At the same time, the economics behind extortion are weakening. Average payments dropped 66% between Q2 and Q3 2025, and only 23% of victims paid anything at all — the lowest rate ever recorded. As revenue shrinks, attackers are turning their attention to the systems that offer the greatest leverage once breached: identity providers.
Identity compromise now sits at the center of modern intrusion campaigns. Remote access compromise represented more than half of all Q3 incidents, and the boundary between social engineering, help-desk manipulation, and technical exploitation has nearly disappeared. Attackers increasingly obtain access not by bypassing controls but by convincing legitimate users or support personnel to provision it for them. In several cases, groups directly approached employees with offers to purchase credentials — a tactic once associated with targeted espionage, now firmly part of commercial ransomware operations.
6 Reasons to Protect Your SaaS Data
FILL THE FORM BELOW
You have been directed to this site by Software Insider. For more details on our information practices, please see our Privacy Policy, and by accessing this content you agree to our Terms of Use. You can unsubscribe at any time.