Tracking cyberattacks since last year, a report by Crowdstrike found that physical attacks and kidnappings have increased dramatically, particularly in Europe. “In January 2025, threatening actors kidnapped and attempted to blackmail the co-founder of Ledger, a well-known cryptocurrency wallet provider, in France,” the Crowdstrike report states. “While the perpetrators in this case and several others have been apprehended, the threat remains. Between January 2025 and September 2025, there were 17 similar incidents in Europe, 13 of which occurred in France.”
See also: Vulnerabilities in CrowdStrike Falcon Sensor for Windows allow file deletion

Cybersecurity consultants said they have been hearing similar reports of increased brute force to gain access to systems for some time. As a result, both organizations and individuals are already deepening their focus on physical and personnel security. Cybersecurity manuals should explicitly encourage the team to consider whether the incident they are facing could be, in part or in whole, a diversion for some other type of attack.
Art Cooper, the principal security consultant at TrustedSec, said his basic, albeit humorous, recommendation for executives who might be physically threatened by criminals trying to gain access to data is, “Get a gun.” Cooper said part of the problem is the typically lax way many European and American businesses handle physical security, compared to, say, businesses in India. He said Indian businesses typically have multiple layers of physical security around key buildings, with different security companies handling different layers.
When someone enters, they are typically asked to submit all electronic devices for inspection, where guards record all serial numbers. As the visitor moves deeper into the building, other security teams, working for other security companies, inspect those devices and record the serial numbers again. However, he is starting to see businesses in China and Japan adopting the relaxed methods employed by the Americans.
See also: CrowdStrike will lay off 500 employees

The Crowdstrike report analyzed some of the global patterns in the prevalence of attacks. “Entities in Europe are more than twice as likely to be targeted as entities in the Asia-Pacific and Japan region,” the report said, adding that the European Union’s General Data Protection Regulation (GDPR) is one reason. “Attackers have exploited GDPR data breach penalties to pressure victims into paying ransoms. Several attackers have threatened to report entities for non-compliance via their data breach websites, in ransom notes, or during negotiations.”
The report highlighted several statistical attack patterns, including the most targeted sectors (construction, professional services, technology, industrials and engineering, and retail) and the most popular attack methods, including, as it states, “Credential dumping from backup and recovery configuration databases, which often store credentials used to access supercomputing infrastructure. Remote file encryption, ransomware execution, often from an unmanaged system and performing the file encryption process outside of the targeted system. Exploiting access to unmanaged systems to steal data and deploy ransomware, and deploying Linux ransomware on VMware ESXi infrastructures.”
Another increasingly popular attack method, the report says, is creating fake CAPTCHAs to deliver malware. Some criminal agencies have aggressively promoted specific capabilities as their specialties, the report noted. As expected, the report found that the tradition of Russian attack groups avoiding targeting Russian businesses and consumers is still very much in evidence.
See also: CrowdStrike vs Delta: Legal battles over summer blackout

“The ban on targeting organizations and citizens of Russia and the Commonwealth of Independent States (CIS) countries has long been an unspoken and often codified rule in the Russian-speaking underground ecosystem,” the report states. “While this ban likely has its roots in an attempt to evade domestic law enforcement, patriotism likely also plays a role, with CIS-based eCrime threat actors preferring to target external entities.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
