Ransomware remains the primary threat to medium- and large-sized businesses, while the most active criminal groups are increasingly turning to AI to generate low-effort, high-return campaigns
Acronis, global leader in the cybersecurity and in the data protection, released the results of the Acronis Cyberthreats Report H1 2025, which analyzes the main attack vectors, the most active threat groups and the sectors affected in the first half of 2025. Ransomware remains the main threat for large and medium-sized companies, with new groups leveraging AI to automate their activities: phishing represents 25% of all attacks and 52% of those launched against MSPs, with an increase of 22% compared to the 1st half of 2024.
The semi-annual report offers a global overview of detections made by the Acronis Threat Research Unit (TRU) and Acronis sensors on Windows endpoints between January and June 2025. The analyzes are based on over a million unique endpoints distributed globally and include specific statistics on threats aimed at Windows operating systems, which are more popular than MacOS and Linux.
“While spreading ransomware remains the ultimate goal of criminals, how they get there is changing,” said Gerald Beuchelt, CISO at Acronis. "Today, even less experienced attackers can access advanced AI capabilities, generate social engineering attacks, and automate their tasks with minimal effort. The result is that MSPs, manufacturers, ISPs, and other operators are constantly exposed to increasingly sophisticated attacks, such as advanced deepfakes, and it only takes one mistake to compromise the future prospects of companies. To address this scenario and avoid the severe consequences of a ransomware attack, it is essential to adopt a holistic cyber protection strategy that integrates advanced detection, response, and recovery capabilities."
Main findings from the Acronis Cyberthreats Report for the first half of 2025:
– Ransomware remains the dominant threat: The number of known victims increased by almost 70% compared to the same periods in 2023 and 2024. Cl0p, Akira and Qlin are the most active ransomware groups.
– AI e social engineering: Ransomware groups are increasingly leveraging AI, as demonstrated by popular threat vectors: Social engineering and BEC attacks rose from 20% to 25.6% between January 2025 and May 2025 compared to the same period in 2024, likely driven by the growing use of AI to create convincing impersonations. Malware was detected in 1.47% of Microsoft 365 email backups.
– MSP targeted by phishing: While the overall number of attacks targeting MSPs has declined over the period, it is the nature of the attacks that has changed dramatically. Phishing is at the origin of 52% of all attacks against MSPs, compared to 30% in 2024, while there is no longer any trace of attacks on the RDP protocol.
– More sophisticated phishing: Phishing remains the preferred tool for attackers, but they are increasingly focusing on collaboration apps, avoiding simple BEC campaigns. Nearly 25% of attacks against these apps used AI-generated deepfakes or automated exploits.
– Manufacturing sector most affected: Manufacturing companies accounted for 15% of all cases recorded in the first quarter of 2025, followed by retail and food & beverage (12%) and telecommunications and media (10%).






