An analysis of X‑Force Incident Response engagements highlights the industries most impacted by cyberattacks in 2025.
Manufacturing remained the most-targeted sector, representing 27.7% of all incidents. Its reliance on interconnected supply chains, valuable intellectual property and complex operational technology environments continues to make manufacturing a prime focus for threat actors.
Following close behind, the finance and insurance sector accounted for 27% of incidents, reflecting persistent adversary interest in financial data, capital access, and extortion opportunities.
Professional, business, and consumer services accounted for 9% of incidents, reflecting growing exposure tied to third‑party service operations, supply chain integration and customer‑facing platforms. Both the energy and transportation services sectors each represented 8% of incidents, underscoring persistent risks to critical infrastructure, industrial control systems and logistics networks, as these industries continue to digitize core operations.
These patterns illustrate how threat actors gravitate toward industries with valuable data, operational complexity and opportunities to create financial or strategic disruption. Addressing this landscape requires organizations to implement tailored risk assessments, enhance security investments aligned to industry needs and strengthen cooperative defense efforts across partners and supply chains. By doing so, critical sectors can better withstand emerging threats and build more durable cyber resilience.
For the fifth consecutive year, the manufacturing sector remained the most attacked industry, representing 27.7% of all incidents within the top industries. This ongoing targeting reflects its critical role in global supply chains and the high value of operational and intellectual property data.
Attackers leveraged several methods to breach manufacturing systems, with exploitation of public-facing applications (32%) emerging as the most common vector. Valid accounts (domain) (16%) and external remote services (11%) were also prominent, reflecting attackers’ reliance on exploiting misconfigured or insufficiently secured access points.
After gaining access to manufacturing environments, attackers focused on establishing control, compromising systems or exfiltrating valuable data. Malware accounted for 45% of observed actions on objective, indicating a strong emphasis on operational disruption and financial extortion. The use of legitimate tools (31%) also stood out, showcasing the value of compromised access in enabling further attacks.
Manufacturing organizations experienced significant impacts from these attacks. Data theft (40%) was the most prevalent, targeting both financial assets and intellectual property such as trade secrets. Credential harvesting (10%) further increased risks, enabling persistent attacker access. The sector also faced challenges with brand reputation damage (20%), which underscores the broader business and social consequences of cyber incidents.
The Asia-Pacific region continued to be the epicenter of manufacturing-related incidents, accounting for 68% of attacks. North America (23%) followed as the second most impacted region, reflecting the economic significance of its manufacturing operations. Europe (5%) and Latin America (2%) also faced activity, with a slight decrease over the past year.
The Finance and insurance sector ranked as the second most attacked industry for the fifth year in a row—trailing only manufacturing—and accounted for 27% of all incidents in 2025. The sector continued to be a high-value target given its critical role in the global economy and the significant value of its financial data and assets.
Attackers primarily breached finance and insurance systems through exploiting public-facing applications (36%). Valid accounts (domain) (14%) and external remote services (14%) were also common tactics, highlighting the need for robust credential and access management practices, as well as monitoring remote access vulnerabilities.
Once attackers were inside, the focus was on reconnaissance and data exfiltration. The most observed action on objective was the deployment of malware (54%) and the use of legitimate tools (29%).
The sector faced substantial impacts from these incidents. Credential harvesting (46%), and data leaks (31%) were the most common, with attackers focusing on stealing and leaking sensitive information and compromising account credentials. Other impacts, such as brand reputation (15%), highlighted additional attempts to tarnish brand identity and overall reputation within the sector.
Regionally, Europe experienced the highest volume of incidents (35%), likely driven by the region’s concentration of major financial institutions, regulatory complexity across jurisdictions and its central role in global financial markets. The Asia-Pacific (19%) region followed, driven by its economic growth and expanding digital footprint. North America (19%) also remained a major target this year, tying the Asia-Pacific region. Latin America (16%) faced notable activity with fewer cases compared to the prior year, while the Middle East and Africa only experienced 12% of incidents in 2025.
The professional, business, and consumer services sector ranked as the third most attacked industry for the second year in a row, accounting for 9% of all incidents. This diverse sector—comprising professional services such as consultancies, management companies and law firms; business services such as IT, technology and public relations firms; and consumer services such as real estate, entertainment and recreation—remains a high-value target due to its reliance on sensitive data and operational dependencies.
Attackers employed varied tactics to achieve their objectives, with malware (50%) emerging as the most common action observed. Server access (25%) and email thread hijacking (25%) were also prominent, reflecting attackers’ interest in establishing control and enabling further malicious activity.
Exploiting public-facing applications (33%), external remote services (33%) and drive-by compromise (33%) were the three initial access vectors affecting this industry.
The primary impact of these incidents was data theft (33%), emphasizing the attackers’ intent to exfiltrate and monetize sensitive data. Credential harvesting (17%), data leak (17%), extortion (17%) and data destruction (17%) also highlighted the financial and reputational risks posed to organizations in this sector.
Regionally, Europe experienced the highest volume of incidents, accounting for 50% of cases, followed by North America (21%) and Asia-Pacific (14%). Activity in the Middle East and Africa (7%) and Latin America (7%) was lower, reflecting regional disparities in targeting and attacker focus.
The energy sector—which includes electric utilities, oil and gas companies, and related industries—ranked as the fourth most targeted industry, accounting for 8% of all incidents. Energy infrastructure remained a persistent target due to its critical role in sustaining global operations and the outsized impact even limited disruptions can cause.
Attackers employed a diverse range of tactics, with server access (29%) and malware (29%) among the most observed actions on objectives. Additional techniques included business email compromise, defacement and use of legitimate tools (14% each), showcasing a broad spectrum of strategies aimed at gaining access and control, stealing data and monetizing breaches.
The primary initial access method used was exploitation of public-facing applications (50%). There was also an equal distribution across additional access vectors such as trusted relationships, supply chain compromise (software supply) and phishing (spearphishing) (17% each). This distribution highlights attackers' adaptability and their focus on exploiting human error and vulnerabilities in exposed systems. Concerning the impact on the energy industry, there is an equal split between credential harvesting and data leaks.
The Asia-Pacific region experienced the highest volume of incidents, accounting for 27% of cases, with Europe following behind in second place at 22%. Other regions, including Latin America (17%), North America (17%) and the Middle East and Africa (17%), saw an even distribution of attacks, emphasizing the global nature of threats to energy infrastructure.
The transportation sector was the fifth most-attacked industry in 2025, accounting for 8% of all incidents. This finding reflects the sector's critical role in global logistics, commerce, and infrastructure, making it a target for both financially motivated attackers and those seeking to disrupt operations.
Malware (60%) was the most important action on objective for the industry, followed by a tie for second place by spam and business email compromise (20% each).
The two attack vectors observed for this industry were exploitation of public-facing applications and valid accounts (50% each).
The transportation sector faced significant impacts, with data leaks (100%) being the sole impact observed, reflecting attackers' interest in monetizing sensitive information.
Regionally, Europe experienced the highest volume of incidents, accounting for 42% of attacks, followed by Asia-Pacific (25%), North America (25%) and Latin America (8%). The concentration of incidents in Europe reflects the region's growing prominence in global transportation and logistics, as well as its expanding attack surface.
The retail sector accounted for 6% of incidents in 2025, a very slight increase from the prior year. Retailers’ heavy reliance on digital infrastructure to store consumer data and process transactions continued to make the sector an attractive target for financial gain or operational disruption.
Attackers employed a range of tactics, with server access and the use of legitimate tools (38% each) as the most observed actions. Email thread hijacking and malware (13% each) followed. These methods highlight attackers’ focus on both accessing and exploiting sensitive systems for further financial or operational gain.
The primary initial access vector was exploitation of public-facing applications (43%), underscoring the importance of securing internet-exposed services and promptly remediating vulnerabilities to prevent unauthorized access. Additional notable initial access vectors include valid accounts (cloud), valid accounts (local), valid accounts (default) and external remote services (14% each). Credential harvesting (100%) also dominated the impact on this sector, showing the increase in attackers monetizing stolen data.
Regionally, Europe (50%) experienced the highest proportion of retail-related incidents, followed by North America (40%) and Asia-Pacific (10%). This distribution underscores the concentration of threats in regions with a large volume of retail activity and digital infrastructure.
The wholesale sector accounted for 6% of incidents in 2025, representing a six‑fold increase over the previous year. Wholesalers—responsible for distributing goods from manufacturers to retailers or directly to consumers—are critical links in the global supply chain, making disruptions to this sector impactful.
Server access (29%) was the most common action on objective, closely followed by the abuse of legitimate tools and malware (28% each). Attackers employed two primary initial vectors in wholesale incidents: valid accounts (local) (50%) and phishing (spearphishing via service) (50%), highlighting a focus on diverse and potentially tailored attack methods.
Credential harvesting was the sole impact observed affecting this industry directly. Regionally, incidents were only observed in North America (100%), underscoring a geographically concentrated threat landscape within this sector.
The healthcare sector accounted for 4% of all incidents, dropping from seventh place last year to eighth this year. Despite its lower ranking, the sector remains a high-value target due to its dependence on sensitive patient data, the need for uninterrupted operations and the prevalence of legacy systems.
Attackers predominantly focused on malware (50%) as well as server access and legitimate tools (25% each) as their main actions on objective, reflecting a focus on both operational disruption and financial extortion. These actions highlight the sector’s vulnerability to attacks that compromise systems and hold data or services hostage.
The sole initial access vector observed was exploitation of public-facing applications (100%), emphasizing the risks posed by exposed systems and the urgent need for robust vulnerability management practices.
Regionally, North America (57%) experienced the highest volume of healthcare-related incidents, followed by Asia-Pacific, Europe and Latin America (14% each), indicating a significant concentration of threats in regions with advanced healthcare infrastructure.
The government sector accounted for 3% of all incidents in 2025. Despite the sector’s lower incident rate, government entities remain high-value targets due to the vast amounts of sensitive data they manage, including state-level intelligence, classified assets and personally identifiable information (PII).
Attackers predominantly used server access (50%) and tool (credential acquisition) (50%) as their primary actions on objective, reflecting a focus on exploiting vulnerabilities and obtaining authentication data to expand their foothold within targeted environments. These techniques highlight the sector’s ongoing exposure to methods that enable unauthorized access and facilitate subsequent operational disruption or data theft. The two observed initial access vectors were evenly split between valid accounts (local) and phishing (spearphishing attachment) (50% each), showcasing attackers’ ability to exploit credential mismanagement and human error to infiltrate systems.
Regionally, North America (80%) experienced the highest volume of government-related incidents, followed by the Middle Eastand Africa (20%), reflecting the strategic importance of government entities in these regions and their prominence as targets for cybercriminals and nation-state actors.
Strengthen security and compliance with IBM IAM services, streamlining identity across hybrid cloud environments.
Optimize your security program with IBM’s global, vendor-independent threat response services.
Build a secure identity foundation with IBM Verify to simplify access, improve authentication, and scale with confidence.