Bitdefender
Reports
All Statistics
47.4% of IT and security professionals acknowledge only partial or no visibility into individual Shadow AI tools or personal accounts used for work.
57.8% of IT and security managers believe they have full visibility into AI tool usage compared to 45.9% of practitioners.
45% of IT and security professionals identify internal AI systems and large language models (LLMs) as their primary security concern.
Younger consumers are twice as likely to fall victim to scams as adults aged 55 and older, with victimization rates of 20% versus 9.7%.
14% of consumers report falling victim to a scam in the past year.
Approximately 5.2% of SMS messages (about 1 in 20) exhibit characteristics consistent with scam infrastructure or coordinated fraud activity.
48% of consumers do not use a third-party security solution on their phone, despite 53% conducting sensitive transactions such as bill payments or online shopping in 2025.
37% of consumers worldwide identified the use of artificial intelligence in sophisticated scams, such as deepfakes, as their top concern in 2025.
37% of consumers worldwide still write down passwords, while 32% reuse the same password across multiple accounts in 2025.
Germany reported the highest difficulty with tool complexity at 41%.
20.3% of respondents view AI-powered malware as an extremely significant risk. This concern for AI-powered malware climbs to 25% among senior management, compared to just 15% of middle management.
One in four (25%) flagged compliance navigation as their biggest challenge with security solutions.
February 2025 saw a total of 962 victims claimed by ransomware groups.
Out of the 962 victims claimed in February 2025, 335 were claimed by the Clop (Cl0p) group.
The number of victims claimed by Clop (Cl0p) saw a 300% jump from the previous month.
44% of IT and security professionals identify cloud infrastructure and application environments as a primary security concern.
33.3% of IT and security professionals identify identity and access management (IAM) systems as a top security concern.
55.2% of IT and security professionals who experienced a security incident or breach in the past 12 months state they were told to keep it confidential despite believing it should have been reported.
The 55.2% of IT and security professionals told to keep breaches confidential is slightly down from 57.6% in 2025 and substantially higher than 42% in 2023.
68.6% of IT and security professionals in the U.S. who experienced a breach report being told to keep it confidential, the highest regional rate.
57.2% of IT and security professionals in both Germany and the U.K. who experienced a breach report being told to keep it confidential.
56.8% of IT and security managers and 53.5% of practitioners who experienced a breach report pressure to stay silent.
35.9% of IT and security professionals report experiencing business email compromise (BEC) resulting in financial or data loss in the past 12 months.
54.7% of IT and security professionals in the U.S. report experiencing BEC incidents, nearly 19 percentage points above the overall average.
59.2% of IT and security professionals confirm experiencing AI-driven social engineering attacks in the past 12 months.
The top barriers to reducing the attack surface reported by IT and security professionals are high overhead in maintaining hardening rules and exceptions (38%), fear of operational disruption (35.4%), and resource constraints (34.6%).
Difficulty securing legacy systems is reported by 34.5% of IT and security professionals and visibility gaps are reported by 33.8%.
87% of IT and security professionals in the U.S., 85% in the U.K., and 77% in Germany say they would likely switch cybersecurity vendors due to data sovereignty concerns.
0.5% of IT and security managers report zero visibility into AI tool usage versus 4.5% of practitioners.
51.8% of IT and security professionals report full visibility into sanctioned and unsanctioned AI tool usage.
IT and security professionals rate attackers using AI to generate self-mutating malware as a high or extreme risk at 55.9%, employees leaking sensitive data into public LLMs at 53.5%, AI-driven evasion techniques at 52.5%, and deepfakes or voice cloning used in fraud or BEC at 51.9%.
25.6% of IT and security professionals report experiencing ransomware in the past 12 months.
20.4% of IT and security professionals rate employees leaking sensitive data into public LLMs as a low or extremely low risk.
48.8% of IT and security professionals in the U.S. report marked gaps in visibility compared to the overall average of 33.8%.
64% of IT and security professionals in Singapore and 61.6% in the U.S. view agentic AI expanding the attack surface as a regional flashpoint.
79.4% of IT and security managers and 72.8% of practitioners say they would likely switch vendors due to data sovereignty concerns.
76.1% of IT and security professionals say they would likely switch cybersecurity vendors due to concerns about data sovereignty, jurisdiction, or foreign government access to their data.
41.8% of IT and security professionals report experiencing a cloud infrastructure or application breach in the past 12 months.
More than 23 million incoming calls are classified as unwanted, meaning about 1 in 6 calls reaching protected devices is fraudulent or unsolicited.
Losses due to scams globally reach nearly half a billion US dollars in 2025.
Respondents reported managing an average of five online accounts, with nearly two-thirds holding at least three accounts in 2025.
48% of consumers accept all cookies by default, while only 36% manually manage them and 16% reject all cookies in 2025.
Social media is the leading medium for successful scams at 34%, surpassing email (28%), phone calls (25%), text messages (24%), and online ads (21%) in 2025.
14% of consumers reported falling victim to a scam in the past year, with an average loss of $545, resulting in over $534,000 lost among survey participants.
When asked about the most concerning threats, 51% cited AI-generated threats (e.g., deepfakes, automated malware, malicious code).
63.3% believe their organization experienced an attack involving some element of AI within the past 12 months.
28% of respondents cited internal skills shortages as a challenge with current security solutions.
In Singapore, 59% of respondents stated the cybersecurity skills gap within their organization has worsened over the past 12 months.
Singapore reported the highest concern with lack of in-house expertise with tools, at 39%.
50% of professionals in the U.S. and Singapore plan to seek new jobs in the next year.