90% of Ransomware Attacks Exploit Firewall Vulnerabilities in 2025

  • 90% of ransomware incidents in 2025 exploited firewalls through unpatched software or vulnerable accounts.
  • The fastest observed ransomware attack took just three hours from breach to encryption, involving Akira ransomware.
  • 66% of incidents involved the supply chain or third-party vulnerabilities, up from 45% in 2024.
  • 96% of incidents with lateral movement resulted in ransomware deployment.
  • The most widely detected vulnerability dated back to 2013 (CVE-2013-2566), highlighting outdated encryption risks.

Barracuda Networks' report underscores the evolving tactics of ransomware attackers, who increasingly exploit legacy vulnerabilities and third-party weaknesses. The rapid progression from breach to encryption highlights the need for integrated, AI-powered security solutions that can autonomously detect and respond to threats in real time. As cyber threats become more sophisticated, organizations must prioritize proactive vulnerability management and supply chain security to mitigate risks.

Vulnerability Management
How organizations will address the prevalence of unpatched software and outdated encryption in their systems.
Supply Chain Risk
Whether the increasing reliance on third-party software will continue to escalate ransomware risks.
Response Time
The pace at which cybersecurity firms can develop solutions to detect and mitigate ransomware attacks within critical three-hour windows.
Firewall Flaws Fuel 90% of Ransomware Attacks, New Report Finds