Annual Report

Cyber security: attacks are set to rise in 2025, but preventive capabilities are also increasing

Email is the main channel for cyberattacks, accounting for 40 per cent of the total. The role of the National Cybersecurity Agency is growing

E-mail spam phishing scammer concept. Red warning symbol on envelope in fishing hook icon as bait on laptop screen, criminal hacker cyberattack sending scam malware spreading virus sms text message. tete_escape - stock.adobe.com

2' min read

Translated by AI
Versione italiana

2' min read

Translated by AI
Versione italiana

The email remains the main vector for cyberattacks: 40 per cent of cyberattacks in 2025 were carried out via email. This is revealed in the ‘Report on the Activities Carried Out by the National Cybersecurity Agency”, submitted to the Presidency on 19 May 2026 and published on the Chamber of Deputies’ website on 11 August 2026. In second place is the exploitation of compromised credentials, which reduce the likelihood of detection as they allow access to systems using legitimate identities. Third place goes to the exploitation of system vulnerabilities through security flaws in operating systems, applications or network devices. Among the types of threat, however, it was DDoS attacks (Distributed Denial of Service) that prevailed: online services are rendered inaccessible by flooding them with traffic until their resources are exhausted. Data exposure and phishing rank second and third respectively.

The sectors

According to the analysis, the sectors most affected last year were public administration , telecommunications and technology. Out of a total of 3,907 confirmed victims, 628 were employed by local government and 519 by central government, whilst 378 worked in the telecommunications sector. As the report points out, a single incident may involve multiple entities, each of which may operate in one or more sectors: it is therefore possible that there may be overlaps in the sector classifications.

Loading...

There were a total of 2,729 cyber incidents, 615 of which were incidents – that is, cases where the attack had consequences. This represents 22.5 per cent, or just under one in four. In 55 cases, intervention by staff from the National Cybersecurity Agency was required; they work alongside those affected to help manage the incident and its consequences. In 2024, there were 40 such interventions: according to the report, the increase is due, on the one hand, to the Agency’s greater capacity to provide support and, on the other, to a higher number of cases requiring intervention. Forty per cent of the operations were carried out in support of the central public administration, 16 per cent to local public administration and 11 per cent to the technology sector.

The effects

The peak in cyber incidents was recorded in June, when there were 90 incidents out of a total of 434 attacks. On average, there were just over 227 cyber incidents per month, whilst there were just over 51 incidents. Most of the attacks, which had consequences (34%), affected the confidentiality and/or integrity of data. Damage relating to data availability (27%) and account compromise (21%) was also frequent. Less common, however, were system compromises (14%) and application compromises (4%).

Compared with the previous year, the increase in events is substantial: in 2024 there were 1,979, representing a rise of 37.9 per cent. The rise in incidents, however, was considerably more modest, rising from 573 in 2024 to 615 in 2025: +7.3 per cent. The report states that the discrepancy between the rise in incidents and that in accidents ‘is attributable to preventive alerting measures’.

Copyright reserved ©

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti