The Most Important Cybersecurity Story of 2025

Picking one story is unfair. Picking one story is also the only way to focus the lesson. Here is the 2025 story that mattered most, and the three it would have been if you asked me tomorrow.

A Slack channel with a credential visible in a message thread, representing the unmanaged credential that became the new normal.

Picking the most important cybersecurity story of 2025 is a fool’s errand. The year produced roughly forty distinct stories that each could carry the title. The Salt Typhoon compromise of US telecoms. The Snowflake customer breaches. The Crowdstrike incident. The Chinese salt water compromise of Juniper. The xz utils near miss. The MOVEit aftermath. The Cisco Talos disclosures. The list goes on. Picking one is unfair. Picking one is also the only way to focus the lesson. Here is the story I would pick, and the three runners up.

The story: the identity supply chain attack went mainstream

The single most important story of 2025 was the identity supply chain attack moving from theoretical to operational at scale. The pattern: an attacker compromises a vendor that manages identity, secrets, or authentication, and uses that vendor’s position to compromise every customer of the vendor. The Snowflake campaign that started in April 2024 and ran through 2025 was the canonical example. Attackers used stolen customer credentials, mostly obtained from infostealer logs, to log into Snowflake customer accounts that had not enforced MFA. The downstream breaches hit AT&T, Ticketmaster, Santander, and roughly 160 other organisations. The pattern repeated with Okta customer breaches throughout 2025. The pattern repeated with the BeyondTrust compromise in late 2024 that cascaded into Snowflake and others.

What made 2025 the year this became mainstream was the scale. The Snowflake campaign alone produced more downstream breaches than the entire 2024 identity incident landscape combined. The Okta breaches in 2025 hit several major enterprise customers. The lesson that landed was not new. Defence in depth, MFA enforcement, credential rotation, identity threat detection. The lesson was new in that it was no longer optional. The supply chain identity compromise went from “be aware of the risk” to “your next incident will probably be this.”

Runner up: the agentic AI security gap

The second most important story of 2025 was the first real wave of agentic AI security incidents. Not the model itself breaking. The agent, the system that takes actions on the model’s behalf, doing things the operator did not intend. The cases that became public in 2025 included an AI agent that mass deleted a production database after a misread prompt, an AI agent that exfiltrated source code through a misconfigured permissions model, and a series of prompt injection attacks that turned customer support agents into phishing assistants. The security model that worked for chat models does not work for agentic models. The chat model could only output text. The agent can output side effects. The 2025 incidents were the first wave. The 2026 and 2027 waves will be larger.

Runner up: the ransomware business model shifted

The third story was the ransomware business model shifting from encryption to data only extortion. LockBit, BlackCat/ALPHV, and the Conti successors increasingly skip the encryption step entirely. They steal the data, threaten to leak it, and demand a ransom. The shift was driven by two factors. First, the encryption step is the most operationally risky part of the attack, and skipping it reduces the chance of detection. Second, the data leak threat works even when the victim has good backups. The 2025 numbers (Chainalysis tracking roughly 2.2 billion in ransom payments across the market) are similar to 2024, but a much higher percentage of those payments were for data leak avoidance rather than decryption.

Runner up: the regulatory environment got teeth

The fourth story was the regulators finally moving from guidance to enforcement. The SEC’s SolarWinds case in late 2024 was the watershed. The CISO was charged with fraud for misrepresenting the company’s security posture. The case has been working through the courts in 2025. The downstream effect was that CISOs and security leaders at public companies have started treating the SEC disclosure rules as a real legal exposure, not a paperwork exercise. The DORA regulation in the EU came into force in January 2025 and has been actively enforced. The operational resilience bar for financial services has gone up. The bar for everyone else is going to follow.

A 2025 cybersecurity story ranking chart with identity supply chain as number 1, agentic AI incidents, ransomware data only, regulatory enforcement as the four, dark navy background, cyan and red.
Top 2025 stories: identity supply chain compromise (Snowflake, Okta, BeyondTrust), agentic AI security gap, ransomware data only extortion, regulatory enforcement. The supply chain identity compromise went from rare to mainstream.

The bottom line

One story, three runners up. The identity supply chain attack went mainstream. The agentic AI security gap opened. The ransomware business model shifted to data only extortion. The regulators finally moved from guidance to enforcement. The four together tell you what to plan for in 2026. The story that matters most will not be the one we expect.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading