Deloitte Report

Surge in cyberattacks and generative AI makes fraud more convincing

Criminals’ arsenal includes cloned voices, deepfakes and personalised phishing, as well as personal data breaches

4' min read

Translated by AI
Versione italiana

4' min read

Translated by AI
Versione italiana

Wave of cyberattacks targeting large companies and the public sector. According to the latest figures presented by the National Cybersecurity Agency (ACN), 2025 saw a significant increase in the volume of hostile activity (2,729 incidents handled), with the monthly average rising by 38 per cent, from 165 to 227. Despite this increase, incidents with confirmed impacts rose by only +7 per cent, totalling 615 cases. These findings emerge from the report ‘Cybersecurity, Fraud and Data Privacy’, produced by Deloitte in its capacity as Knowledge Partner for the first edition of WeSec – The Security Exhibition, organised by ABI, which will take place in Milan on 22 and 23 September 2026.

“The ongoing digitalisation of services, payments and critical infrastructure is helping to make cyber security a strategic component for the resilience of the economic and financial system, the protection of public and business confidence, and business continuity,” said Fabio Battelli, Enterprise Security Leader at Deloitte. “For the banking sector, cybersecurity is a key enabler of digital innovation and, increasingly, of the secure adoption of artificial intelligence, as well as an essential component of risk management and compliance with the European regulatory framework.”

Loading...

The public sector remains the most exposed sector in absolute terms. In fact, over 1,100 incidents recorded by the ACN in 2025 and over 28 per cent of Italian incidents in the CLUSIT sample (an increase of approximately 290 per cent) can be considered predominantly ‘demonstrative’ attacks, but with insidious characteristics, as they are directly linked to the exposure of public databases and to breaches affecting web service providers that involve multiple organisations. The manufacturing sector is the area of greatest structural vulnerability. Around 16 per cent of global attacks on the sector target Italian organisations, with ransomware attacks concentrated on SMEs and the convergence of IT and OT, which transforms incidents into production stoppages. The energy sector, a prime target for targeted phishing, is of systemic importance to both criminal groups and state actors.

Ai alert

When planning and preparing cyberattacks, criminal gangs make extensive use of artificial intelligence, which enables them to escalate cyberattacks and fraud. ACN, Clusit and the European Union Agency for Cybersecurity document the use of generative AI to produce more credible, personalised and scalable phishing and spear-phishing campaigns, and to automate stages of the attack that were once carried out manually, from reconnaissance and vulnerability discovery to the development of malicious code. On the fraud front, data from the Italian Postal Police confirm the spread of cloned voices and deepfake videos used to support scams and fraudulent investment schemes. Technological advances are also paving the way for an environment of increasingly autonomous threats, in which AI-based agents can carry out growing portions of the attack chain with limited human supervision, further reducing the reaction time available to defenders. “The picture that emerges from the report highlights how the decisive factor will be the ability to manage risk,” explains Daniele Frasca, Senior Partner at Deloitte. In this context, five priorities emerge for senior management: to place cyber risk firmly on the Board’s agenda; to shift the focus from protection alone to resilience; to strengthen oversight of the human factor and digital identities; managing AI both as a defence mechanism and a new source of risk; and, finally, extending oversight to the entire digital supply chain of all suppliers. Compliance must also evolve in this direction: the GDPR, NIS2, DORA, CRA and AI Act cannot be managed as separate exercises, but must converge within an integrated risk and control framework.”

This is how it will be in 2025

During 2025, over 2,700 incidents were recorded, whilst investment in cyber security grew by 12 per cent, according to estimates by the Milan Polytechnic Observatory, with expenditure totalling 2.78 billion euros. Spending on cybersecurity has risen at a significantly faster rate than the 1.5 per cent increase in national digital spending. This growth was driven by European funds from the National Recovery and Resilience Plan (PNRR) in the public administration sector (+28 per cent), the finance sector (+22 per cent) and the logistics and transport sector (+18 per cent). Furthermore, it emerges that over a third of large enterprises (34%) suffered cyber-attacks last year, and 3% experienced direct impacts on their operations. Furthermore, 57 per cent of these companies have initiated a structural review of their incident response plans, and 70 per cent of large enterprises anticipate further budget increases in 2026 for cyber security. The overall scale of criminal activity is revealed by the latest figures from the Italian Postal Police, which show that in 2025, 51,560 cases were handled, of which 27,085 related to cybercrime, with sums stolen exceeding 269 million euros (+16 per cent on 2024). There is evidence of the increasingly widespread use of AI for fraudulent purposes, through cloned accounts, deepfakes and personalised phishing. Added to this is the issue of personal data breaches, as the number of notifications issued by the Data Protection Authority reached 2,415 in 2025 (+10 per cent on the previous year), with fines totalling over €37 million, specifically targeting shortcomings in security measures.With regard to payment systems, data from the Bank of Italia updated to the second half of 2025 show a fraud rate of 0.003 per cent of the total transaction value, with 10 fraudulent activities per 100,000 transactions. In particular, remote transactions remain among the most vulnerable to potential fraud attempts: 0.060 per cent by value for card use in e-commerce, compared with 0.006 per cent for physical POS terminals. The public sector remains the most exposed in absolute terms. In fact, over 1,100 incidents detected by the ACN in 2025 and over 28 per cent of Italian incidents in the CLUSIT sample (an increase of approximately 290 per cent) can be considered predominantly ‘demonstrative’ attacks, but with insidious characteristics, as they are directly linked to the exposure of public databases and to the compromise of web service providers affecting multiple organisations. The manufacturing sector is the area of greatest structural vulnerability. Around 16 per cent of global attacks on the sector target Italian organisations, with ransomware attacks concentrated on SMEs and the convergence of IT and OT, which transforms incidents into production stoppages. The energy sector, a prime target for targeted phishing, is of systemic importance to both criminal groups and state actors.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti