Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Fortinet: ransomware cases jump 389% as AI speeds attacks

Global ransomware cases rose 389% year on year to 7,831 in 2025 as cybercriminals used AI and moved faster to exploit software vulnerabilities, according to cybersecurity company Fortinet.

Manufacturing recorded the highest number of attacks at 1,284 cases, followed by business services with 824 and retail with 682.

Fortinet said exploit activity targeting software vulnerabilities increased 25% to about 1,219 cases.

The company also said the average time between a vulnerability disclosure and the first attack attempt has narrowed to between 24 and 48 hours, down from 4.76 days.

Fortinet vice president Derek Manky said threat actors are beginning to use agentic AI to automate more advanced cyberattacks.

🔗 Source: The Chosun Daily

🧠 Food for thought

Implications, context, and why it matters.

Stolen identities now drive more cybercrime than software bugs

  • Identity-based attacks have moved ahead of software exploit-led cloud incidents 1.
  • In 2025, most confirmed cloud incidents came from stolen, exposed, or misused login credentials. Hospitals, physician clinics, and retail businesses ranked among the top targets 1.
  • The dark web market is well established. “Stealer logs,” datasets built by malware that steals usernames, passwords, cookies, and device data, made up 67.12% of advertised and shared datasets. That was higher than “combolists,” or bundled username-password lists, at 16.47%, while leaked credentials reached 5.96% 1.
  • AI-enabled cybercrime tools such as WormGPT and FraudGPT, malicious chatbot-style tools sold for phishing, fraud, and other abuse, are marketed as services and products. BruteForceAI is part of the same market, and these “crime service kits” track with a rise in ransomware victims 1.

Cybercrime now runs like an industry, pushing defenders to move faster

  • Cybercrime now works as a connected system. Groups cover the full life cycle. They include access brokers who sell entry into hacked systems. They also include botnet operators who run networks of infected devices 2.
  • Speed now shapes risk. Newly disclosed vulnerabilities can be exploited within hours or days rather than weeks 3.
  • Fortinet says security teams need a defense model built for automation. It also says teams need AI-enabled tools that can respond at the pace of current threats 2.
  • Public-private work is part of the response. The World Economic Forum’s Cybercrime Atlas maps cybercriminal networks. A joint effort led by INTERPOL, the international police organization, and supported by Fortinet helped take down a cybercriminal network in Operation Red Card 2.0 2.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.