Hewlett Packard Enterprise (HPE) has released findings from its first In the Wild threat research report, revealing a major shift in how cyber adversaries operate across industries and public infrastructure worldwide. Drawing on real-world threat activity tracked throughout 2025, the report shows that cybercrime has evolved into a highly organized, scalable ecosystem driven by automation, coordination, and repeatable attack methods.
The study analyzed 1,186 active threat campaigns recorded between January and December 2025. The findings point to a threat landscape defined by speed, scale, and precision targeting. Attackers are increasingly using shared infrastructure, established vulnerabilities, and standardized workflows to repeatedly compromise high-value targets faster than many organizations can respond.
Government entities were the most targeted, accounting for 274 campaigns across national, state, and local systems. Financial services and technology sectors followed, with 211 and 179 campaigns respectively, reflecting sustained focus on data-rich and revenue-driven environments. Additional sectors under pressure included defense, manufacturing, telecommunications, healthcare, and education, underscoring the broad exposure of critical infrastructure.
Over the course of the year, threat actors deployed more than 147,000 malicious domains, nearly 58,000 malware variants, and exploited 549 known vulnerabilities. Many of these operations were structured similarly to large enterprises, with defined roles, coordinated execution, and continuous scaling of attack infrastructure.
The report also highlights the growing use of automation and artificial intelligence to increase efficiency and impact. In some cases, attackers used automated workflows on messaging platforms to extract stolen data in real time. Others employed synthetic media, including AI-generated voices and videos, to carry out impersonation fraud and targeted phishing campaigns.
To counter these developments, the report emphasizes the need for stronger coordination across security systems rather than simply adding more tools. Recommended measures include improving threat intelligence sharing, addressing commonly exploited entry points such as VPNs and edge devices, and adopting zero trust frameworks to limit unauthorized access. Enhancing visibility through advanced detection technologies and extending security practices beyond corporate networks are also identified as critical steps.
The report reflects a broader shift in cyber risk, where attackers operate with increasing discipline and efficiency. Organizations are urged to strengthen resilience by aligning strategy, technology, and response capabilities to keep pace with this evolving threat environment.