Russian IT specialists and cybersecurity experts have identified the key cyber threats of 2025. According to a study by “K2 Cybersecurity,” part of the K2Tech ecosystem, ransomware viruses have emerged as the most dangerous threat to Russian companies. The survey included representatives from 104 organizations across key sectors of the economy, including finance, oil and gas, and telecommunications.
Ransomware: The Primary Threat
According to the research, 64% of respondents identified ransomware as the main cyber threat of 2025. These malicious programs are designed to encrypt a company’s critical data and demand a ransom for its decryption. As Alexander Shilov, head of network security at K2 Cybersecurity, pointed out, the consequences of such attacks can be especially devastating for industrial enterprises. If ransomware infiltrates from the corporate network into the production environment, it can bring technological processes to a complete halt, leading to unpredictable losses.
Other Notable Threats
The second most significant threat is targeted attacks (APT attacks), cited by 28% of respondents. These attacks involve long-term preparation and aim to gather confidential information or damage infrastructure. In third place are DDoS attacks, mentioned by 8% of participants. Interestingly, DDoS attacks were considered the top threat last year (62%), indicating a major shift in the cyber threat landscape.
Changing Priorities in Cybersecurity
The shift in focus from DDoS attacks to ransomware reflects the evolution of cybercriminal tactics. While DDoS was previously the main tool for disrupting systems, attackers now more frequently deploy ransomware for financial extortion or deliberate infrastructure damage. This trend is backed by other studies: for instance, the company F6 recorded over 500 ransomware attacks in Russia during 2024 — one and a half times more than in 2023.
The Need for Comprehensive Protection
Experts emphasize that recovery from ransomware attacks is a complex and highly specific process that requires pre-established protocols. Alexander Shilov noted that being prepared to restore systems is just as crucial as their preventive protection. Companies are advised to implement a comprehensive security strategy, including regular software updates, employee training in phishing prevention, and the use of professional solutions to protect against DDoS attacks and malware.
Conclusion
The cyber threat landscape in 2025 continues to grow more complex, with ransomware clearly dominating the field. Russian IT specialists urge companies to strengthen their cybersecurity measures, focusing not only on preventing attacks but also on preparing for their aftermath. The advancement of security technologies and the improvement of employees’ digital literacy will be key factors in the fight against cybercrime in the near future.






