SHARE
Facebook X Pinterest WhatsApp

Threat Group Activity Tripled in 2025, Dataminr Study Finds

Threat actor activity surged 225% in 2025, with alerts tripling and identity-based attacks rising, according to Dataminr’s Cyber Threat Landscape Report

Written By
thumbnail
Luis Millares
Luis Millares
Feb 18, 2026
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Threat group activity tripled in 2025 compared to 2024, according to Dataminr’s inaugural Cyber Threat Landscape Report.

Designed to provide cybersecurity teams with actionable insight into an evolving threat landscape, the report aims to help professionals identify and understand trends that can strengthen ongoing protection efforts for their organization.

Significant uptick in alert and threat activity

The report found a 225 percent surge in threat actor activity in 2025, with average monthly alerts rising from 1,490 to 4,840. The analysis was based on Dataminr’s tracking of 6,500 threat actors to identify major shifts in attacker behavior.

“The problem is bigger than alert fatigue. As threat actors ramp up their attacks, it’s becoming increasingly difficult for security analysts to keep up,” said Dataminr in an official statement.

Dataminr also observed that several threat actors in 2025 re-exploited initial vendor fixes to compromise victims.

One example cited was Microsoft SharePoint vulnerabilities CVE-2025-49706 and CVE-2025-49704, which were reportedly bypassed within days of the July patches. That led to secondary CVEs, CVE-2025-53770 and CVE-2025-53771, tied to the same underlying flaws.

“These recurring bypasses highlight a systemic failure in traditional vulnerability management. Organizations are shifting to prioritize fixes based on real-world exploitability and live telemetry rather than static CVSS scores,” Dataminr said.

Advertisement

Identity-focused attacks and other key findings

Alongside the rise in alerts, the study highlighted the growing prevalence of “identity-centric” tactics. It identified a shift away from traditional exploits toward identity-focused attacks, with people increasingly serving as the primary entry point through AI-enhanced social engineering. 

The report cited Scattered Lapsus$ Hunters (SLH) as one example, noting the group’s use of AI-enhanced voice phishing (vishing) to bypass technical security controls.

Other key findings include:

  • Qilin emerged as the most active ransomware group of the year, consolidating the market by offering high affiliate payouts and a stable platform.
  • 2025 marked a shift from frequent cyber losses to fewer events with materially larger financial impacts.
  • Dwell time continued to collapse, with the window between initial targeting and data exfiltration effectively shrinking to near zero.
  • Digital risk and exposure grew sharply, as organizations faced an overwhelming volume of external threats beyond their immediate infrastructure.

In terms of methodology, the Cyber Threat Landscape Report used both qualitative and quantitative methods and relied primarily on data from Dataminr and ThreatConnect. This included more than 43 terabytes of event, threat, and risk signals ingested by Dataminr daily.

Last year, Dataminr acquired cybersecurity platform ThreatConnect for $290 million, aiming to combine real-time event intelligence with deeper contextualization capabilities. Read more about the move and how it’s expected to strengthen resilience across industries.

thumbnail
Luis Millares

Luis Millares has extensive experience reviewing virtual private networks (VPNs), password managers, and other security software. He has tested and reviewed numerous forms of tech, covering consumer technology like smartphones and laptops, all the way to enterprise software and cybersecurity products. He has authored over 450 online articles on technology and has worked for the leading tech journalism site in the Philippines, YugaTech.com. He currently contributes to the Daily Tech Insider newsletter, providing well-researched insights and coverage of the latest in technology.

Recommended for you...

Genetec Adds Investigation Capabilities in Security Center SaaS
Jordan Smith
Feb 19, 2026
Cloud Range Rolls Out Validation Range for Secure AI Testing
Luis Millares
Feb 18, 2026
Vectra AI Report Warns AI Gains Aren’t Boosting Resilience
Luis Millares
Feb 16, 2026
Pathlock CEO Talks Identity in the AI Era
Victoria Durgin
Feb 13, 2026
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.