Holiday Cyber Attacks

The holiday season has become the most dangerous period for cybersecurity incidents, with ransomware attacks surging 30% during November-December compared to monthly averages.

Introduction

The holiday season has become the most dangerous period for cybersecurity incidents, with ransomware attacks surging 30% during November-December compared to monthly averages. Analysis of major breaches from 2020-2025 reveals that cybercriminals systematically exploit reduced IT staffing, distracted employees, and rushed business operations during holidays to launch devastating attacks. In December 2024 alone, a record 574 ransomware attacks occurred globally, while phishing campaigns spiked 46% above normal levels.

The threat landscape has evolved dramatically. Average ransom demands have massively increased 253% from $310,000 in 2020 to $1.1 million in 2025, and recent incidents like Change Healthcare’s breach affecting 192.7 million individuals demonstrate unprecedented scale. With emerging attack techniques including AI-powered phishing, reverse proxy tools like Evilginx bypassing multi-factor authentication, and ClickFix social engineering campaigns, organizations face more sophisticated threats than ever before.

This critical alert provides actionable intelligence on holiday threat patterns, recent major incidents, 2025 attack forecasts, and defensive strategies including how organizations can maintain robust security even when IT teams are off during the holidays.

Key Statistics

The data demonstrates clear patterns of strategic timing by threat actors:

  • 30% increase in ransomware attacks during holiday periods (November-December) versus monthly averages
  • 70% surge in attempted ransomware attacks during November-December compared to January-February
  • 46% spike in phishing alerts during December relative to monthly averages
  • 574 ransomware attacks recorded globally in December 2024 a record high
  • 95% of data breaches stem from human errors, which spike dramatically when employees are distracted during holidays

Ransomware attacks increase by 30% during holiday periods compared to monthly averages (2018-2020)

Financial Impact Escalation

The economic consequences of cyberattacks have grown exponentially:

  • Average ransom payments climbed 253% from $310,000 (2020) to $1.1 million (2025)​
  • Global cybercrime costs projected to reach $10.5 trillion annually by 2025​
  • Healthcare breach costs average $10.93 million per incident​
  • Total ransomware economic damage reached $31.5 billion in 2025, up from $20 billion in 2020​

Ransomware trends 2020-2025: escalating attack volumes, ransom demands, and economic damage

Industry Vulnerabilities

Average cost per cyberattack incident by industry sector (in millions USD) 

Healthcare remains the costliest target at $10.93 million average per breach, with the 2024 Change Healthcare attack affecting 192.7 million individuals, the largest healthcare breach in U.S. history. Retail experienced a 100% year-over-year increase in ransomware attacks from holiday 2022 to 2023, with payment card data the primary target (37% of breaches). Financial services face $5.9 million average breach costs, while entertainment and manufacturing sectors average $330,000 per incident.

Healthcare remains the costliest target at $10.93 million average per breach, with the 2024 Change Healthcare attack affecting 192.7 million individuals, the largest healthcare breach in U.S. history. Retail experienced a 100% year-over-year increase in ransomware attacks from holiday 2022 to 2023, with payment card data the primary target (37% of breaches). Financial services face $5.9 million average breach costs, while entertainment and manufacturing sectors average $330,000 per incident.

December 2020:

SolarWinds Supply Chain Attack

Discovered December 13, 2020, the SolarWinds Orion attack represents one of the most sophisticated cyberattacks in history. Russian state-sponsored APT29 actors compromised SolarWinds’ software build process, injecting malicious code into updates distributed to approximately 18,000 organizations. Victims included the U.S. Department of Homeland Security, Department of Energy, and major corporations like Cisco and Intel. The attack remained undetected for months, with hackers patiently moving laterally through victims’ networks to access sensitive government data.

Supply chain vulnerabilities can create cascading impacts. Even trusted software vendors can become vectors for nation-state espionage.

December 2021:

Kaseya July 4th Weekend Attack

While technically July, the Kaseya VSA attack exemplifies deliberate holiday timing, executed over the July 4th weekend when U.S. businesses were closed. The REvil ransomware group exploited zero-day vulnerabilities in Kaseya’s remote management software, affecting 800-1,500 businesses and demanding an unprecedented $70 million ransom. Swedish supermarket chain Coop was forced to close all 800 stores for nearly a week.

Holiday weekends provide optimal conditions for attackers to maximize disruption while minimizing detection risk.

December 2022:

LockBit, Royal, and Play Ransomware Surge

December 2022 saw coordinated spikes across major ransomware groups during the “holiday gift season”:​

  • LockBit regained dominance, breaching California’s Department of Finance (75GB, 246,000 files) and SickKids Hospital​
  • Royal ransomware disproportionately targeted healthcare, breaching telecommunications company Intrado​
  • Play ransomware surged 136%, exploiting Microsoft Exchange vulnerabilities to breach Rackspace cloud services during peak holiday shopping​
  • ALPHV/BlackCat recorded 70% increase to highest attack volume of 2022

Multiple sophisticated ransomware groups operate simultaneously during holidays, creating overwhelming pressure on security teams.

December 2023:

Ohio Lottery Christmas Eve Attack

DragonForce ransomware struck Ohio’s lottery system on Christmas Eve, disrupting internal applications and stealing over 3 million entries containing Social Security numbers, dates of birth, and personal information. The Christmas Eve timing maximized disruption while minimizing rapid response likelihood from government IT staff.

Government systems face particular vulnerability during holidays when staffing is minimal.

December 2024:

Record-Breaking Month

December 2024 recorded 574 ransomware attacks globally, the highest monthly count on record:​

  • BT Conferencing (Dec 3): Black Basta ransomware, 500GB data stolen​
  • Texas Tech University (Dec 16): Interlock ransomware, 1.4 million patients affected, 2.6TB leaked​
  • SRP Federal Credit Union (Dec 10): Nitrogen ransomware, 240,000+ members, 650GB stolen​
  • Krispy Kreme (November-December): Play ransomware disrupted online ordering during peak holiday sales​
  • West Haven, CT (Christmas Day): Government systems breached, municipal IT shut down​
  • UK Local Councils (pre-Christmas): Westminster, Kensington & Chelsea affected, data copied before Christmas

The December 2024 surge demonstrates that attackers are intensifying holiday targeting, with record attack volumes and increasingly sophisticated tactics.

2025 Threat Forecast:

Emerging Attack Techniques

Reverse Proxy Phishing & Clickfix

The vast majority of phishing attacks in 2025 now use reverse proxy techniques, fundamentally changing the threat landscape. Evilginx and similar adversary-in-the-middle (AiTM) tools bypass multi-factor authentication by intercepting credentials AND session tokens in real-time.

How it works:

  1. Victim receives phishing link to fake domain (e.g., login-phishing.com)
  2. Evilginx proxies authentication to legitimate service (accounts.microsoft.com)
  3. Victim enters credentials and completes MFA on what appears to be the real site
  4. Evilginx captures everything: passwords, MFA tokens, AND authenticated session cookies
  5. Attacker imports session cookies for immediate account access, no need to bypass MFA

Critical statistics:

  • 96% of suspicious phishing domains bypass traditional protections like blacklists and spam filters​
  • EvilProxy (Phishing-as-a-Service variant) used in over 1 million account takeover attempts in early 2025​
  • Attacks complete within minutes, before takedowns can occur​

Detection challenge: These attacks use HTTPS with valid certificates, closely mimic legitimate domains, and employ user agent spoofing making them nearly indistinguishable from legitimate traffic.

ClickFix Social Engineering Campaign

ClickFix represents a dangerous evolution in social engineering, tricking users into manually executing malicious commands in both Windows and MacOS operating systems. First discovered in 2024, the technique saw massive deployment in 2025.

Attack mechanics:

  • Phishing email with HTML attachment or compromised website visit
  • Fake error message displays (“Word Online extension not installed” or “Windows Update required”, “Verify you are human by completing action below”)
  • Instructions tell user to press Windows+R, then CTRL+V to “fix” the problem
  • Malicious PowerShell command already copied to clipboard executes automatically​
  • Command downloads malware: DarkGate, Lumma Stealer, NetSupport RAT, or Latrodectus​

2025 Trends

  • ClickFix now is being delivered by malicious/fake google ads.
  • Now mimics full-screen Windows Update interface for maximum authenticity​

AI-Powered Phishing

Generative AI has democratized sophisticated phishing attacks. ChatGPT-4o Mini and similar models can be “jailbroken” to generate convincing phishing content, enabling novice attackers to conduct professional-grade campaigns.

AI capabilities exploited by attackers:

  • Craft personalized spear phishing emails using public data from LinkedIn, social media​
  • Generate phishing websites and content in minutes
  • Adapt messaging based on target’s role, industry, recent activities
  • Create convincing urgency scenarios (year-end financial requests, holiday shipping issues)
  • Scale personalized attacks to thousands of targets simultaneously

Research shows that human-guided, AI-assisted attacks evade traditional anti-phishing mechanisms because they lack predictable patterns. LLMs enable attackers to produce context-aware phishing that appears legitimate even to security-aware users.​

Phishing-as-a-Service (PhaaS) Explosion

Criminal platforms have industrialized phishing attacks. Over 1 million PhaaS attacks occurred in just the first two months of 2025, with platforms like EvilProxy and VoidProxy enabling non-technical criminals to launch sophisticated campaigns.​

The PhaaS model provides:

  • Ready-made phishing kits with reverse proxy capabilities
  • Hosting infrastructure that rotates domains to evade blacklists
  • Customer support for criminal “clients”
  • Continuous updates to bypass new security measures
  • Affiliate models where malware developers rent tools to attackers

Recently Exploited Critical Vulnerabilities:

CVE-2024-1086: Linux Kernel Privilege Escalation (CVSS 7.8) ACTIVE RANSOMWARE EXPLOITATION

CISA confirmed October 31, 2025 that this vulnerability is being actively exploited in ransomware campaigns. This use-after-free flaw in the Linux kernel’s netfilter component allows attackers with local access to gain root privileges. Shockingly, the vulnerability was present in the Linux kernel for over 10 years (code from February 2014) before discovery in January 2024.​

Impact: Root access enables ransomware operators to disable endpoint protections, clear logs, encrypt critical files, and establish persistent backdoors. With privileged access, attackers can launch full ransomware operations against Linux infrastructure.​

Risk: Legacy and seldom-used Linux systems may still be exposed, creating open surfaces for ransomware attacks.​

CVE-2024-50623 & CVE-2024-55956: Cleo MFT Products ACTIVE RANSOMWARE CAMPAIGNS

Critical remote code execution vulnerabilities affecting Cleo Harmony, VLTrader, and LexiCom, impacting over 4,200 users including Fortune 500 companies. The initial patch (version 5.8.0.21) was bypassed by attackers on December 3, 2024, with exploitation spiking dramatically by December 8.​

Impact: At least 10 organizations hit by ransomware attacks using these vulnerabilities as entry points. Attackers achieved arbitrary file write leading to full system compromise.​

CVE-2025-5086: DELMIA Apriso Manufacturing Software (CVSS 9.0) ACTIVELY EXPLOITED

Added to CISA’s Known Exploited Vulnerabilities catalog in September 2025 after confirmed exploitation. This deserialization vulnerability in Dassault Systèmes’ manufacturing operations software (affecting Release 2020 through Release 2025) allows unauthenticated remote code execution.​

Impact: Attackers deploy Zapchast trojan for keylogging, screenshot capture, and data exfiltration via FTP. Federal agencies must patch by October 2, 2025.

CVE-2024-3400: Palo Alto GlobalProtect

Remote code execution on Palo Alto firewalls exploited in Operation MidnightEclipse by China-nexus APTs. Attackers deployed stealthy backdoors and exfiltrated network configurations. This vulnerability demonstrates how internet-facing security devices themselves have become prime targets compromising the very infrastructure meant to protect organizations.​

CVE-2025-32756 & CVE-2025-32701: Fortinet & Windows Zero-Days (Critical) MAY 2025 TOP CVES

CVE-2025-32756 (Fortinet products): Stack-based buffer overflow allowing remote, unauthenticated code execution with SYSTEM privileges. Affects FortiVoice, FortiMail, FortiNDR, FortiRecorder, and FortiCamera.​

CVE-2025-32701 (Windows CLFS): Use-after-free vulnerability linked to PipeMagic malware and ransomware deployments. Attackers escalate from low-level access to SYSTEM privileges, then deploy ransomware with full administrative control.​

Both vulnerabilities rank among the Top CVEs of May 2025 and have been added to CISA’s KEV catalog.​

How Wizard Cyber Can Help

“24/7/365 Managed SOC Services”

The holiday vulnerability gap exists because internal IT teams take time off exactly when attackers strike hardest. Wizard Cyber’s 24/7/365 Security Operations Center ensures continuous protection regardless of holidays, weekends, or staff vacations.

Wizard Cyber’s Detection & Response Services provide:

  • AI and machine learning-powered threat detection that identifies anomalies in real-time
  • Complete security coverage: detect, investigate, and respond to threats around the clock
  • Global SOC infrastructure maintaining full staffing during all holiday periods
  • Rapid incident response with clearly defined escalation and communication protocols
  • Phishing Detection Solutions.
  • Custom Threat Intelligence Feeds for Phishing and ClickFix
CYBERSECURITY READINESS

Strengthen Your Cyber Defences Today

As cyber threats grow more complex, proactive detection is no longer optional.

With Wizard Cyber’s Microsoft expertise, organizations can transform their security posture and gain real-time visibility across all endpoints.

Start your journey to smarter, faster cybersecurity today.

EXPLORE MORE

Related Blogs & Insights

Discover blogs that deepen your knowledge and accelerate your security strategy.

Mohammad A’mir & Dyaa Soussan

Cyber Shield Intelligence (CSI) Team

Cyber Shield Intelligence (CSI) Team

Wizard Cyber’s first line of defense in proactive threat intelligence. CSI is dedicated to the identification, monitoring, and analysis of emerging cyber threats, including activity across the dark web, underground forums, and threat actor infrastructure. Leveraging advanced threat intelligence platforms, OSINT tools, and adversary tracking methodologies, the team provides actionable intelligence to anticipate attacks before they occur. With expertise in threat actor profiling, TTP mapping (aligned with the MITRE ATT&CK framework), and IOC enrichment, CSI equips clients with the critical insights needed to fortify defenses, mitigate risk, and stay ahead of evolving threat landscapes.

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation