The holiday season has become the most dangerous period for cybersecurity incidents, with ransomware attacks surging 30% during November-December compared to monthly averages.
The holiday season has become the most dangerous period for cybersecurity incidents, with ransomware attacks surging 30% during November-December compared to monthly averages. Analysis of major breaches from 2020-2025 reveals that cybercriminals systematically exploit reduced IT staffing, distracted employees, and rushed business operations during holidays to launch devastating attacks. In December 2024 alone, a record 574 ransomware attacks occurred globally, while phishing campaigns spiked 46% above normal levels.
The threat landscape has evolved dramatically. Average ransom demands have massively increased 253% from $310,000 in 2020 to $1.1 million in 2025, and recent incidents like Change Healthcare’s breach affecting 192.7 million individuals demonstrate unprecedented scale. With emerging attack techniques including AI-powered phishing, reverse proxy tools like Evilginx bypassing multi-factor authentication, and ClickFix social engineering campaigns, organizations face more sophisticated threats than ever before.
This critical alert provides actionable intelligence on holiday threat patterns, recent major incidents, 2025 attack forecasts, and defensive strategies including how organizations can maintain robust security even when IT teams are off during the holidays.
Key
Statistics
The data demonstrates clear patterns of strategic timing by threat actors:
30% increase in ransomware attacks during holiday periods (November-December) versus monthly averages
70% surge in attempted ransomware attacks during November-December compared to January-February
46% spike in phishing alerts during December relative to monthly averages
574 ransomware attacks recorded globally in December 2024 a record high
95% of data breaches stem from human errors, which spike dramatically when employees are distracted during holidays
Ransomware attacks increase by 30% during holiday periods compared to monthly averages (2018-2020)
Financial Impact
Escalation
The economic consequences of cyberattacks have grown exponentially:
Average ransom payments climbed 253% from $310,000 (2020) to $1.1 million (2025)
Global cybercrime costs projected to reach $10.5 trillion annually by 2025
Healthcare breach costs average $10.93 million per incident
Total ransomware economic damage reached $31.5 billion in 2025, up from $20 billion in 2020
Average cost per cyberattack incident by industry sector (in millions USD)
Healthcare remains the costliest target at $10.93 million average per breach, with the 2024 Change Healthcare attack affecting 192.7 million individuals, the largest healthcare breach in U.S. history. Retail experienced a 100% year-over-year increase in ransomware attacks from holiday 2022 to 2023, with payment card data the primary target (37% of breaches). Financial services face $5.9 million average breach costs, while entertainment and manufacturing sectors average $330,000 per incident.
Healthcare remains the costliest target at $10.93 million average per breach, with the 2024 Change Healthcare attack affecting 192.7 million individuals, the largest healthcare breach in U.S. history. Retail experienced a 100% year-over-year increase in ransomware attacks from holiday 2022 to 2023, with payment card data the primary target (37% of breaches). Financial services face $5.9 million average breach costs, while entertainment and manufacturing sectors average $330,000 per incident.
December 2020:
SolarWinds Supply
Chain Attack
Discovered December 13, 2020, the SolarWinds Orion attack represents one of the most sophisticated cyberattacks in history. Russian state-sponsored APT29 actors compromised SolarWinds’ software build process, injecting malicious code into updates distributed to approximately 18,000 organizations. Victims included the U.S. Department of Homeland Security, Department of Energy, and major corporations like Cisco and Intel. The attack remained undetected for months, with hackers patiently moving laterally through victims’ networks to access sensitive government data.
Supply chain vulnerabilities can create cascading impacts. Even trusted software vendors can become vectors for nation-state espionage.
December 2021:
Kaseya July 4th
Weekend Attack
While technically July, the Kaseya VSA attack exemplifies deliberate holiday timing, executed over the July 4th weekend when U.S. businesses were closed. The REvil ransomware group exploited zero-day vulnerabilities in Kaseya’s remote management software, affecting 800-1,500 businesses and demanding an unprecedented $70 million ransom. Swedish supermarket chain Coop was forced to close all 800 stores for nearly a week.
Holiday weekends provide optimal conditions for attackers to maximize disruption while minimizing detection risk.
December 2022:
LockBit, Royal, and
Play Ransomware Surge
December 2022 saw coordinated spikes across major ransomware groups during the “holiday gift season”:
LockBit regained dominance, breaching California’s Department of Finance (75GB, 246,000 files) and SickKids Hospital
Royal ransomware disproportionately targeted healthcare, breaching telecommunications company Intrado
Play ransomware surged 136%, exploiting Microsoft Exchange vulnerabilities to breach Rackspace cloud services during peak holiday shopping
ALPHV/BlackCat recorded 70% increase to highest attack volume of 2022
Multiple sophisticated ransomware groups operate simultaneously during holidays, creating overwhelming pressure on security teams.
December 2023:
Ohio Lottery
Christmas Eve Attack
DragonForce ransomware struck Ohio’s lottery system on Christmas Eve, disrupting internal applications and stealing over 3 million entries containing Social Security numbers, dates of birth, and personal information. The Christmas Eve timing maximized disruption while minimizing rapid response likelihood from government IT staff.
Government systems face particular vulnerability during holidays when staffing is minimal.
December 2024:
Record-Breaking
Month
December 2024 recorded 574 ransomware attacks globally, the highest monthly count on record:
BT Conferencing (Dec 3): Black Basta ransomware, 500GB data stolen
Texas Tech University (Dec 16): Interlock ransomware, 1.4 million patients affected, 2.6TB leaked
SRP Federal Credit Union (Dec 10): Nitrogen ransomware, 240,000+ members, 650GB stolen
Krispy Kreme (November-December): Play ransomware disrupted online ordering during peak holiday sales
West Haven, CT (Christmas Day): Government systems breached, municipal IT shut down
UK Local Councils (pre-Christmas): Westminster, Kensington & Chelsea affected, data copied before Christmas
The December 2024 surge demonstrates that attackers are intensifying holiday targeting, with record attack volumes and increasingly sophisticated tactics.
2025 Threat Forecast:
Emerging Attack
Techniques
Reverse Proxy Phishing & Clickfix
The vast majority of phishing attacks in 2025 now use reverse proxy techniques, fundamentally changing the threat landscape. Evilginx and similar adversary-in-the-middle (AiTM) tools bypass multi-factor authentication by intercepting credentials AND session tokens in real-time.
How it works:
Victim receives phishing link to fake domain (e.g., login-phishing.com)
Evilginx proxies authentication to legitimate service (accounts.microsoft.com)
Victim enters credentials and completes MFA on what appears to be the real site
Evilginx captures everything: passwords, MFA tokens, AND authenticated session cookies
Attacker imports session cookies for immediate account access, no need to bypass MFA
Critical statistics:
96% of suspicious phishing domains bypass traditional protections like blacklists and spam filters
EvilProxy (Phishing-as-a-Service variant) used in over 1 million account takeover attempts in early 2025
Attacks complete within minutes, before takedowns can occur
Detection challenge: These attacks use HTTPS with valid certificates, closely mimic legitimate domains, and employ user agent spoofing making them nearly indistinguishable from legitimate traffic.
ClickFix Social Engineering Campaign
ClickFix represents a dangerous evolution in social engineering, tricking users into manually executing malicious commands in both Windows and MacOS operating systems. First discovered in 2024, the technique saw massive deployment in 2025.
Attack mechanics:
Phishing email with HTML attachment or compromised website visit
Fake error message displays (“Word Online extension not installed” or “Windows Update required”, “Verify you are human by completing action below”)
Instructions tell user to press Windows+R, then CTRL+V to “fix” the problem
Malicious PowerShell command already copied to clipboard executes automatically
Command downloads malware: DarkGate, Lumma Stealer, NetSupport RAT, or Latrodectus
2025
Trends
ClickFix now is being delivered by malicious/fake google ads.
Now mimics full-screen Windows Update interface for maximum authenticity
AI-Powered Phishing
Generative AI has democratized sophisticated phishing attacks. ChatGPT-4o Mini and similar models can be “jailbroken” to generate convincing phishing content, enabling novice attackers to conduct professional-grade campaigns.
AI capabilities exploited by attackers:
Craft personalized spear phishing emails using public data from LinkedIn, social media
Generate phishing websites and content in minutes
Adapt messaging based on target’s role, industry, recent activities
Scale personalized attacks to thousands of targets simultaneously
Research shows that human-guided, AI-assisted attacks evade traditional anti-phishing mechanisms because they lack predictable patterns. LLMs enable attackers to produce context-aware phishing that appears legitimate even to security-aware users.
Phishing-as-a-Service (PhaaS) Explosion
Criminal platforms have industrialized phishing attacks. Over 1 million PhaaS attacks occurred in just the first two months of 2025, with platforms like EvilProxy and VoidProxy enabling non-technical criminals to launch sophisticated campaigns.
The PhaaS model provides:
Ready-made phishing kits with reverse proxy capabilities
Hosting infrastructure that rotates domains to evade blacklists
Customer support for criminal “clients”
Continuous updates to bypass new security measures
Affiliate models where malware developers rent tools to attackers
Recently Exploited
Critical Vulnerabilities:
CVE-2024-1086: Linux Kernel Privilege Escalation (CVSS 7.8) ACTIVE RANSOMWARE EXPLOITATION
CISA confirmed October 31, 2025 that this vulnerability is being actively exploited in ransomware campaigns. This use-after-free flaw in the Linux kernel’s netfilter component allows attackers with local access to gain root privileges. Shockingly, the vulnerability was present in the Linux kernel for over 10 years (code from February 2014) before discovery in January 2024.
Impact: Root access enables ransomware operators to disable endpoint protections, clear logs, encrypt critical files, and establish persistent backdoors. With privileged access, attackers can launch full ransomware operations against Linux infrastructure.
Risk: Legacy and seldom-used Linux systems may still be exposed, creating open surfaces for ransomware attacks.
CVE-2024-50623 & CVE-2024-55956: Cleo MFT Products ACTIVE RANSOMWARE CAMPAIGNS
Critical remote code execution vulnerabilities affecting Cleo Harmony, VLTrader, and LexiCom, impacting over 4,200 users including Fortune 500 companies. The initial patch (version 5.8.0.21) was bypassed by attackers on December 3, 2024, with exploitation spiking dramatically by December 8.
Impact: At least 10 organizations hit by ransomware attacks using these vulnerabilities as entry points. Attackers achieved arbitrary file write leading to full system compromise.
Added to CISA’s Known Exploited Vulnerabilities catalog in September 2025 after confirmed exploitation. This deserialization vulnerability in Dassault Systèmes’ manufacturing operations software (affecting Release 2020 through Release 2025) allows unauthenticated remote code execution.
Impact: Attackers deploy Zapchast trojan for keylogging, screenshot capture, and data exfiltration via FTP. Federal agencies must patch by October 2, 2025.
CVE-2024-3400: Palo Alto GlobalProtect
Remote code execution on Palo Alto firewalls exploited in Operation MidnightEclipse by China-nexus APTs. Attackers deployed stealthy backdoors and exfiltrated network configurations. This vulnerability demonstrates how internet-facing security devices themselves have become prime targets compromising the very infrastructure meant to protect organizations.
CVE-2025-32756 & CVE-2025-32701: Fortinet & Windows Zero-Days (Critical) MAY 2025 TOP CVES
CVE-2025-32756 (Fortinet products): Stack-based buffer overflow allowing remote, unauthenticated code execution with SYSTEM privileges. Affects FortiVoice, FortiMail, FortiNDR, FortiRecorder, and FortiCamera.
CVE-2025-32701 (Windows CLFS): Use-after-free vulnerability linked to PipeMagic malware and ransomware deployments. Attackers escalate from low-level access to SYSTEM privileges, then deploy ransomware with full administrative control.
Both vulnerabilities rank among the Top CVEs of May 2025 and have been added to CISA’s KEV catalog.
How Wizard Cyber Can Help
“24/7/365 Managed SOC Services”
The holiday vulnerability gap exists because internal IT teams take time off exactly when attackers strike hardest. Wizard Cyber’s 24/7/365 Security Operations Center ensures continuous protection regardless of holidays, weekends, or staff vacations.
Wizard Cyber’s first line of defense in proactive threat intelligence. CSI is dedicated to the identification, monitoring, and analysis of emerging cyber threats, including activity across the dark web, underground forums, and threat actor infrastructure. Leveraging advanced threat intelligence platforms, OSINT tools, and adversary tracking methodologies, the team provides actionable intelligence to anticipate attacks before they occur.
With expertise in threat actor profiling, TTP mapping (aligned with the MITRE ATT&CK framework), and IOC enrichment, CSI equips clients with the critical insights needed to fortify defenses, mitigate risk, and stay ahead of evolving threat landscapes.