> ## Content Index
> Fetch the complete content index at: https://www.cybersecstats.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CyberSecStats #11 - APTs, infostealers, and quantum computing
- URL: https://www.cybersecstats.com/cybersecstats-11-apts-infostealers-and-quantum-computing/
- Published: 2025-05-05T13:54:29.000Z
- Updated: 2026-01-18T18:24:56.000Z
- Author: Laura M

Hello! 👋🏼 Laura from CyberSecStats here with a weekly email of the latest cybersecurity vendor reports and research. 

All the cybersecurity statistics below were published between April 28th - May 4th, 2025\. 

---

## General

### Logicalis 2025 CIO Report

Survey of 1,000 global IT leaders with over 250 employees with involvement in digital transformation and cloud computing within their organizations. 

#### Key stats:

- CIOs’ biggest worries: malware/ransomware (42%), data breaches (37%), AI-driven attacks (34%) and phishing (33%).
- Just 58% of CIOs feel confident they can spot security gaps.
- 50% of tech leaders say their security tools don’t fully meet their needs.

**Read the full report** [**here**](https://www.us.logicalis.com/2025-CIO-Report?ref=cybersecstats.com)**.**

### Optiv 2025 Cybersecurity Threat and Risk Management Report

How organizations are adapting their cybersecurity investments and governance priorities to combat evolving threats. 

#### Key stats:

- 79% of respondents report changes to their cybersecurity budget.
- Among those, 71% say their security budgets are rising.
- 67% now use risk and threat assessments to guide budget decisions (up from 53% in 2024).

**Read the full report** [**here**](https://www.optiv.com/insights/discover/downloads/2025-cybersecurity-threat-and-risk-management-report?ref=cybersecstats.com)**.**

### Trellix The CyberThreat Report: April 2025

The cyber threat landscape and the tools, techniques, and motivations of APTs. 

#### Key stats:

- APT detections targeting the U.S. in Q1 2025 jumped 136% (2.4×) over Q4 2024.
- Global APT detection volume rose 45% from Q4 2024 to Q1 2025.
- Cybercrime–market AI tools can cost as little as $0.30.

**Read the full report** [**here**](https://www.trellix.com/advanced-research-center/threat-reports/april-2025/?ref=cybersecstats.com)**.**

### 2025 LevelBlue Futures™ Report

The characteristics of cyber resilient organizations, evolving attack vectors, and how leaders are aligning business goals and cybersecurity.

#### Key stats:

- Just 29% of executives hesitate to adopt AI due to security concerns.
- 32% feel their organization is ready to handle deepfake attacks.
- 68% say high-profile breach news has raised cybersecurity priority in the C-suite.

**Read the full report** [**here**](https://levelblue.com/resource-center/futures-reports/2025-levelblue-futures-report-cyber-resilience-and-business-impact?ref=cybersecstats.com)**.**

### Fortinet 2025 Global Threat Landscape Report

A snapshot of the active threat landscape and trends from 2024\. 

#### Key stats:

- Active scanning climbed 16.7% year-over-year worldwide.
- Over 40,000 new vulnerabilities were logged in the National Vulnerability Database in 2024 - a 39% jump from 2023.
- Initial access brokers now offer corporate credentials (20%), RDP access (19%), admin panels (13%) and web shells (12%).

**Read the full report** [**here**](https://www.fortinet.com/resources/reports/threat-landscape-report?ref=cybersecstats.com)**.**

## Ransomware

### Comparitech Ransomware roundup: April 2025 

Ransomware insights from April 2025\. 

#### Key stats:

- April 2025 saw 479 ransomware attacks (vs. 530 in Jan, 973 in Feb, 713 in Mar).
- 39 of April’s attacks were confirmed by the targets.
- Most prolific ransomware gangs (based on attack claims) in April 2025: Qilin (67), Akira (62), Play (50), Lynx (32), NightSpire (22). RansomHub had no new victims.

**Read the full report** [**here**](https://www.comparitech.com/news/ransomware-roundup-april-2025/?ref=cybersecstats.com)**.**

## Email

### Barracuda 2025 Email Threats Report

Current state of email-based risks facing organizations worldwide. 

#### Key stats:

- 20% of organizations faced at least one account takeover attempt or success each month.
- 68% of malicious PDFs embed QR codes leading to phishing sites.
- 24% of all emails are malicious or unwanted spam.

**Read the full report** [**here**](https://www.barracuda.com/reports/2025-email-threats-report?ref=cybersecstats.com)**.**

### VIPRE Security Group Email Threat Trends Report: 2025: Q1

Email security trends from the first quarter of 2025.

#### Key stats:

- In Q1 2025, 16% of phishing attempts used callback phishing.
- In Q1 2024, 75% relied on malicious links.
- 36% of phishing attacks employ PDF attachments.

**Read the full report** [**here**](https://vipre.com/resources/q1-2025-email-threat-report/?ref=cybersecstats.com)**.**

### KnowBe4 Q1 2025 Phishing Report

Most deceptive email subjects users click in phishing simulations. 

#### Key stats:

- 60.7% of clicked simulations referenced an internal team.
- 61.6% of clicks targeted internal topics or impersonated known brands.
- Top QR scans: HR’s new drug & alcohol policy (14.7%), DocuSign review/sign request (13.7%), Workday birthday message (12.7%).

**Read the full report** [**here**](https://www.knowbe4.com/hubfs/Q1-2025%5FPhishing-Report-Infographic%5FEN.jpg?ref=cybersecstats.com)**.**

## Authentication

### 2025 Hive Systems Password Table

2025 version of the yearly Hive Systems Password Table. 

#### Key stats:

- Cracking passwords with consumer-grade GPUs is now nearly 20% faster than a year ago.
- A basic eight-character, all-lowercase password can be broken in about three weeks on those GPUs.
- With AI-grade hardware, password cracking speeds have surged by over 1.8 billion percent compared to consumer-grade machines.

**Read the full report** [**here**](https://www.hivesystems.com/blog/are-your-passwords-in-the-green?ref=cybersecstats.com).

### Cybernews Password crisis deepens in 2025: lazy, reused, and stolen

Comprehensive study on recently leaked credentials to examine the 2025 password creation trends.

#### Key stats:

- 42% of passwords are 8-10 characters long, with 8-character passwords the single most common.
- People’s names are the second most popular component in passwords.
- Credential-stuffing attacks succeed 0.2–2% of the time - enough to turn millions of login attempts into thousands of hijacked accounts.

**Read the full report** [**here**](https://cybernews.com/security/password-leak-study-unveils-2025-trends-reused-and-lazy/?ref=cybersecstats.com)**.**

### FIDO Alliance World Passkey Day 2025 Consumer Password & Passkey Trends

Insights into authentication preferences.

#### Key stats:

- Over 35% of people had at least one account compromised by password vulnerabilities in the past year.
- 47% of consumers abandon purchases if they forget their password to that specific account.
- 53% of those familiar with passkeys say they’re more secure than passwords.

**Read the full report** [**here**](https://fidoalliance.org/wp-content/uploads/2025/04/World-Password-Day-2025-Final.pdf?ref=cybersecstats.com)**.**

## AI

### Trend Micro AI is Changing the Cyber Risk Game. Are You Keeping Up?

How AI is changing attack surfaces.

#### Key stats:

- 75% of security incidents stem from unmanaged assets.
- Only 43% of organizations use dedicated tools to actively manage their attack surface.
- On average, just 27% of cybersecurity budgets go toward attack surface risk management.

**Read the full report** [**here**](https://www.trendmicro.com/explore/aichangingcyberrisk?ref=cybersecstats.com)**.**

## Industry-specific

### Northern.tech 2025 State of Industrial IoT Device Lifecycle Management

Challenges OEMs face navigating the shift to a software-centric economy. 

#### Key stats:

- OEMs rank security and time-to-market as equally top priorities.
- A fifth of OEMs are rolling out a compliance plan for the EU Cyber Resilience Act.
- A fifth of OEMs aren’t sure which cybersecurity regulations or standards apply to them.

**Read the full report** [**here**](https://northern.tech/dlm-industry-report-2025?ref=cybersecstats.com)**.**

## Other

### KELA Inside the Infostealer Epidemic: Exposing the Risks to Corporate Security

How infostealer malware is fueling credential theft and enabling ransomware attacks. 

#### Key stats:

- Infostealer activity has jumped 266%.
- Most at-risk roles for credential theft: Project Management (28%), Consulting (12%), Software Development (10.7%).
- On average, 2.5 weeks pass between credentials being exposed and a ransomware attack.

**Read the full report** [**here**](https://www.kelacyber.com/resources/research/the-infostealer-epidemic/?ref=cybersecstats.com)**.**

### Zimperium 2025 Global Mobile Threat Report

Mobile threat trends from the past year.

#### Key stats:

- 50% of mobile devices are running on outdated operating systems.
- Over 25% of mobile devices cannot upgrade to the latest OS versions.
- 70% of organizations support BYOD (Bring Your Own Device)

**Read the full report** [**here**](https://lp.zimperium.com/hubfs/Reports/2025%20Global%20Mobile%20Threat%20Report.pdf?ref=cybersecstats.com)**.**

### Robert Half 2025 Building Future-Forward Tech Teams 

Priorities and challenges for technology leaders in 2025\. 

#### Key stats:

- Securing IT systems and data is a top priority for tech leaders in 2025.
- 76% of tech leaders report skills gaps on their teams - 30% of those gaps are in cybersecurity and privacy.

**Read the full report** [**here**](https://www.roberthalf.com/us/en/insights/building-tech-teams?ref=cybersecstats.com)**.**

### Utimaco Insights into PQC Migration from 200+ IT Security Professionals

PQC readiness survey results. 

#### Key stats:

- Quantum computers could crack today’s public-key encryption by 2030, and over half of the most cyber-mature organizations expect to be prepared before then.
- 20% of organizations have already begun migrating to post-quantum cryptography (PQC).
- 63% favor a hybrid approach, blending classical and post-quantum cryptography.

**Read the full report** [**here**](https://utimaco.com/market-trends/2025-utimaco-pqc-readiness-report?ref=cybersecstats.com)**.**

### Seemplicity 2025 Remediation Operations Report

How security teams are adapting their remediation practices in the face of growing exposure management complexity and operational challenges. 

#### Key stats:

- 91% of organizations experience delays in vulnerability remediation.
- 61% of organizations still measure success of vulnerability remediation by the number of vulnerabilities resolved.
- 1 in 5 organizations take four or more days to fix critical vulnerabilities.

**Read the full report** [**here**](https://seemplicity.io/papers/the-2025-remediation-operations-report/?ref=cybersecstats.com)**.**

### OpenVPN & TechTarget's Enterprise Strategy Group (ESG) Secure Access Technology Trends

How small and mid-sized businesses utilize secure remote access strategies. 

#### Key stats:

- 71% of SMBs Use a VPN.
- Organizations were 61% more likely to report using VPNs, compared to all other solutions, to secure internet access.
- Nearly 2/3 of all respondents currently not using a VPN anticipate adopting VPN solutions within the next 12 to 24 months

**Read the full report** [**here**](https://hs.openvpn.net/research-openvpn-esg-state-of-vpn?ref=cybersecstats.com)**.**

### vFunction 2025 Architecture in Software Development

Executive perception vs reality in software architecture management. 

#### Key stats:

- 56% of companies say their architecture documentation is out of date.
- 50% face security or compliance problems because of the disconnect between their documented software architecture and the architecture in production.
- Within the financial services sector, 50% of respondents cite security and compliance issues as their primary concern related to architectural misalignment.

**Read the full report** [**here**](https://vfunction.com/resources/report-2025-architecture-in-software-development/?ref=cybersecstats.com)**.**

### Forescout The Rise of State-Sponsored Hacktivism

Insights into hacktivist activity in 2024\. 

#### Key stats:

- Four state-aligned hacktivist groups claimed 780 attacks in 2024.
- Top targets by country: Ukraine (141), Israel (80), Spain (64).
- Critical infrastructure hit hard: 44 attacks on government/military services, and 21% of all attacks on transportation & logistics.

**Read the full report** [**here**](https://www.forescout.com/resources/the-rise-of-state-sponsored-hacktivism/?ref=cybersecstats.com)**.**

### Cubic³ Consumer and OEM Attitudes to Software-Defined Vehicles Report

Opportunities and challenges facing automotive OEMs as they persuade drivers to buy and subscribe to in-vehicle digital services. 

#### Key stats:

- Globally, 48% of consumers report they worry their car could be hacked.
- 44% of consumers globally do not think OEMs should be able to sell driver data.
- Fewer than one in five (18%) OEMs are currently selling data on.

**Read the full report** [**here**](https://www.cubic3.com/content-library/report-consumer-and-oem-attitudes-to-the-software-defined-vehicle/?ref=cybersecstats.com)**.**

### The Rise of the AppSec Leader: Survey Findings The Rise of the AppSec Leader: Survey Findings

The effects of AI-generated code, open-source and supply-chain threats on organizations. 

#### Key stats:

- 76% of respondents are prioritizing investment in application security posture management (ASPM) for 2025.
- 84% see supply chain vulnerabilities as the biggest threat to their enterprise applications.
- 65% report lacking visibility across their AppSec toolset.

**Read the full report** [**here**](https://www.armorcode.com/blog/rise-of-the-appsec-leader?ref=cybersecstats.com)**.**

### ISACA Taking the Pulse of Quantum Computing

Perceptions and preparations for quantum computing.

#### Key stats:

- 95% of organizations lack a quantum computing roadmap.
- 62% of technology and cybersecurity professionals are worried that quantum computing will break today’s internet encryption.
- Just 5% say quantum computing is a high priority for the near future.

**Read the full report** [**here**](https://www.isaca.org/quantum-pulse-poll?ref=cybersecstats.com)**.**

### Expereo Enterprise Horizons 2025

Trends, priorities, opportunities and challenges faced by enterprises today.

#### Key stats:

- 34% of tech leaders have had to rethink their infrastructure because of rising geopolitical risks.
- 42% say AI governance or ethics concerns are a major barrier to their AI projects.
- 33.3% feel their board has unrealistic expectations about AI’s impact on business performance.

**Read the full report** [**here**](https://www.expereo.com/enterprise-horizons-2025?ref=cybersecstats.com)**.**