Full Report
Learn top cybercrime trends from Huntress’ 2025 survey of more than 500 American IT professionals. Plus, learn tips for improving your cybersecurity.
Analysis Summary
# Industry News: Huntress 2025 Report Reveals Shift to Data Extortion and RMM Exploitation
## Summary
The Huntress 2025 Cybercrime Report reveals that while 54% of American organizations faced malware attacks last year, threat actors are pivotally shifting strategies from traditional encryption toward data theft and extortion. Despite these evolving threats, IT professionals express high confidence in their defensive capabilities, even as cybercriminals increasingly leverage legitimate Remote Monitoring and Management (RMM) tools for lateral movement.
## Key Details
- **Date:** July 17, 2025
- **Companies Involved:** Huntress (Primary Researcher)
- **Category:** Market Analysis / Industry Research
## The Story
Based on a survey of over 500 American IT professionals, the 2025 report outlines a maturing cybercrime economy where financial gain remains the primary motivator. The research highlights a significant evolution in attacker "tradecraft." Rather than simply locking systems with ransomware, hackers are now prioritizing the theft of sensitive information to use as leverage in extortion schemes.
A critical finding is the misuse of Remote Monitoring and Management (RMM) tools. Attackers are increasingly "living off the land," using the very tools IT teams use for maintenance to maintain persistence and move through networks undetected. While malware (54%) and phishing (44%) remain the dominant entry vectors, the survey notes a rise in Business Email Compromise (36%) and supply chain vulnerabilities (24%), indicating that attackers are targeting the entire ecosystem of business operations.
## Business Impact
### For the Companies Involved (Huntress)
- Positions Huntress as a thought leader in the SMB and MSP (Managed Service Provider) space.
- Validates their focus on Managed Endpoint Detection and Response (EDR) by highlighting that 32% of threats now come from insiders or credential misuse.
### For Competitors
- Competitors in the EDR/MDR space must pivot their marketing from "anti-ransomware" to "anti-extortion" and "RMM monitoring" to remain relevant to shifting buyer concerns.
### For Customers
- Organizations are facing average annual losses between $100,001 and $500,000 due to cyber incidents.
- There is a growing need for customers to re-evaluate their trust in remote access tools and implement stricter MFA and security awareness training.
### For the Market
- The formalization of Ransomware-as-a-Service (RaaS) and Initial Access Brokers (IABs) has lowered the barrier to entry for criminals, leading to a more crowded and dangerous threat landscape for healthcare, education, and government sectors.
## Technical Implications
The report emphasizes the decline of "loud" encryption in favor of stealthy persistence. Technologically, this requires a shift from signature-based malware detection to behavioral analysis that can identify when legitimate administrative tools (like RMM software) are being used for malicious lateral movement.
## Strategic Analysis
- **Market Positioning:** Huntress is doubling down on the "human-led" defense narrative, countering the trend of total reliance on automated AI tools.
- **Competitive Advantage:** By identifying the specific shift toward data extortion, they provide actionable intelligence that helps MSPs justify security spend to their SMB clients.
- **Challenges:** The "confidence gap"—where 90% of IT pros feel secure despite high infection rates—suggests a potential market complacency that could delay necessary security investments.
## Industry Reactions
- **Analyst Opinions:** Analysts view the shift toward extortion as a response to better backup and recovery solutions; if companies can restore from backups, attackers must steal data to maintain leverage.
- **Expert Commentary:** Lindsey O'Donnell-Welch (Huntress) notes that the "versatility" of malware allows criminals to achieve multiple objectives—access, theft, and disruption—with a single tool.
## Future Outlook
- **Predictions:** Expect a continued rise in "identity-based" attacks rather than "file-based" attacks, as hackers focus on credential stuffing and account takeovers.
- **What to Watch for:** The integration of AI by threat actors to personalize phishing at scale, and how organizations will balance the benefits of remote work with the risks of expanded attack surfaces.
## For Security Professionals
Practitioners should prioritize "hardening" RMM tools and auditing remote access logs. The data suggests that MFA and regular system patching are no longer "optional extras" but the baseline requirements for preventing the most common 2025 threat vectors.