Cyber Crime & ForensicPress Release

Kaspersky: Government, Industrial Sectors Primary Targets for Cybercriminals in 2025

Underscores the Need to Strengthen Not Only Technology But Also Organisational Resilience

According to the global report by Kaspersky Security Services, Anatomy of a Cyber World, the government sector emerged as the most targeted sector for the second consecutive year, accounting for 19% of all high-severity incidents in 2025. The industrial sector closely followed at 17%, while the IT sector rose to third place with 15%, displacing finance from the top three targeted industries.

The Anatomy of a Cyber World is a comprehensive global report drawing on incident statistics from Kaspersky Managed Detection and Response, Kaspersky Incident Response, Kaspersky Compromise Assessment, and Kaspersky SOC Consulting. It sheds light on the most prevalent attacker tactics, techniques, and tools, as well as the characteristics of detected incidents and their distribution across regions and industry sectors.

As Malaysia advances its digital economy, the increasing reliance on government platforms, industrial systems, and IT infrastructure is becoming central to national growth. According to official targets, the digital economy is expected to contribute up to 30% of Malaysia’s GDP by 2030, highlighting the scale of digital integration across public services, manufacturing, and business operations. This growing interconnectivity reflects the same sectors identified in Kaspersky’s findings as key targets globally.

Kaspersky Findings

Building on these findings, the report reveals that government bodies continued to be the most targeted sector in 2025. A deeper examination of the root causes of attacks within this sector uncovers that Advanced Persistent Threats (APTs) were the most common, accounting for 33.3% of incidents. This trend highlights the increasing sophistication of adversaries who persistently evolve their tactics to bypass automated protection. Additionally, 18.9% of government organisations experienced social engineering attacks, underscoring that employees remain a critical entry point for cyber threats.

Kaspersky’s threat intelligence tracking further shows that APT groups such as Lazarus, Naikon, and ToddyCat have been active across Southeast Asia, targeting government networks, critical infrastructure, and enterprise IT environments. These campaigns are typically designed to maintain long-term access and extract sensitive data.

The dual vulnerability—from both advanced persistent attackers and social engineering campaigns—underscores the need to strengthen not only technology but also organisational resilience. Implementing measures such as role-based access control and limiting privileges can significantly reduce the impact of compromised accounts, particularly in large, distributed government environments.

The industrial sector presents a different but equally concerning profile. Threats in industrial environments are distributed with striking uniformity: APT-driven incidents constitute 17.8%, malware 14.9%, and social engineering 13.9%. This pattern suggests that industrial organisations attract a broad range of adversaries with different capabilities and objectives, rather than being primarily targeted by a single type of threat actor. Notably, confirmed cyber exercises such as red teaming account for 22.8% of incidents in the sector—the highest share among the top three industries—reflecting growing investment in proactive security validation among industrial organisations.

In contrast, the IT sector shows a markedly different pattern. With 41% of incidents attributed to human-driven APT attacks—the highest rate across all sectors—IT organisations are clearly a priority target for sophisticated threat actors seeking to exploit trusted relationships and scale their impact through supply chains. APT traces, which are artefacts from previous advanced persistent threat activity, were identified in an additional 17% of cases, while social engineering accounted for 11%. Red teaming represents only 9% of IT incidents, suggesting that proactive security testing remains underutilised relative to the sector’s actual threat exposure.

Interestingly, the finance sector was displaced from the top three targeted industries. According to the report, red teaming in this sector accounts for 36.1% of incidents, reflecting a mature, compliance-driven approach to proactive defence, while confirmed APT activity remains comparatively low at 11.5%. This pattern indicates that sustained investment in security assessment can effectively enhance a company’s ability to identify vulnerabilities early, avoiding costly breaches and reducing the risk of significant damage to reputation and operations.

“Government, industrial, and IT organisations consistently attract sophisticated adversaries because of the strategic value of what they hold, operate, and connect to geopolitical intelligence, critical infrastructure, and global supply chains, respectively. The 2025 data confirms that these attacks are not opportunistic: they are targeted and often aimed at establishing persistent access. Each of these sectors needs to operate on the assumption that determined attackers will find a way in, and focus their defences on early detection, rapid containment, and minimising the window of exposure. So, proactive threat hunting, continuous monitoring, and regular compromise assessments are no longer optional for organisations of any size across these industries,” commented Sergey Soldatov, Head of Security Operations at Kaspersky.

Kaspersky Gives Its Recommendations

To strengthen protection against human-driven attacks, Kaspersky recommends the following:

  • Augment existing security controls with human-led detection from Kaspersky Managed Detection and Response (MDR) and receive comprehensive, detailed analysis of security incidents with Kaspersky Incident Response. These services offer 24/7 monitoring and cover the entire incident management cycle—from threat identification to continuous protection and remediation.
  • Align internal processes and technologies with today’s evolving threat landscape through Kaspersky SOC Consulting. This service helps organisations build an in-house SOC from scratch, assess the maturity of an existing SOC, or enhance specific capabilities such as detection and response procedures.
  • Use centralised and automated solutions such as Kaspersky Next XDR Expert to enable comprehensive protection of all assets. By aggregating and correlating data from multiple sources in one place and using machine-learning technologies, this solution provides effective threat detection and fast automated response.

To learn more about attacker tactics and techniques, the characteristics of detected incidents and their distribution across regions and industry sectors, read the full Kaspersky report.

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *