Report by Forescout

2025H1 Threat Review

20 FINDINGSPublished Aug 4, 2025
View Original Report →

Key Findings

Ransomware rose 36% year over year.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsRansomware

40% of threat actor updates in H1 2025 were attributed to state-sponsored groups.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsThreat actorsState sponsored threat actors

Ransomware attacks are averaging 20 incidents per day.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsRansomware

62% of breaches in H1 2025 involved data stored on network servers.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsBreachNetwork servers

9% of threat actor updates in H1 2025 were attributed to hacktivists.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsThreat actorsHacktivists

76% of breaches in H1 2025 stemmed from hacking or IT incidents.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsBreach

There were 3,649 documented ransomware attacks in H1 2025.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsRansomware

Ransomware attacks grew in frequency to 608 per month, or roughly 20 per day.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsRansomware

Zero-day exploits increased 46% in H1 2025.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsZero-day exploits

Modbus accounted for 57% of OT protocol traffic in Forescout honeypots in H1 2025.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsModbus

The U.S. was the top ransomware target, accounting for 53% of all ransomware incidents, in H1 2025.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsRansomwareUS

24% of breaches IN h1 2025 were on email systems.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsBreachEmail

47% of newly exploited vulnerabilities were originally published before 2025.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsVulnerabilities

Zero-day exploitation increased 46% in H1 2025.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsZero-day exploits

Published vulnerabilities rose 15% in H1 2025.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsVulnerabilities

45% of published vulnerabilities in H1 2025 were rated high or critical.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsVulnerabilities

CVEs added to CISA KEV jumped 80% in H1 2025.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsCVEsCISA KEV

The healthcare sector experienced an average of two healthcare breaches per day in the first half of 2025.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsHealthcareBreach

51% of threat actor updates in H1 2025 were attributed to cybercriminals, such as ransomware groups.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsThreat actors

Nearly 30 million individuals were affected by breaches in H1 2025.

Forescout2025H1 Threat Review·Aug 4, 2025
ThreatsBreach