Money: Discover how tamper-proof currency can enhance stability.Efficient Payment Rails: See how fast, neutral payment systems support humanitarian projects.Carbon Footprint: Compare Bitcoin's environmental impact with traditional banking. "We're excited to host this event and dive into the critical topics of Bitcoin

World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye