Global Overview

In October 2025, the global volume of cyber attacks continued its upward trajectory. Organizations worldwide experienced an average of 1,938 cyber attacks per week, marking a 2% increase from September and a 5% rise compared to October 2024.

Check Point Research data reveals that this steady escalation underscores a persistent and evolving cyber threat landscape fuelled by the growing sophistication of ransomware operations and the expanding risks associated with the adoption of generative AI (GenAI).

Industry Insights: Education

The education sector once again topped the list of most-targeted industries, enduring an average of 4,470 attacks per organization per week, a 5% increase year-over-year.

Following in the top attacked sectors were telecommunications with 2,583 weekly attacks (up 2% YoY) and government organizations, which averaged 2,550 attacks per week, representing a 2% decline from last year.

Important to also note the high 40% YoY increase in the hospitality sector, as we near the holiday season, climbing from 8th to 5th in the most attacked industries this month.

Regional Breakdown: Latin America Leads, North America Surges

Latin America recorded the highest attack frequency, with an average organization in the region facing 2,966 weekly attacks, a 16% rise compared to October 2024. Africa followed with 2,782 attacks per organization per week (down 15% YoY), and APAC recorded 2,703 (down 8% YoY).

However, North America saw the sharpest rise, with attacks increasing 18% year-over-year, indicating a renewed focus on critical infrastructure and business services in the region.

European organization also experienced an uptick from last year, with a 4% increase, similar to the global average.

Region Weekly Attacks per Organization YoY Change
Latin America 2966 +16%
Africa 2782 -15%
APAC 2703 -8%
Europe 1616 +4%
North America 1464 +18%
GenAI Security Risks Intensify

As enterprise use of generative AI tools becomes ubiquitous, organizations face growing exposure to sensitive data risks.

In October, Check Point observed that 1 in every 44 GenAI prompts submitted through enterprise networks posed a high risk of sensitive data leakage. Alarmingly, 87% of organizations using GenAI tools regularly were impacted by this type of exposure risk. An additional 19% of prompts contained potentially sensitive, private or proprietary information.

These risks in the use of generative AI tools coincide with an 8% increase in average daily usage among corporate users. Notably, there’s a relative increase in the exposure of source code and credentials compared to the other data types such as PII and Financial information. While some usage occurs through managed tools, organizations still average 11 different GenAI tools per month – most of which are likely unsupervised.

Ransomware Escalation: 48% YoY Spike

Ransomware activity saw a dramatic increase in October, with 801 reported attacks, representing a 48% surge compared to the same month in 2024.

North America accounted for the majority of incidents (62%), followed by Europe (19%). The United States remained the primary target, responsible for 57% of reported victims and a staggering 56.8% month-over-month increase.

Other heavily impacted countries included Canada (5%), France (4%), and the United Kingdom (3%).

Across industries, business services bore the brunt of ransomware activity (12% of total victims), followed by consumer goods & services (10.5%) and industrial manufacturing (10.4%).

Most Active Ransomware Groups

The Qilin ransomware group dominated October’s threat landscape, responsible for 22.7% of all published attacks.
Originally operating as “Agenda,” Qilin has evolved into a sophisticated ransomware-as-a-service (RaaS) operation with extensive affiliate support and a Rust-based encryptor.

Akira ranked second with 8.7% of the published attacks, continuing to target business and industrial sectors using both Windows and Linux payloads. Sinobi, a newer entrant emerging in mid-2025, accounted for 7.8% of incidents, with a notable focus on U.S.-based healthcare targets.

Conclusion

October 2025’s cyber statistics highlight a world where threat actors are increasingly opportunistic, leveraging geopolitical instability, AI-powered automation, and double-extortion tactics to expand their reach.

As ransomware groups evolve and GenAI risks proliferate, organizations must strengthen their threat prevention, data security, and AI governance strategies to stay ahead of adversaries.

 

 

You may also like