Report by Sophos

The Sophos Annual Threat Report: Cybercrime on Main Street 2025

13 FINDINGSPublished Apr 16, 2025
View Original Report →

Key Findings

Compromised network edge devices account for a quarter of the initial compromises of businesses in cases that could be confirmed from telemetry.

SophosThe Sophos Annual Threat Report: Cybercrime on Main Street 2025·Apr 16, 2025
Network edge devicesSecurity incident

Most active STAC campaigns tracked by Sophos MDR in 2024 were ransomware-related.

SophosThe Sophos Annual Threat Report: Cybercrime on Main Street 2025·Apr 16, 2025
Ransomware

Use of remote ransomware increased 50 percent in 2024 over last year.

SophosThe Sophos Annual Threat Report: Cybercrime on Main Street 2025·Apr 16, 2025
RansomwareRemote ransomware

The Veeam vulnerability (CVE-2024-40711) and similar documented vulnerabilities played a role in nearly 15 percent of the cases Sophos MDR tracked involving malicious intrusions in 2024.

SophosThe Sophos Annual Threat Report: Cybercrime on Main Street 2025·Apr 16, 2025
VulnerabilitiesMalicious intrusion

The use of remote ransomware increased 50 percent in 2024 over last year, and 141 percent since 2022.

SophosThe Sophos Annual Threat Report: Cybercrime on Main Street 2025·Apr 16, 2025
RansomwareRemote ransomware

Use of remote ransomware increased 141 percent since 2022.

SophosThe Sophos Annual Threat Report: Cybercrime on Main Street 2025·Apr 16, 2025
RansomwareRemote ransomware

Obsolete and unpatched hardware and software constitute an ever-growing source of security vulnerabilities.

SophosThe Sophos Annual Threat Report: Cybercrime on Main Street 2025·Apr 16, 2025
VulnerabilitiesObsolote hardwareUnpatched hardware

The most frequently seen "EDR killer" in 2024 was EDRSandBlast.

SophosThe Sophos Annual Threat Report: Cybercrime on Main Street 2025·Apr 16, 2025
EDR

Ransomware and data theft attempts accounted for nearly 30 percent of all Sophos Managed Detection and Response (MDR) tracked incidents (in which malicious activity of any sort was detected) for small and midsized businesses.

SophosThe Sophos Annual Threat Report: Cybercrime on Main Street 2025·Apr 16, 2025
RansomwareData theft

Over a third of all incidents involving intrusion into smaller organisations have systems on the network edge as the initial point of compromise.

SophosThe Sophos Annual Threat Report: Cybercrime on Main Street 2025·Apr 16, 2025
Malicious intrusionSmall businessNetwork edge devices

The average price of "junk gun" ransomware obtained from an underground marketplace is $375.

SophosThe Sophos Annual Threat Report: Cybercrime on Main Street 2025·Apr 16, 2025
Ransomware

EDRSandBlast variants were detected in waves of attempted ransomware attacks throughout 2024, including a dramatic peak around the US Thanksgiving holiday in November

SophosThe Sophos Annual Threat Report: Cybercrime on Main Street 2025·Apr 16, 2025
RansomwareHoliday

Ransomware cases accounted for over 90 percent of Sophos Incident Response cases for midsized organisations (from 500 to 5000 employees) in 2024.

SophosThe Sophos Annual Threat Report: Cybercrime on Main Street 2025·Apr 16, 2025
RansomwareMiddle market