Cyber Security Insights January 2025

Cyber Security Insights January 2025

Written by Bryan Altimas

Happy New Year! Most of us are well into 2025 now and hopefully those goals are being realised. Of course, the threat actors will have been making their resolutions for 2025. We take a look at what may be coming our way in terms of cyber security and data protection risks this year.

Artificial Intelligence (AI)

AI is both a threat and an ally. Threat actors are using it to increase the frequency and accuracy of attacks. AI is used in cyber security to more quickly identify threats by querying vast data sets and automating mundane tasks freeing up more time for reviewing and understanding real suspected threats and vulnerabilities.

The Risks of AI

We think there are 3 channels of risks:

  1. How we use AI and how our data is used by the AI model. Self created threats.
  2. AI hallucination
  3. How the threat actors are using AI.

How We Use AI

Our use of AI will increase dramatically this year together with the risks it poses to our organisations. How many of us really understand what happens to the data we give AI access to. Have we looked at the terms and conditions of the vendor?

Obtain reasonable assurance that your data is not taken into the machine learning of the model. We have seen cases where a company has purchased an AI model and thought data input was for their own use. All the data input was actually taken into the wider machine learning.

An example from publicly available AI but the principle could be the same for a SaaS model. Many people produced their LinkedIn 2024 activity summary by using one of several AI models that took your LinkedIn data from your account and produced a summary of your activity. Are they aware they licensed these AI's to use their 2024 data and future data in the ML and for them to earn revenue from their data?

We are sure their will be many more cases of AI not observing intellectual property and copyright law.

AI Hallucination

AI hallucination is when AI erroneously makes up data and creates misinformation. Apple are a great case study. Apple AI was launched in November 2024. It looks at the news sites of the world's media and produces summaries. The BBC has complained to Apple that their AI inaccurately summarised a news article about the assassination of the United Healthcare CEO saying that the alleged assassin had shot himself. He had not. The second BBC complaint said that Apple AI said that Luke Littler had won the world darts championship hours before the match took place.

The New York Times has also had reason to complain. The AI summary reported that Benjamin Netanyahu had been arrested. He had not.

Not only does it reduce trust in Apple's product, in this case, but trust is diminished in the companies that are the source of the original data.

Threat Actors Use of AI

We will see threat actors increasing their usage of AI to create more convincing phishing, vishing or deep fake voice cloning, SMS and social engineering attacks.

State actors and cyber criminals will escalate use of deep fakes for identity theft, fraud and bypassing know-your-customer security requirements.

Malicious actors will experiment with LLMs and deepfake applications for vulnerability research, code development, and reconnaissance.

There will be development of LLMs that lack security guardrails, allowing threat actors to query for illicit topics without limit.

As AI capabilities become more widely available throughout 2025, enterprises will increasingly struggle to defend themselves against these more frequent and effective compromises.

Concerned about your organisation's use of AI? Contact us by email at info@riversidecourtconsulting.co.uk or by LinkedIn messenger with the message "AI concerns"

State Actors in 2025

The UK experiences daily attacks from nation states for various reasons. Most are detected by GCHQ but, inevitably some get through. Many of you are probably thinking why would a nation state bother with me. You may not be the target but you could be impacted by the fallout of a nation state attack.

There are the big 4 nation state attackers and each has their own reason for attacking:

  • China
  • Iran
  • North Korea
  • Russia

China

People's Republic of China threat actors will continue to aggressively attack the west, Taiwan and other Asian countries bordering the South China Sea with disinformation and deep fake impersonation attacks designed to destabilise public opinion.

Cyber attacks against critical national infrastructure and technology companies exploiting vulnerabilities may be laying the groundwork for future destructive attacks. Technology companies are targeted as a gateway into other organisations, such as government departments, to gather information.

Chinese threat actors will continue to be innovative and target devices where Endpoint Detection and Response solutions are not readily available and forensics and incident response are difficult, such as firewalls and VPN gateways. The malware they deploy camouflages their activity and hinders investigation efforts.

Iran

As long as the Israel - Hamas conflict continues Iranian cyber attacks will be mainly focused on Israel in support of Hamas. Other Iranian strategic attacks will target telecommunications companies and governments across the Middle East and North Africa. Some dabbling in cyber crime will also occur to raise much needed currency.

North Korea

Geopolitics and economic need will be the focus of North Korean cyber attacks in 2025. Cyber espionage operations to support the geopolitical goals of the country will include targeting government, defence, education, think tank targets with a focus on South Korea and the US with less focus on the UK, Germany, Australia and, ironically, China and Russia.

Supply chain compromises using trojanised open source software packages in social engineering operations targeting software developers are likely to continue this year.

North Korea is in dire need of finance and threat actors will continue to pursue cryptocurrency theft. Revenue generation will also be pursued by IT workers with fake identities applying for high paying software development jobs in mainly US companies and once recruited they will also leverage privileged access to their employers' systems to enable malicious activity.

Russia

Ukraine is likely to remain a high priority of Russia's cyber attacks, cyber espionage and disinformation during 2025.

Globally Russian cyber espionage is likely to continue to target governments, politicians, government workers, journalists, media outlets and technology companies in Europe and NATO countries. Disinformation operations will use a variety of tactics to promote Russian interests and undermine opponents and capitalise on high profile events as we observed with the Paris Olympics in 2024.

Are you concerned you could become a victim of a nation state attack. Contact us by LinkedIn messenger or by email at info@riversidecourtconsulting.co.uk with the message nation state.

Ransomware

The most destructive type of cybercrime, ransomware and data theft extortion, will continue in 2025 at similar high volumes and levels of destruction. Attacks in healthcare will continue because of their high impact on the organisation attacked and their patients. However, ransomware and data theft extortion are a global menace affecting every industry vertical.

The number of data leak sites on the dark web doubled in 2024 over 2023 and the emergence of ransomware as a service (RaaS) highlights the thriving and prolific nature of the ransomware and data theft extortion landscape.

Infostealer Malware

Infostealer malware delivered through phishing attacks to steal logon credentials although not new had a surge in sophistication and effectiveness. In 2024 Microsoft blocked 7,000 password attacks per second highlighting the persistent and pervasive nature of these threats. 2025 will see a continuation of these attacks with infostealers a primary vector to obtain them, particularly in environments where multi-factor authorisation is not enforced.

The sophistication surge introduced anti-evasion techniques and capabilities to bypass Endpoint Detection and Response, rendering them an even more formidable challenge in the threat landscape.

Compromised Identities in Multi Cloud Environments

In 2025 it will be critical for organisations to secure their identities as the move towards multi-site and bring your own device environment and multi-cloud environments continues. It is important that organisations align processes, security controls, and validation efforts to minimise the overall impact of a single compromised identity resulting in downstream consequences, and also to reinforce the strategy of strong authentication.

At a minimum the use of password managers to enforce the use of strong and unique passwords for each account combined with multi-factor authorisation (MFA). As the roll out of pass keys gathers pace the use can only be encouraged. Further mitigation can be enforced with shorter session lifetime.

If a cloud service does not offer MFA the organisation must seriously consider the risks and benefits of its continued use.

The Cyber Landscape

In 2025 there will be the democratisation of cyber attack capabilities as the barriers to entry continue to lower. RaaS and other "as a service resources", e.g. phishing, allow less skilled threat actors to successfully enter the arena.

Concerned about your cyber security in 2025? Contact us via LinkedIn messenger or by email at info@riversidecourtconsulting.co.uk with the message cyber25.


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right