July 2025: Global cyberthreats

July 2025: Global cyberthreats

In an increasingly interconnected world, the digital battleground knows no borders. Recent weeks have seen a surge in cyberattacks across major global economies, highlighting the persistent and evolving threats faced by governments, businesses, and public institutions alike. From sophisticated zero-day exploits targeting corporate giants to relentless ransomware campaigns crippling essential services and social engineering tactics compromising local administrations, cybercriminals are demonstrating a diverse arsenal. This overview delves into the latest incidents impacting Germany, the UK, Japan and the US, underscoring the urgent need for enhanced cybersecurity measures and vigilance worldwide.

Germany

Germany has seen a concerning spate of cyberattacks targeting its public sector and local infrastructure. In early July 2025, a phishing attack impacted a county administration in Hesse (Landratsamt Odenwaldkreis), highlighting the continued vulnerability of local government entities to social engineering tactics. Simultaneously, DDoS attacks were reported against state ministries in Magdeburg, Sachsen-Anhalt, demonstrating coordinated efforts to disrupt governmental online services. These incidents underscore the persistent threat actors pose to critical public infrastructure, emphasising the need for robust defensive measures and continuous employee training against evolving phishing schemes and denial-of-service campaigns.


United Kingdom

The UK’s retail sector continues to be a high-value target for cybercriminals. In early July 2025, a 20-year-old woman and three teenagers were arrested in connection with recent cyberattacks targeting prominent UK retailers, including M&S, Co-op, and Harrods. These arrests, part of a National Crime Agency (NCA) operation, indicate ongoing investigations into significant data breaches and operational disruptions that have impacted these high-profile companies. The incidents highlight the persistent threat of sophisticated ransomware groups and data exfiltration campaigns against major consumer-facing businesses, stressing the importance of comprehensive security frameworks and swift law enforcement response to protect customer data and critical business operations.


Japan

Nippon Steel Solutions recently disclosed a data breach that resulted from a zero-day attack on its network equipment. Announced on July 10, 2025, this incident led to unauthorised access and the potential leakage of personal data belonging to customers, partners, and employees. The exploitation of a zero-day vulnerability, an unknown software flaw, before a patch is available, represents a significant challenge for even sophisticated organisations. This attack underscores the critical importance of continuous vulnerability management, advanced threat detection, and swift incident response capabilities in defending against highly sophisticated and previously unknown attack vectors targeting supply chains and corporate networks.


USA

In the US, the Pierce County Library System (PCLS) in Washington notified over 336,000 individuals of a ransomware attack by the “Inc” group, which occurred in April 2025. The breach, disclosed on July 10, exposed sensitive data, including names and dates of birth, with the “Inc” group reportedly posting images of stolen driver’s licenses, passports, and internal documents. This incident highlights the ongoing vulnerability of public sector entities, including libraries, to ransomware threats that can lead to significant data exposure and disruption of services. It reinforces the need for robust backup strategies, strong endpoint protection and comprehensive incident response plans for organizations holding sensitive personal information.

Browse our latest issue

Intelligent CISO

View Magazine Archive