Gridware Logo

2025 Cybersecurity Recap

By Ahmed Khanji Updated 18 December 2025 3 min read

in 𝕏
2025 Cybersecurity Recap

Looking Back at 2025

What stood out this year instead was how consistent the same problems remained, even as the targets changed. Across all industries, attackers relied on access that already existed and timing that worked in their favour.

Third Party Access

The year opened with a clear signal. Qantas confirmed a cyber incident that exposed the personal details of millions of customers after attackers accessed an offshore call centre platform. Core systems were unaffected, but the data still mattered. Names, contact details, birth dates, and frequent flyer numbers were enough to support follow on attacks.

Later in the year, incidents like the Google CRM breach and the iiNet customer data exposure showed the same issue from different angles. Organisations kept relying on external platforms for customer support, marketing, and operations. Those platforms sat outside core infrastructure but held data attackers were happy to take.

By the end of 2025, it was clear that third party access was one of the most reliable ways in.

Ransomware Focused on Opportunity

In July, the SafePay ransomware attack on Ingram Micro disrupted global operations after attackers likely entered through a VPN platform. The concern was not necessarily the outage, but the level of administrative access Ingram held across customer environments.

Later in the year, we looked at how ransomware groups were deliberately timing attacks around weekends, holidays and periods of reduced coverage in Australia. Attackers were watching how organisations operate and deliberately chose moments when response would be slowest.

Social Engineering Kept Working

Several of the most impactful incidents in 2025 didn’t involve malware or software exploits at all. The Tea app breach, which led to the leak of over 13,000 private photos relied entirely on abusing SMS verification flows. No systems were breached and users were only ‘tricked’ into handing over MFA codes. Nevertheless, the outcome was still severe.

Throughout the year, Scattered Spider remained active by calling help desks, impersonating staff, and exploiting urgency. In some cases, these attacks moved from initial access to ransomware in less than a day. We explored these tactics in more detail during our Scattered Spider webinar earlier in the year.

Identity and Access Management

Across almost every story we covered, compromised identity played a role. Whether it was a stolen staff login, a reset MFA token, a SIM swapped phone number, or over privileged vendor access, attackers repeatedly entered environments through accounts that should have been better protected. By November, it was hard to ignore the gap between how confident organisations felt about their cyber posture and how incidents actually unfolded.

Heading Into 2026

As 2026 begins, the lessons from this year are hard to ignore. The challenge now is whether they lead to real change, or whether attackers will be allowed to keep relying on the same access paths they’ve been using all along.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.