News, Releases, Events

New Threat Vectors: Why Businesses Need to Rethink Their Cybersecurity Approach

In 2025, domestic IT infrastructure faced unprecedented pressure from cyber threats. According to data presented at a high-level interagency security commission meeting, the number of attacks on mission-critical information infrastructure increased fourfold over the year. At the same time, despite a general slowdown in the growth of cybercrime, remote theft and computer-related offenses remain consistently high, while the financial sector recorded a 13% increase in attacks in the first half of the year.

These alarming figures are supported by official statistics. On September 16, senior ICT official Tatiana Matveeva stated that more than 63,000 IT attacks were recorded in the first six months of 2025, which is 27% more than in the same period of 2024. Two thirds of them were deliberately targeted at mission-critical infrastructure.

Economic Damage and Shifting Attack Vectors

The direct economic damage caused by cybercrime remains enormous. According to Deputy Head of the Digital Development Authority Ivan Lebedev, in 2024 it was estimated at RUB 160 billion, while some estimates place the figure at up to RUB 250 billion annually. In 2024, the number of IT-related crimes increased by 34.8%, with theft and fraud accounting for 70.2% of them, confirming financial motivation as the main driver of cybercrime.

This year, attackers are actively changing their tactics. According to Kaspersky Lab, although the number of attacks using backdoors decreased by 63%, incidents targeting financial organizations through online resources increased by 81%. Malware used to steal funds via remote access also became 2.4 times more common.

The Human Factor as the New Weak Link

Alongside infrastructure attacks, another threat is gaining momentum: corporate networks are being compromised through employees’ personal devices. The number of such attacks increased by 30% in the first half of 2025. Experts link this trend to the shift toward remote work, which has blurred the line between personal and corporate digital environments.

Smartphones are infected through malicious applications from unofficial sources or phishing messages in messengers, while laptops are most often compromised through phishing emails with infected attachments or illegal software.

Business Takeaways: The Need for Comprehensive Protection

The statistics clearly show that traditional security measures are no longer sufficient. Attackers deliberately target both mission-critical assets and less protected personal devices used by employees to gain access to corporate networks.

In an environment where the financial sector consistently ranks third in the number of threats after industry and highly regulated institutional segments, while the clearance rate for IT crimes, despite growing to 28.9%, remains low, businesses must take much greater responsibility for their own security.
Made on
Tilda