Content Benefit

Content Strategy | UX Writing | Content Design | Globalization | Communications

Cybersecurity: growing pains

Cybersecurity: growing pains

Cybersecurity: an attack every five minutes, and I’m starting to worry

I’ll admit it: I have never been the victim of a cyberattack. No drained account, no hijacked profile, no files held hostage. And yet, over the past few months, something has shifted. The attempts landing on my screen are increasingly sophisticated, polished, almost believable. The fake contact requests churned out by bots have become a permanent fixture in my notifications, and the feeling of being watched by something automated and patient is beginning to weigh on me. Then I read an article in Corriere della Sera that put a number on my unease: in Italy, in 2025, there was a cyberattack every five minutes.

The Italian figures: 116,498 attacks in a year

According to Tinexta Cyber’s Threat Landscape 2025, cited by Corriere, our country recorded 116,498 cyberattacks over the year, or 2,249 a week. A frequency 17% higher than the global average. Ransomware, meaning the digital blackmail that comes with a ransom demand, grew by 48%, peaking in July.

The number that struck me most, though, is another one: one intrusion in three starts from stolen credentials. No break-in, no spectacular viruses. Criminals simply log in with our passwords, bought on illegal marketplaces where the supply of compromised data rose by more than 40% in a single year.

The international picture offers no comfort

Widen the lens and the global scene confirms the trend. The Clusit 2026 Report counted 5,265 serious incidents worldwide in 2025, up 49% on the previous year and 157% over five years. Financially motivated cybercrime accounts for 90% of cases, and one episode in three is now rated critical or extreme in severity.

Across the planet, there are over 1.2 billion known malicious programs in circulation, with a daily output of fresh variants swinging between 450,000 and 560,000. In 2025, roughly 15 billion stolen credentials were identified. Figures that convey the shape of a genuine industry, organized and profitable, a far cry from teenagers in a basement.

Italy is a favourite target

Here is something that should give us pause: our country, while representing about 2% of world GDP, suffers 9.6% of the serious incidents logged globally. Again, according to Clusit, the grave episodes registered in Italy in 2025 numbered 507, up 42%. Some 64% of the world’s hacktivism, meaning the offensives driven by political and ideological motives, hits precisely us, and Italian manufacturing alone absorbs 16% of the blows dealt to the sector internationally.

Meanwhile, the national cybersecurity market is worth 2.778 billion euros, just 0.13% of GDP, less than half the average of the other G7 countries. We invest little, and it shows.

Artificial intelligence has changed the rules

This is where my worry really kicks in. In 2025, the first case of extortion generated entirely by an artificial intelligence model was observed, capable of adjusting messages, timing, and methods according to the victim’s reactions. Badly written phishing, riddled with errors and easy to spot, belongs to the past: today the messages are contextual, built on real data lifted beforehand, and they adapt on their own.

I have already written about AI’s impact on our jobs in AI and the labor market. However, the darker side of the same technology moves even faster: generative tools and “bot as a service” platforms let even attackers with minimal skills launch campaigns on a large scale.

Bots have overtaken humans

My fake contact requests have a precise statistical explanation. According to Imperva’s Bad Bot Report, for the first time in a decade, automated traffic has overtaken human traffic, reaching 51% of the total. Malicious bots alone make up 37% of all internet traffic, rising for the sixth consecutive year.

Account takeover breaches, meaning the outright theft of a profile, grew by 40% in a single year, with financial services as the preferred target. No surprise that digital payment systems are so tempting: I touched on this when writing about Google Wallet and its shift toward a super-app and the promises of Web 3.0 between crypto and payments. The more our economic life runs through the smartphone, the more appealing it becomes to anyone automating fraud.

When it happens to someone you know

These statistics stopped feeling abstract to me the day one of my friends was hit. His WhatsApp profile was stolen, and to this day it is unclear how they managed it. Shortly afterward, a message from him reached me with a request for a bank transfer, written convincingly enough to deserve at least a moment’s doubt. I called him right away to warn him and, of course, I sent nothing.

The rest of the story is perhaps the most tragicomic part. He reported everything to the relevant authorities, but the complaint did not resolve much: recovering a compromised account and tracing whoever is using it is anything but simple. In the end, it was the fraudsters themselves who gave up, after sending money requests to a good chunk of his contacts without collecting a cent. The lesson I drew from it is twofold: the verification phone call to anyone asking you for money over chat is worth more than any antivirus, and prevention remains the only truly effective defense, because after-the-fact remedies almost always arrive too late.

What we can actually do

My worry, in the end, turned into a few new habits. Two-factor authentication wherever it’s available, a password manager in place of the usual three recycled keywords, and a healthy distrust of any contact request from profiles I’ve never seen before, however plausible they may look. If one attack in three starts from stolen credentials, protecting your own is already half the battle.

We also need a collective mindset shift: cybersecurity has become a strategic factor that affects the economy, essential services, and people’s trust, as Andrea Monti of Tinexta Cyber has pointed out. Waiting until you become a victim before dealing with it strikes me, frankly, as the worst possible strategy.

Related sources