Skip to content

cyber

Increasing Cyber Attacks: Why Ransomware and AI Worry Businesses and Institutions

In 2025, ransomware attacks recorded over 7,400 claims worldwide, an increase of 42% compared to 2024, while in Italy there were 166 cases, with a growth of 14%. All the data from the Cyber Security Report by Tim and Cyber Security Foundation.

Cybersecurity becomes a matter of national security.

This is highlighted by the second edition of the “Cyber Security Report – Threat Analysis and Scenario Evolution,” produced by Cyber Security Foundation and TIM with the contribution of the TIM Study Center, presented today at the Chamber of Deputies.

In 2025, ransomware attacks recorded over 7,400 claims globally, an increase of 42% compared to 2024, while in Italy the cases were 166, with a growth of 14%. About 4 out of 10 incidents detected in our country were concentrated in the Northwest, with Lombardy accounting for over 30% of the national total, according to the report.

At the same time, the report also highlights a positive direction: the growth of awareness and cooperation among institutions, businesses, and the technical community today represents a fundamental lever to transform threat analysis into concrete prevention, response, and resilience capabilities.

All the details on the report.

INDUSTRIALIZATION OF CYBERCRIME

At the base of the ransomware acceleration is a process of industrialization of cybercrime, also fueled by a more unstable international context, where cyberattacks increasingly intertwine with dynamics of geopolitical pressure and strategic competition. In this scenario, artificial intelligence plays a dual role: it is used to automate the production of malicious code and refine phishing techniques, but it also represents an increasingly important lever to strengthen prevention, analysis, and response capabilities. Not just a snapshot of observed attacks, but an analytical and guiding tool for citizens, businesses, and institutions called to face a now structural risk for the continuity of essential services, the competitiveness of the production system, and the overall security of the country.

DDOS ATTACKS DECLINE

On the DDoS front, the Report highlights about 4,300 events, down 36% compared to 2024, also due to prevention measures activated. However, the volume contraction does not signal a relaxation of the threat: attacks are less widespread but more targeted, persistent, and focused on strategic targets, aiming to maximize operational impact. Campaigns were in fact more concentrated, with an increase in average exposure time of 19%. Excluding events targeting households and citizens, which represent about 7 out of 10 cases detected by the TIM SOC, the Government sector reached 46% of the total, followed by professional services, telecommunications, and transport. Overall pressure, therefore, does not decrease: it changes form and increasingly targets subjects and services of high systemic relevance.

RANSOMWARE ATTACKS GROW, EU SECOND MOST AFFECTED AREA AFTER THE USA

Moving to ransomware, this type of attack confirms strong global acceleration, almost one in two events concerns the USA, while the EU is the second most affected area with 16% of cases. The most marked increases recorded in various European contexts redraw the ranking of the most affected countries: Germany surpasses the United Kingdom, while Italy falls to fourth place. Manufacturing and professional services are the most affected sectors, confirming how industrial density, operational continuity, and reputational pressure represent relevant exposure factors.

MALWARE CAMPAIGNS IN 2025

Then the report also focuses on malware campaigns, which in 2025 affected subjects in about 200 countries, and on the growth of known vulnerabilities, which reached almost 48,500, with an increase of 20% compared to 2024. The Report also dedicates a focus to zero-days, flaws not yet known to producers and therefore without patches, which can become tools for market, espionage, or strategic cyber operations. In this context, artificial intelligence emerges as a threat multiplier, capable of accelerating phishing, fraud, cloud service abuse, and manipulations, but also as a possible defensive lever for triage activities, vulnerability analysis, and support to Security Operation Centers.

THE EU AND NATIONAL CYBER SECURITY REGULATORY FRAMEWORK

Alongside the operational reading of threats, the report also addresses the European and national regulatory framework, referring to cyber resilience, protection of critical infrastructures, obligations for the most exposed organizations, and management of technological dependencies in supply chains. The last part looks at emerging technologies and new risk fronts: promptware, quishing, QRishing, smart devices, virtual and augmented reality, quantum-safe cryptography, and satellite network security. AI, quantum computing, and space emerge as three decisive frontiers: artificial intelligence accelerates phishing, fraud, and manipulations but can also support defense; quantum technologies open the risk of “harvest now, decrypt later”; satellite networks become increasingly strategic infrastructures to protect and govern.

CYBER THREAT AS A STRUCTURAL DIMENSION OF SECURITY

“The cyber threat is today a structural dimension of national security and the resilience of the country system,” emphasized Gianluca Galasso, Director of Cyber Operations and Crisis Management Service of the National Cybersecurity Agency, adding that “Artificial intelligence is accelerating the speed and sophistication of attacks, drastically reducing the time between the discovery of a vulnerability and its exploitation. In this scenario, it becomes essential to update internal processes, strengthen threat intelligence, detection, vulnerability, and crisis management capabilities, rapidly transforming data into operational decisions. It is equally important to structure risk management processes and understanding of the threat scenario to achieve real operational readiness and continuous resilience.”

WORDS FROM MICHELINI (TELSY)

“The growth of cyber threats confirms that digital security can no longer be considered an exclusively specialist or merely defensive issue. Telecommunications networks, data, cloud infrastructures, and communication systems constitute essential strategic assets for the operational continuity of the country and for the competitiveness of the economic system. For this reason, the response cannot be limited to emergency management: it is necessary to invest in digital sovereignty, skills development, and secure technologies, while strengthening collaboration among institutions, industry, and the research world. In this perspective, cybersecurity represents a real lever for growth and innovation. It helps generate trust, protect national strategic assets, and make digital transformation more resilient, sustainable, and competitive in the long term,” declared Alessandra Michelini, CEO and Chairwoman of Telsy.

“A DEMOCRATIC ISSUE”

“Digital security is no longer a technical issue: it is a democratic issue. Cyberattacks are today tools of geopolitical pressure, levers of economic destabilization, vectors of interference in democratic processes. Ignoring this dimension means leaving citizens, businesses, and institutions without the tools to understand what is happening. The Report is born exactly from this responsibility: to make accessible the reading of a threat that continuously changes form and intensity, transforming knowledge into a first, concrete form of collective defense. As Cyber Security Foundation, we believe that cybersecurity must become a widespread culture, capable of speaking to institutions, businesses, and citizens. Because a digitally more aware country is, above all, a safer country,” highlighted Marco Gabriele Proietti, founder and President of Cyber Security Foundation.

Back To Top