> ## Content Index
> Fetch the complete content index at: https://www.cybersecstats.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CyberSecStats #31 - Ransomware, AI-written code, and AI bots
- URL: https://www.cybersecstats.com/cybersecstats-31-ransomware-ai-written-code-and-ai-bots/
- Published: 2025-10-06T13:00:27.000Z
- Updated: 2026-02-26T12:48:21.000Z
- Author: Laura M

Hello! 

Laura from CybersecStats here.

Back after a short break, which also involved getting caught up in a real-world ransomware attack (that sent my luggage 1000km away from my destination). 

This week, we have a lot of data to share. 

As always, thank you for subscribing. 

So let's dive in.

## This Month's Eye-Openers

Before we get into the full breakdown, here are three findings that made me do a double-take:

1. **Bot protection in freefall**: Only 2.8% of websites are fully protected against bots in 2025, down from 8.4% last year. We're literally moving backward while AI bots multiply.
2. **Overconfidence in scam**.**detection**: 69% of people think they can spot a scam, but 43% of those "experts" still fell victim in the past year..
3. **IT teams are feeling (very) stressed**: 84% of IT professionals report feeling uncomfortably stressed at work, and 78% fear being personally blamed for breaches.

## Big Picture Reports

### Global Risk Management Survey (AON)

Nearly two decades of tracking what keeps executives up at night.

**The headlines:**

- Cyberattacks remain the #1 business risk globally for the fourth consecutive year.
- The trajectory is up and to the right: #9 in 2015 → #5 in 2017 → #1 in 2021-2025.
- AI ranks #29 on current risk lists.

**Read the full report** [**here**](https://www.aon.com/en/insights/reports/global-risk-management-survey/key-findings?ref=cybersecstats.com)**.**

### 2025 Cybersecurity Threat Report (Comcast Business)

34 billion real-world events from Comcast customers over the past year. 

**The numbers:**

- 19.5 billion resource development events detected.
- 9.8 billion drive-by compromise attempts blocked.
- 4.7 billion phishing attempts targeting human error.

**Read the full report** [**here**](https://business.comcast.com/enterprise/resources/reports/2025-comcast-business-cybersecurity-threat-report/?ref=cybersecstats.com)**.**

### Beyond Big Data: From Roadmap to Reality (Ocient)

How enterprises are moving from AI experimentation to actual deployment. 

**The shift:**

- 75% of data leaders now cite security as a top investment area (up from 55% in 2023).
- 60%+ say data security and privacy is their biggest AI/ML concern.
- 53% would completely change their AI deployment strategy for better security.

**Read the full report** [**here**](https://ocient.com/tech-papers/beyond-big-data-from-roadmap-to-reality/?ref=cybersecstats.com)**.**

### Object First Survey: The Stress Epidemic in IT (Object First)

What happens when risk responsibility grows faster than teams and budgets? 

**The reality check:**

- 84% of IT pros report uncomfortable stress levels due to IT security responsibilities and risks.
- 78% fear personal blame for incidents.
- 55% cite heavy workloads and understaffing as the primary stressors.

**Read the full report** [**here**](https://objectfirst.com/newsroom/press-releases/object-first-survey-84-of-it-pros-feel-uncomfortably-stressed-at-work-amid-rising-cybersecurity-threats/?ref=cybersecstats.com)**.**

### State of Cybersecurity 2025 (ISACA)

ISACA’s 11th annual survey of 4,000 cybersecurity professionals worldwide. 

**The trends:**

- Hands-on experience is now considered "very important" by 60% (down from 73%).
- 30% of organisations are addressing skill gaps through contractors/consultants (down from 36%).
- Just 41% expect budget increases next year (down from 47% last year).

**Read the full report** [**here**](https://www.isaca.org/resources/reports/state-of-cybersecurity-2025%20https://www.isaca.org/resources/reports/state-of-cybersecurity-2025?ref=cybersecstats.com)**.**

### New World, New Rules: Cybersecurity in an Era of Uncertainty (PwC)

Geopolitics is changing the cybersecurity threat landscape in an increasingly unpredictable way. 

**The gap:**

- 60% of leaders prioritize cyber investment due to the geopolitical landscape.
- Only 6% feel confident across all vulnerabilities.
- Cloud and connected product attacks top the "least prepared" list.

**Read the full report** [**here**](https://www.pwc.com/us/en/services/consulting/cybersecurity-risk-regulatory/library/global-digital-trust-insights.html?ref=cybersecstats.com)**.**

### ENISA Threat Landscape 2025 (ENISA)

ENISA report on over 4,875 incidents across the EU between July 2024 and June 2025\. 

**The breakdown:**

- 53.7% of incidents target essential entities (government, transportation, finance, and manufacturing).
- Phishing accounts for \~60% of intrusion vectors.
- 79.4% of attack objectives are driven by ideology.

**Read the full report** [**here**](https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025?ref=cybersecstats.com)**.**

## Ransomware

### Ransomware Impact Report 2025 (Hornet Security)

Insights from IT and security professionals on ransomware attacks, attack vectors, response & awareness. 

**The escalation:**

- 24% of organizations hit by ransomware (up from 18.6% in 2024).
- 26% of incidents now involve compromised endpoints.
- 61% believe AI has significantly increased ransomware risk.

**Read the full report** [**here**](https://www.hornetsecurity.com/en/ransomware-report/?ref=cybersecstats.com)**.**

## AI

### Survey Reveals Consumer Sentiment on AI-Created Apps (Legit Security)

A survey of consumers on their knowledge and concerns about AI in app development.

**Consumer trust:**

- 25% would lose trust if their favorite app uses AI-written code.
- 51% say it wouldn't affect their trust at all.
- 53% think an app downloaded from an official app store is secure by default.

**Read the full report** [**here**](https://www.legitsecurity.com/blog/survey-reveals-consumer-sentiment-on-ai-created-apps?ref=cybersecstats.com)**.**

### Bridging the Trust Gap in the Age of AI (Ping Identity)

A survey into whether consumers trust organisations with their identity data.

**Trust levels:**

- Only 17% fully trust organizations with their identity data.
- 40% would give up social media to avoid identity theft.
- 34% say biometric authentication improves their trust in brands online.

**Read the full report** [**here**](https://hub.pingidentity.com/surveys/4231-consumer-survey-bridging-trust-gap-age-of-ai?ref=cybersecstats.com)**.**

## Bots

### 2025 Global Bot Security Report (DataDome)

DataDome tested nearly 17,000 websites across 22 industries to assess their vulnerability to unwanted bots, agentic AI, and LLM crawlers. 

**The crisis:**

- AI bots and crawlers now make up 1 in 10 verified bot requests.
- LLM crawler traffic jumped from 2.6% to 10.1% in just 8 months.
- Only 2.8% of websites are fully protected (down from 8.4% in 2024).

**Read the full report** [**here**](https://datadome.co/resources/bot-security-report/?ref=cybersecstats.com)**.**

## Authentication

### 2025 Global State of Authentication Report (Yubico)

A snapshot of how people are managing their security at work and at home. 

**The weak link:**

- 54% couldn't identify a phishing email when shown one.
- Gen Z most susceptible: 62% clicked phishing links in the past year.
- Only 48% of companies use MFA across all apps.

**Read the full report** [**here**](https://www.yubico.com/resource/global-state-of-authentication-survey-2025-perception-vs-reality/?ref=cybersecstats.com)**.**

## Consumer Scams

### Scam Intelligence & Impacts Report 2025 (F-Secure)

A deep dive into scams in 2025, including who is most at risk and consumer scam awareness. 

**The overconfidence problem:**

- 69% believe they can spot scams, but 43% fell victim to scams anyway.
- Scam rates in the USA doubled year-over-year.
- 50% willing to pay for scam protection.

**Read the full report** [**here**](https://www.f-secure.com/en/partners/insights/scam-intelligence-and-impacts-report-2025?ref=cybersecstats.com)**.**

### 2025 Consumer Cyber Readiness (Consumer Reports)

U.S. consumer cyber readiness in 2025, with interesting data on how most scams start and who is most frequently impacted. 

**The attack vectors:**

- 46% of Americans encountered a cyberattack or scam attempt.
- 19% of those who encountered attacks lost money.
- 74% of scams started via email, social media, text, or messaging apps.

**Read the full report** [**here**](https://innovation.consumerreports.org/new-report-2025-consumer-cyber-readiness/?ref=cybersecstats.com)**.**

## Data Compliance

### Research into AI and Data Privacy Trend (Perforce Software)

Research on trends related to AI and data privacy. 

**The problem:**

- 60% experienced data breaches in software development, AI, and analytics environments (up 11%).
- 91% think sensitive data should be allowed in AI training (what could go wrong?).
- 84% still allow compliance exceptions in non-production.

**Read the full report** [**here**](https://www.perforce.com/resources/pdx/state-of-data-compliance-and-security-report?ref=cybersecstats.com)**.**

## Mobile VPNs

### Insecure Mobile VPNs: The Hidden Danger (Zimperium)

Insights from Zimperium zLabs analysis of 800 free VPN apps for both Android and iOS.

**The findings:**

- 1% of VPNs are vulnerable to Man-in-the-Middle attacks.
- 25% of iOS VPN apps lack valid privacy manifests.
- 6% of iOS VPNs request restricted private entitlements

**Read the full report** [**here**](https://zimperium.com/blog/insecure-mobile-vpns-the-hidden-danger?ref=cybersecstats.com)**.**

## Regional Spotlight

### The U.S. Business Email Report 2025 (Exclaimer)

Research into the state of business email security among U.S. organizations. 

- 73% experienced email security incidents in the past year.
- 86% say that more than half of business communication flows through email.
- 46% cite external threats (phishing/spoofing) as their top challenge.

**Read the full report** [**here**](https://exclaimer.com/research/us-business-email-report-2025/?ref=cybersecstats.com)**.**

### The UK Business Email Report 2025 (Exclaimer)

Research into the state of business email security among U.K. organisations. 

- 83% suffered at least one email incident.
- 49% hit in just the past 12 months.
- 36% of all security incidents are email-driven.

**Read the full report** [**here**](https://exclaimer.com/research/uk-business-email-report-2025/?ref=cybersecstats.com)**.**

## Industry Deep Dives

### AI in Schools: Balancing Adoption With Risk (Keeper)

Cybersecurity risks associated with Artificial Intelligence (AI) for students, teachers, and administrators. 

**Education under pressure:**

- 41% already experienced AI-related cyber incidents.
- 83% of education leaders are aware of AI cybersecurity risks.
- Only 25% of educators are confident in spotting AI scams.

**Read the full report** [**here**](https://www.keeper.io/hubfs/AI-in-Schools-Report-EN.pdf?ref=cybersecstats.com)**.**

### AI Everywhere. Trust Nowhere? (HCLTech)

The payments industry perspective. 

**Financial services reality:**

- 91% concerned about AI risks.
- 60% find AI fraud detection tools ineffective.
- 49% operate without formal AI policies.

**Read the full report** [**here**](https://www.hcltech.com/payments-research-report?ref=cybersecstats.com)**.**

### From Readiness to Reality: CMMC Compliance in Defense (CyberSheath)

Readiness levels among defense contractors as the Cybersecurity Maturity Model Certification (CMMC) program advances. 

**Defense contractor preparedness:**

- Only 1% fully prepared for CMMC assessments.
- Average annual compliance budget: nearly $50K.
- 90% already suffered losses from cyber incidents.

**Read the full report** [**here**](https://www.hcltech.com/payments-research-report?ref=cybersecstats.com)**.**

### State of Pentesting in Financial Services 2025 (Cobalt)

The security posture of financial services, highlighting persistent challenges in remediation despite relatively strong vulnerability prevention.

**The remediation problem:**

- Median time to fix serious findings: 61 days. In contrast, hospitality fixes serious issues in 20 days.
- Only 66.7% of serious findings get resolved
- Top concern: third-party software vulnerabilities.

**Read the full report** [**here**](https://resource.cobalt.io/state-of-pentesting-financial-services-2025?ref=cybersecstats.com)**.**