Executive Summary
In early 2025, the Picus Blue Report identified a concerning trend in global ransomware attacks: despite widespread awareness of ransomware tactics, organizations failed to prevent over a third of attack attempts, with prevention rates plummeting to 62%. Far more alarming, only 3% of simulated data exfiltration attempts were effectively blocked, exposing substantial gaps in data security frameworks. Attackers leveraged a blend of known and emerging ransomware variants to infiltrate networks, bypassing traditional and next-gen defenses by exploiting east-west traffic and insufficient segmentation. This led to successful encryption and large-scale data theft, disrupting business continuity for multiple sectors globally.
This incident underscores a broader industry challenge: as ransomware evolves, so do the techniques for bypassing established defenses. The drastic fall in exfiltration prevention highlights an urgent need for modernized controls, especially with the regulatory and reputational stakes of breaches rising sharply in 2025.
Why This Matters Now
Ransomware actors are rapidly outpacing defensive innovation, and low exfiltration prevention rates expose organizations to double-extortion and compliance failures. Immediate investment in detection and zero trust segmentation is crucial, as attackers leverage east-west techniques, hybrid cloud blind spots, and unprotected internal traffic.
Attack Path Analysis
The attack began when adversaries gained an initial foothold into the cloud environment, likely leveraging weak credentials or exposed services. After access, they escalated privileges, abusing IAM misconfigurations or credential reuse to traverse environments. Using this elevated access, the attacker moved laterally via workload-to-workload and service-to-service communications, possibly including Kubernetes clusters. They established command and control through covert channels, blending into normal outbound traffic. Data was exfiltrated through egress channels that evaded traditional prevention controls. Finally, the adversary deployed ransomware, encrypting resources and disrupting business operations.
Kill Chain Progression
Initial Compromise
Description
Adversaries gained entry by exploiting exposed cloud services or weak credentials to access the environment.
Related CVEs
CVE-2024-50686
CVSS 9.1A critical insecure direct object reference (IDOR) vulnerability in SunGrow iSolarCloud's commonService API allows authenticated attackers to access or modify data of other users or tenants.
Affected Products:
SunGrow iSolarCloud – prior to October 31, 2024 remediation
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing
Valid Accounts
Command and Scripting Interpreter
Obfuscated Files or Information
Data Encrypted for Impact
Exfiltration Over C2 Channel
Impair Defenses
Brute Force
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Prevention and Detection of Data Exfiltration
Control ID: 3.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model 2.0 – Enable Data Loss Prevention (DLP) and Exfiltration Controls
Control ID: Data Pillar - Detection & Response
NIS2 Directive – Incident Handling and Reporting
Control ID: Article 21(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Ransomware attacks exploit unencrypted traffic and lateral movement vulnerabilities, threatening HIPAA compliance and critical patient data with only 3% data exfiltration prevention success.
Financial Services
Banking systems face severe ransomware exposure through east-west traffic vulnerabilities and inadequate segmentation, risking PCI compliance violations and customer financial data compromise.
Government Administration
Government networks vulnerable to ransomware via Salt Typhoon-style attacks targeting unencrypted communications, requiring zero trust segmentation and enhanced threat detection for NIST compliance.
Information Technology/IT
IT infrastructure providers critically exposed to ransomware through Kubernetes vulnerabilities and shadow AI risks, necessitating comprehensive cloud-native security fabric implementation and anomaly detection.
Sources
- Known. Emerging. Unstoppable? Ransomware Attacks Still Evade Defenseshttps://www.bleepingcomputer.com/news/security/known-emerging-unstoppable-ransomware-attacks-still-evade-defenses/Verified
- Picus Security Finds 46% of Enterprise Passwords Vulnerable to Cracking — 2X Increase from 2024https://www.picussecurity.com/resource/press-release/picus-launches-blue-report-2025Verified
- The Blue Report 2025https://www.picussecurity.com/resource/the-blue-report-2025Verified
- Average ransom payment doubles in a single quarterhttps://www.itpro.com/security/ransomware/average-ransom-payment-doubles-in-a-single-quarterVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, granular egress policy, precise traffic visibility, and workload isolation would have constrained attacker movement and data theft at every stage, significantly reducing both the likelihood and blast radius of ransomware impact.
Control: Multicloud Visibility & Control
Mitigation: Early detection of unauthorized or anomalous access attempts.
Control: Zero Trust Segmentation
Mitigation: Limits on unauthorized privilege escalation across workloads.
Control: East-West Traffic Security
Mitigation: Prevents or detects unauthorized workload-to-workload east-west traffic.
Control: Cloud Firewall (ACF) & Inline IPS (Suricata)
Mitigation: Block malicious command and control channels and identify threat patterns.
Control: Egress Security & Policy Enforcement
Mitigation: Stops unauthorized data exfiltration to external destinations.
Enables rapid identification and response to ransomware execution.
Impact at a Glance
Affected Business Functions
- Data Management
- Customer Service
- Financial Transactions
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive customer data, including personal and financial information, due to unauthorized access facilitated by compromised credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Apply workload- and identity-based segmentation to restrict lateral movement and limit attacker reach.
- • Enforce strong egress traffic controls with policy enforcement and deep packet inspection to block data theft and malicious command channels.
- • Implement centralized visibility and monitoring across multicloud environments for rapid detection of anomalies.
- • Use continuous threat detection and automatic anomaly response to identify ransomware behaviors and mitigate impact early.
- • Regularly audit access privileges and apply least privilege principles to all accounts and service identities in cloud and container workloads.



