ExtraHop, a leader in modern network detection and response (NDR), has released the 2025 ExtraHop Global Threat Landscape Report, offering a comprehensive analysis of the ever-shifting cybersecurity environment. The report examines the expanding attack surface, detailing the evolving tactics threat actors are using to exploit organisations and carry out increasingly lucrative attacks.
According to the findings, threat actors are shifting away from broad, indiscriminate attacks towards more targeted approaches that deliver greater impact. As IT environments become more complex and attack surfaces expand, adversaries are able to exploit blind spots, spending more time inside organisations to cause greater damage and secure higher payouts.
Ransomware payouts soar as tactics evolve
While the frequency of ransomware incidents has declined from eight attacks per organisation to between five and six over the past year, the average ransom payment has increased by more than US$1 million — rising from US$2.5 million to US$3.6 million.
This divergence between attack frequency and cost reflects attackers’ growing ability to operate undetected within corporate environments. Threat actors had access to networks for nearly two weeks on average before launching an attack and almost one third of organisations only became aware of an incident after data exfiltration had already begun.
Delays in response increase downtime
Organisations take more than two weeks on average to respond to and contain a security alert. These delays allow attackers to maximise disruption, with affected organisations experiencing an average downtime of more than 37 hours following an incident.
Critical infrastructure and government remain prime targets
RansomHub (26.8%), LockBit (26.5%), Darkside (25.7%), APT41 (24%) and Black Basta (23.4%) were the most frequently detected threat actors across organisations. In government environments, LockBit (33.3%), Darkside (33.3%), Black Basta (33.3%) and RansomHub (25.6%) were among the most active groups.
Old tactics still dominate
As attack surfaces grow, organisations cite the public cloud (53.8%), third-party services and integrations (43.7%) and Generative AI applications (41.87%) as their greatest cybersecurity risks. Phishing and social engineering remain the most common entry points (33.65%), followed by software vulnerabilities (19.43%), supply-chain compromise (13.4%) and compromised credentials (12.2%).
Limited visibility undermines defence
The leading barriers to effective threat response include limited end-to-end visibility (41%), overwhelming alert volumes (34%), poorly integrated tools (34%) and inefficient or manual SOC workflows (34%). Visibility challenges were particularly acute in telecoms, finance and education.
“Motivated attackers are exploiting new entry points to bypass traditional defences and remain hidden until the time is right to strike,” said Raja Mukerji, Co-founder and Chief Scientist at ExtraHop. “Organisations must be able to detect threats as they move laterally across systems. Without full visibility and context across network traffic, enterprises will continue to face costly downtime and ransom payments.”


