Looking Back at 2025
What stood out this year instead was how consistent the same problems remained, even as the targets changed. Across all industries, attackers relied on access that already existed and timing that worked in their favour.
Third Party Access
The year opened with a clear signal. Qantas confirmed a cyber incident that exposed the personal details of millions of customers after attackers accessed an offshore call centre platform. Core systems were unaffected, but the data still mattered. Names, contact details, birth dates, and frequent flyer numbers were enough to support follow on attacks.
Later in the year, incidents like the Google CRM breach and the iiNet customer data exposure showed the same issue from different angles. Organisations kept relying on external platforms for customer support, marketing, and operations. Those platforms sat outside core infrastructure but held data attackers were happy to take.
By the end of 2025, it was clear that third party access was one of the most reliable ways in.
Ransomware Focused on Opportunity
In July, the SafePay ransomware attack on Ingram Micro disrupted global operations after attackers likely entered through a VPN platform. The concern was not necessarily the outage, but the level of administrative access Ingram held across customer environments.
Later in the year, we looked at how ransomware groups were deliberately timing attacks around weekends, holidays and periods of reduced coverage in Australia. Attackers were watching how organisations operate and deliberately chose moments when response would be slowest.
Social Engineering Kept Working
Several of the most impactful incidents in 2025 didn’t involve malware or software exploits at all. The Tea app breach, which led to the leak of over 13,000 private photos relied entirely on abusing SMS verification flows. No systems were breached and users were only ‘tricked’ into handing over MFA codes. Nevertheless, the outcome was still severe.
Throughout the year, Scattered Spider remained active by calling help desks, impersonating staff, and exploiting urgency. In some cases, these attacks moved from initial access to ransomware in less than a day. We explored these tactics in more detail during our Scattered Spider webinar earlier in the year.
Identity and Access Management
Across almost every story we covered, compromised identity played a role. Whether it was a stolen staff login, a reset MFA token, a SIM swapped phone number, or over privileged vendor access, attackers repeatedly entered environments through accounts that should have been better protected. By November, it was hard to ignore the gap between how confident organisations felt about their cyber posture and how incidents actually unfolded.
Heading Into 2026
As 2026 begins, the lessons from this year are hard to ignore. The challenge now is whether they lead to real change, or whether attackers will be allowed to keep relying on the same access paths they’ve been using all along.



