Group-IB
All Statistics
Across the META region, Internet and Financial services accounted for over 80% of phishing activity.
In 2025, phishing activity in the META region targeted internet services (52.49%), financial institutions (28.50%), and the logistics sector (11.20%).
In 2025, more than 200 cases of corporate access linked to META organizations were publicly advertised for sale.
Ransomware activity is most heavily concentrated in the GCC, which accounted for over 100 reported incidents in 2025.
Public IAB listings declined 27% shifting high-value deals into private channels.
Financial services (68.45%) was the top industry targeted by phishing attacks globally in 2025.
Access is increasinly sold as tokens, SaaS admin, and integration footholds, not just VPN/RDP.
Financial services (82.74%) was the top industry targeted by phishing attacks in Europe in 2025.
IT (38.24%) was the top industry targeted by phishing attacks in North America in 2025, followed by Financial Services (29.66%) and Internet Services (22.5%).
Financial services (97.36%) was the top industry targeted by phishing attacks in LATAM in 2025.
Financial services (94.24%) was the top industry targeted by phishing attacks in Central Asia in 2025.
Fewer new RaaS programs (-17.9%), but overall activity continued to expand.