TL;DR
- Ransomware victims hit a record high in 2025, and weekly attacks per organisation reached 1,968, up 18% year on year and nearly 70% since 2023, according to Check Point’s 14th annual Cyber Security Report, drawing on its own global telemetry and Check Point Research.
- AI moved from assistant to operator: 89% of organisations were hit by risky AI prompts every month, and a separate investigation found an AI model ran 80 to 90% of the tactical steps in a state-linked espionage campaign with minimal human oversight, according to Check Point’s GenAI Protect data.
- Our view: most of what’s in this report is preventable exposure rather than novel attack technique, which is exactly the argument for catching it before incident response is ever needed, not during it.
Why this report is worth fifteen minutes of your time
Check Point has just published the 14th annual edition of its Cyber Security Report, built from its own global telemetry, Check Point Research and its Incident Response team’s live engagements. We’ve pulled out the findings that matter most to the CISOs and CIOs we work with, with our own view on what to do about them.
Social engineering went multi-channel
Phishing email is no longer the whole story:
- ClickFix, a fake CAPTCHA/verification technique, rose ~500% year on year and appeared in nearly half of all documented malware campaigns (Check Point Research).
- Voice-based impersonation (the Scattered LAPSUS$ Hunters cluster) hit Marks & Spencer (~£300m lost profit + £136m recovery costs), Jaguar Land Rover (~£1.9bn in damages), and ~40 Salesforce environments.
- The FBI attributes over $250 million in 2025 losses to voice-enabled fraud and account takeover.
The takeaway: the M&S breach should end the debate over whether help desk verification is an IT process or a security control. It’s the latter, and usually the weakest link.
Ransomware had a record year, and the ecosystem fractured
Ransomware volumes and the number of active groups both hit records in 2025, per Check Point’s tracking:
- 7,960+ victims named on data-leak sites, up 53% year on year; Q4 alone set a new record at 2,473.
- 140 distinct groups publishing victims, up from ~90 at the end of 2024, as several major RaaS operators went dark and law enforcement disrupted others.
- Qilin became the most active group on an 80 to 85% affiliate profit share; LockBit relaunched as 5.0 and posted 100+ victims in its first month back.
- In Check Point’s own case study, a Qilin affiliate tampered with a victim’s backup servers a day before deploying ransomware, after five weeks of undetected dwell time.
Worth noting: that sequence, backups targeted the day before encryption, is exactly what immutable, Zero Access backup storage is built to defeat.
Edge devices are the new launch pad
- Akira exploited a year-old SonicWall VPN flaw (CVE-2024-40766) even after patching, because harvested credentials stayed valid.
- Qilin and a new actor, Mora_001, both used Fortinet FortiOS/FortiProxy flaws to gain super-admin privileges.
Bottom line: this is a network security discipline problem, not an exotic one. Patch cadence on perimeter appliances is exactly where too many mid-market organisations still fall short.
AI: from assistant to operator
This is the chapter we’d put in front of a board first:
- 89% of organisations were hit by risky AI prompts monthly in Q4 2025; the high-risk prompt rate rose 97% since Q1 (Check Point’s GenAI Protect data).
- The average organisation now uses 14+ AI services, mostly without central visibility.
- 40% of ~10,000 exposed MCP servers reviewed had vulnerabilities, including exposed API keys in 8%.
Anthropic’s own investigation found its Claude Code model handled 80 to 90% of the tactical tasks in a China-affiliated espionage operation, reconnaissance to lateral movement, across around 30 targeted organisations, with minimal human oversight.
Our view: AI governance is now a board-level control gap. If you can’t list which AI services your organisation talks to, that’s the first gap to close.
The vulnerabilities everyone should already have patched
Check Point’s high-profile CVE chapter covers ToolShell (SharePoint), Langflow, Oracle EBS and React2Shell, but the more telling number sits underneath the headlines:
- 46%+ of exploitation attempts in 2025 targeted CVEs published before 2020.
- 2025-disclosed vulnerabilities accounted for just 4% of exploitation attempts.
In practice: for most mid-market organisations, the patch backlog is still the dominant risk, not the latest zero-day.
By the numbers: Check Point’s 2026 report at a glance
| Metric | 2025 figure |
| Ransomware victims on data-leak sites | 7,960+, up 53% year on year |
| Weekly cyber attacks per organisation | 1,968, up 18% YoY and ~70% since 2023 |
| Distinct ransomware groups publishing victims | 140, up from ~90 at end of 2024 |
| Organisations hit by risky AI prompts monthly | 89% |
| Increase in high-risk AI prompt rate during 2025 | 97% |
| MCP servers found with security vulnerabilities | 40% of ~10,000 probed |
| ClickFix social engineering activity increase | ~500% year on year |
| Exploitation attempts targeting pre-2020 CVEs | 46%+ |
What Check Point predicts for 2026
Check Point’s report closes with eight predictions for the year ahead. The headlines:
- Agentic AI moves from assistance to operational autonomy: raising new accountability questions.
- Prompt injection and data poisoning become the new zero-day: models themselves become the vulnerability.
- Supply chain and SaaS exposure intensifies: 62% of large orgs had a third-party compromise in the past year (ENISA).
- Deepfakes make trust the new perimeter: voice cloning increasingly bypasses MFA.
- Quantum risk moves from theory to action: today’s encrypted data is already being harvested for later decryption.
- AI becomes a strategic decision engine: embedded in detection and response, not just support.
- The AI reality check arrives: shadow AI and governance gaps get exposed.
- Regulation converges on provable resilience: NIS2, the EU AI Act and SEC rules demand continuous proof, not annual compliance.
What we’re seeing in practice
The pattern that stands out, and matches what we see in client environments: most serious incidents were preventable long before they became incidents.
- Check Point’s own exposure management chapter notes attackers typically leave detectable external signals, look-alike domains, exposed credentials, phishing infrastructure, before internal compromise.
- That’s the same logic behind our own Attack Surface Snapshot: an outside-in view of what’s already publicly visible, before an attacker acts on it.
UK, EU & New Zealand perspective
Check Point’s report is global, but the regulatory direction in our own markets is worth tracking alongside it:
- UK: the Cyber Security and Resilience Bill is progressing through Parliament (Committee stage completed early 2026), expected to gain Royal Assent this year with phased implementation running to 2028. It introduces mandatory incident reporting and direct regulation of “critical suppliers,” though its scope is narrower and less prescriptive than the EU’s NIS2 Directive, which the UK is no longer bound to post-Brexit.
- EU: NIS2 remains the wider regional benchmark for any UK organisation with EU operations or supply chain exposure, covering a broader range of sectors than the UK Bill, including public administration, space, food and manufacturing.
- NZ: the government’s new Cyber Security Strategy 2026–2030 estimates New Zealanders lose over $1.6 billion a year to cybercrime, and 59% of large NZ businesses surveyed reported a cyber incident in the past year. Its four objectives, Understand, Prevent and Prepare, Respond, Partner, include a single NCSC incident reporting service and a new critical infrastructure regulatory regime, both due for consultation in 2026. New Zealand was also one of the first countries to ban ransom payments by government agencies, in 2023, and continues to discourage payment by businesses. The full strategy is definitely worth a read: New Zealand’s Cyber Security Strategy 2026–2030 (DPMC, PDF)
Our view: the direction across all three is the same, mandatory reporting, less tolerance for ransom payment, more scrutiny on critical infrastructure and supply chain. None of it stays optional for long.
ITogether’s Independent Verdict
Check Point’s report is a useful corrective: 2025’s biggest breaches, M&S, JLR, and Check Point’s own Qilin case study, came down to help desk impersonation, unpatched edge devices and credential theft, not zero-day sophistication. That’s good news for defenders. The highest-value work is unglamorous: patch cadence, verification on high-risk help desk requests, visibility over AI usage, and backup storage that doesn’t trust a compromised admin account.
👉Want to walk through what Check Point’s findings mean for your environment, get in touch.
📞 UK +44 (0) 113 341 0123
📞 NZ +64 (0)9 802 2444
📧 hello@itogether.com
FAQs
What is the Check Point 2026 Cyber Security Report?
Check Point’s 14th annual report on the global threat landscape, built from its own telemetry, Check Point Research’s threat intelligence, and its Incident Response team’s case data from 2025.
What’s the single biggest takeaway for a mid-market CISO?
Most high-impact 2025 breaches came through preventable exposure, unpatched edge devices, help desk impersonation, weak backup immutability, rather than novel attack techniques.
Are we at risk from old CVEs even if we don’t run the specific software named in the report?
Very likely yes. Check Point found that over 46% of exploitation attempts in 2025 targeted vulnerabilities disclosed before 2020, across a wide range of platforms, not just the headline cases.
How does this connect to ITogether’s own services?
Several sections, particularly Check Point’s closing chapter on exposure management, describe exactly the outside-in, pre-breach visibility approach behind our own Attack Surface Snapshot and Proactive Cyber Security Monitoring Service.

0 Comments