Cyber Defence: Plenty of Trouble for the Financial Industry in 2025
Technological advancements in IT continue unabated, and so do cyber threats. In its latest report, Crimeware and Financial Cyberthreats in 2025, the security software company Kaspersky makes predictions about the evolving dangers, particularly for companies in the financial sector.
An increasing threat from ransomware and info-stealers is forecasted. The reasons cited include advancements in quantum computing, artificial intelligence (AI), and machine learning (ML).
AI in Cyber Defense
AI and ML are also expected to play a larger role in cyber defense. They can accelerate anomaly detection and reduce analysis time through predictive capabilities. Simultaneously, reactive measures can be automated, and strategies to counter emerging threats can be strengthened.
Kaspersky experts anticipate a rise in attacks on mobile devices next year, while banking and financially motivated malware attacks are expected to decline.
Poisoned Data and Ransomware-as-a-Service
A change is being observed in ransomware cases. Instead of merely encrypting data, attackers are covertly manipulating database information or inserting false data. «This technique, called ‘data poisoning,’ can call into question the accuracy of an entire company’s data,» the experts write.
The development of quantum-secure ransomware or «Ransomware-as-a-Service» represents a growing threat. Such packages, available for as little as $40, enable even less experienced actors to carry out attacks.
Attacks based on stolen data are also expected to increase. Info-stealer programs will continue to adapt, withstand law enforcement pressure, and employ new techniques.
Instant payment systems from central banks and open banking initiatives are also considered vulnerable. Cybercriminals could gain access to sensitive data through these systems.
Kaspersky also anticipates the emergence of new blockchain-based threats. New blockchain protocols are likely to arise, and criminals could spread malware based on these protocols and use it for various purposes.
Trust No One
The IT security company recommends a strategy that includes a combination of threat intelligence, predictive analytics, continuous monitoring, and a zero-trust approach. Regular employee training is also crucial. «An uninformed workforce is one of the most common initial attack vectors that can lead to serious financial losses for a company.»








