SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
Story image

Trustwave outlines 80% rise in ransomware by 2025

Today

Trustwave has issued its 2025 cybersecurity threat report for the energy and utilities sector, identifying significant trends and highlighting a notable increase in ransomware attacks.

The comprehensive analysis by Trustwave's SpiderLabs team examines current cybersecurity threats impacting the energy and utilities industry, a vital sector subject to increasingly frequent attacks due to its role in supporting national and global infrastructures.

The research underscores several key trends influencing the sector, such as the escalation of ransomware attacks, the merging of operational technology (OT) and information technology (IT) systems, and evolving regulatory demands. Furthermore, the report offers insights into the advanced tactics, techniques, and procedures (TTPs) utilised by threat actors, categorised according to different attack stages.

Trustwave SpiderLabs has also developed two detailed write-ups focused on ransomware, considered one of the most critical threats facing the sector. These documents explore ransomware trends in intricate detail and provide thorough analyses of major threat groups such as Hunters International and 8Base that are targeting the industry.

Kory Daniels, Chief Information Security Officer at Trustwave, remarked on the necessity for resilience against threats for the sector's success. "Resilience to threats, both nefarious and incidental, is critical for the success of the energy and utilities sector," he stated. "Any attacks on the energy sector's supply chain of customers and partners can cause significant damage and harm, including to human life."

Daniels added that with the complex challenges of diverse physical and digital environments, "Continuous testing and cyber defence programs are challenged. To achieve effective threat resilience, asset and exposure management, infrastructure and code testing, OT & IT cyber defence, and business continuity and disaster recovery programs, such cybersecurity measures will increasingly require innovative collaboration between public and private sectors."

The report emphasises the unique challenges faced by the energy and utilities sector. These include a heavy reliance on the integration of physical and digital systems, mounting regulatory pressure, and outdated legacy systems. The geopolitical significance of the sector and potential for widespread social impact enhance its attractiveness as a target for malicious entities.

The Trustwave SpiderLabs 2025 research suite for the energy and utilities sector features notable findings, including an 80% rise in ransomware activity year over year. In the United States, 47% of ransomware attacks were recorded, with Hunters International responsible for 19% of those attacks in the second half of 2024. Phishing was identified as the starting point for 84% of these attacks, while 96% of attackers used remote services for lateral movement. Additionally, 67% of credential access attempts employed brute force techniques.

Follow us on:
Follow us on LinkedIn Follow us on X
Share on:
Share on LinkedIn Share on X