Malicious actors significantly stepped up their identity theft attacks last year, using phishing emails created with artificial intelligence and infostealer malware to improve their results, according to IBM.
See also: CISA: SonicWall VPN flaw is actively used in attacks

According to the IBM X-Force 2025 Threat Intelligence Index, which was published this morning, the data was gathered from the company's own incident response operations, as well as from intelligence sources on the dark web and other cyberthreat.
The report says that about 30% of breaches last year involved identity theft-based attacks, fueled by an 84% year-over-year increase in the volume of emails distributed by infostealers. Artificial intelligence is used to mass-produce highly persuasive phishing emails, as well as to write malicious code.
In first place, tied with the use of legitimate account credentials, as the most widespread method of initial access, is the exploitation of applications accessible from the internet.
The report states that a quarter of attacks against critical infrastructure (CNI) providers use this tactic, with reliance on aging systems and slow software update cycles exposing a growing number of organizations to this risk.
See also: Apple: Fixes two zero-days exploited in iPhone attacks
IBM has revealed that state-sponsored malicious actors and cybercriminals are increasingly sharing information about vulnerabilities on the dark web, with 40% of the most discussed CVEs on underground forums being linked to sophisticated threat groups.

At the same time, ransomware attack tactics are changing. While ransomware accounted for the largest proportion of malware incidents in 2024 (28%), there was an overall year-on-year decrease in the number of incidents last year.
Global operations to dismantle cybercriminal groups have forced some threat actors to abandon established malware families such as Trickbot and Quakbot, turning to “new and short-lived malware families.”
The industrial sector was again the main target last year, being the biggest victim of ransomware, with 29% of extortion attacks and 24% of data theft incidents affecting it.
See also: Conduent confirms theft of customer data due to cyberattack
Increased cooperation between state and criminal groups in cyberspace, combined with the proliferation of artificial intelligence tools and the widespread use of infostealers , creates a particularly dangerous threat landscape. This makes it imperative to continuously update systems, train personnel and adopt advanced security incident detection and response solutions .
Source: infosecurity-magazine
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
