New research from Hornetsecurity reveals that 24% of organizations were victims of ransomware attacks in 2025, up from 18.6% in 2024. This marks the first increase in three years, signaling a shift as cybercriminals adopt new technologies to bypass traditional defenses.
While traditional phishing remains the primary attack vector in nearly half of cases (46%), the study finds a growing reliance on compromised endpoints (26%) and stolen credentials (25%) as access points. Despite this rising threat, fewer organizations are investing in ransomware insurance, with only 46% insured in 2025, down from 54.6% in 2024.
Daniel Hofmann, CEO of Hornetsecurity, commented: “Following a multi-year decline in ransomware attacks, 2025 marks a critical turning point. Organizations must strengthen security against faster, smarter, and AI-automated ransomware. Although obtaining insurance is increasingly difficult, deploying next-gen email security, security awareness programs, and immutable backup storage provides strong protection against these attacks.”
Businesses Respond to AI-Powered Attacks
The study shows a reduction in traditional phishing attacks over the past year (52.3% in 2024 vs 46% in 2025), but over three-quarters of CISOs (77%) identify AI-generated phishing as a growing threat. Improved preparedness is evident, with the proportion of victims paying ransoms dropping to 13% from 16.3% in 2024. Additionally, 82% of organizations now have a Disaster Recovery Plan, and 62% utilize immutable backups.
Training Alone Is Not Enough
Despite widespread training programs, cybersecurity education is still lacking in effectiveness. While 74% of organizations offer end-user training against ransomware, 42% of security leaders report it as insufficient. “False compliance,” particularly among SMBs, occurs when check-box training meets superficial standards without proper follow-up, leaving employees vulnerable to sophisticated phishing and social engineering attacks.
Leadership and Governance Challenges
Human error remains the dominant source of incidents, with 66% of CISOs identifying it as the primary attack vector. Training improvements are often superficial, supporting Hornetsecurity’s findings on the limitations of compliance-focused programs. Hofmann noted: “Effective cybersecurity awareness training must be ongoing, relevant, and personalized — ideally automated by next-gen, AI-powered solutions such as our Security Awareness Service.”
He added: “While the decrease in ransom payments is encouraging, complacency is not an option. Businesses must deploy comprehensive cyber-defense strategies that protect against breaches, prevent future threats, and ensure resilient systems capable of rapid recovery.”
For more updates on AI, IoT, cybersecurity, and industry insights, explore Itech360hub.com.
