Welcome to May 2025 Threat Highlight Report
The May 2025 edition of WithSecure™'s Threat Highlight Report is a deep dive into the most pressing cyber security developments affecting organizations worldwide.
May report covers
This month’s report shines a spotlight on the increasing use of social engineering tactics, turbulence in the ransomware ecosystem, and the evolving threat landscape across cloud and SaaS environments.
The key findings in the May 2025 Threat Highlight Report include:
- Retail sector under siege
Scattered Spider actors launched coordinated ransomware attacks against major UK retailers including M&S and Co-Op, exploiting social engineering and third-party weaknesses to inflict massive operational and financial damage. - Commvault & ConnectWise breaches
Vulnerabilities in SaaS platforms led to compromise of customer environments via cloud-hosted backup and remote access services—highlighting the risk of overly permissive configurations and inherited trust. - Ransomware trends
For the first time since 2024, leak site victim volumes dropped year-over-year. Meanwhile, RansomHub has vanished, Lockbit’s leak site was hacked, and new groups like SAFEPAY and Devman have emerged. - Credential theft & trojanized software
A months-long campaign using trojanized KeePass installers revealed how attackers are blurring the lines between legitimate software and malware—culminating in ransomware deployments. - Identity and Cloud risks on the rise
xAI accidentally exposed private keys giving access to unreleased LLMs, and 89 million Steam user records (with MFA data) were reportedly compromised. Japanese financial services suffered nearly $2Bn in unauthorized trading from credential theft. - Law enforcement takes action
Operation Endgame and Operation PowerOff disrupted more than 300 servers and arrested several operators—showing growing global coordination against cybercriminal infrastructure.
Download the full report or subscribe for future insights to empower your cyber strategy with clarity, data, and expert guidance from WithSecure™.
Be Ahead of the Game!
Stay informed about the latest cybersecurity threats and trends by subscribing to WithSecure's monthly threat highlights report!
Our comprehensive report provides an overview of last month's cybersecurity news, the changing threat landscape, and relevant advice.
Don't miss out on valuable insights - fill out the form to receive our report now!