Get the full Report NOW
The worst incidents of 2025
Financial Warfare – Feb 2025
$1.45B
Lazarus Group (DPRK) · Dubai
MFG Shutdown – Aug / Nov 2025
$1.9B
ShinyHunters · 2021 | Infostealer Credential
Critical Infrastructure – Sep 2025
4 EU Airports Offline
Heathrow – Brussels – Berlin – Dublin
Identity Fraud – Jan 2024 / Conf. 2025
$25.5B
Real-time AI video & voice deepfakes
+ 5 more incidents fully analysed in the report
(Harrods · Bouygues · Dodd Group · Salesforce · Bridgestone)
AI WAEPONIZATION
How threat actors are advancing
Agentic AI attacks
Anthropic’s Claude Code tool was hijacked by state-sponsored actors to run autonomous intrusions across 30 government and financial entities, with 80–90% of the attack lifecycle executed without human intervention.
Deepfake social engineering
Real-time video and voice cloning now bypasses biometric verification. The Arup case proved it: “sensory trust” – the assumption that seeing and hearing a colleague means they are real – is dead.
Supply chain gateway doctrine
5 of the 8 top incidents entered via compromised third-party vendors. Hardening your perimeter is irrelevant when your HVAC contractor or HR software provider is the entry point.
Just-in-Time (JIT) polymorphic malware
New malware families (PROMPTFLUX) use LLMs to rewrite their own code in real time, defeating traditional antivirus and EDR systems that rely on recognising known file hashes or code strings.
“The industrialization of cyber warfare has removed the luxury of time. The window for digital transformation has closed. The window for digital fortification is closing fast.”
KEY TOPICS
Breach Cost by Market 2025

WHAT’S INSIDE
60 Pages of Intelligence for Leaders
- Forensic analysis of 9 landmark incidents, from the Bybit Heist to the Dodd Group breach
- EMEA breach cost statistics with MTTD/MTTR per market: GR, CY, SA, UK, Benelux, Africa
- Sector Risk Matrix across Banking, Energy, Maritime, Healthcare, Telecom and Government
- Strategic mandate for C-Level executives and government officials, with actionable checklist
- AI weaponization deep-dive: Agentic AI, JIT malware, deepfake fraud, quantum computing threats
- The missing dimensions: cyber insurance exclusions, workforce crisis and ransom economics
- Post-2025 Executive Checklist: Immediate – Structural – Strategic actions
- Appendix: 28 EMEA regulatory and compliance frameworks – NIS2, DORA, EU AI Act and more




