The Bottom Line: 68 percent of ransomware attacks via unsecured VPN access succeed because cybercrime-as-a-service operators deliberately exploit these entry points.
Criminals succeed in penetrating systems in 68 percent of VPN-based ransomware attacks. A current analysis shows that insecure remote access, alongside RDP, ranks among the preferred attack channels in the cybercrime-as-a-service model.
The InfoGuard Threat Intelligence Insights 2025 confirms: VPN and RDP access with weak authentication mechanisms represent the most effective entry point for ransomware operations. In two-thirds of these attacks via insecure VPN interfaces, attackers succeeded in gaining a foothold in target networks.
The key finding lies in a shift in cybercriminals’ business model: cybercrime-as-a-service has become the dominant business model in 2025. For security executives, this concretely means that specialized actors purchase or rent access mechanisms to exploit them in ransomware campaigns. Attacks are thus industrialized and decentralized.
For CISOs, this creates an immediate call to action: remote access systems require immediate attention. Weak or reused passwords, missing multi-factor authentication, and outdated VPN implementations present themselves as direct entry points for adversaries. Hardening VPN and RDP environments—particularly through mandatory MFA and regular patching—must become a priority.
Source: www.security-insider.de · Published July 24, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 of the EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.