Briefing

  • Moody's Ratings said on Monday that credit risks could rise in 2025 as cyber attackers use artificial intelligence to bypass defenses and increasingly target large companies capable of paying high ransoms.
  • "Facing declining revenue per victim, cyber attackers are seeking greater returns by demanding higher ransoms," Moody's said in the report. "We believe they are achieving this by targeting large enterprises that can afford higher ransom payments, and we expect this to increase cyber risks for Moody's-rated debt issuers."
  • Meanwhile, Moody's noted that cyber criminals in 2025 may face weaker resistance from the Trump administration, which may soften cyber defense regulations.

In-depth analysis

The U.S. Federal Bureau of Investigation's Internet Crime Complaint Center received a record 880,418 public complaints last year, up nearly 10% from 2022, with estimated losses exceeding $12.5 billion. The FBI said only a small portion of such crimes are reported.

The FBI said the number of ransomware attacks reported by the U.S. public rose 18% last year to 2,825,with losses surging 74%

"Cyber criminals continuously adapt their tactics, and the FBI has observed emerging ransomware trends, such as deploying multiple ransomware variants against the same victim and using data destruction strategies to increase pressure on victims during negotiations," the FBI said in a report.

Moody's said cyber criminals are increasingly deploying generative artificial intelligence tools in extortion and fraud activities.

"Phishing attacks designed to trick users into clicking malicious links will accelerate due to GenAI," the rating agency said. "GenAI tools will enable attackers to craft personalized and convincing text, audio, and video content that mimics legitimate communications from trusted entities."

Moody's noted that cyber criminals are increasingly able to penetrate the defenses of large enterprises by compromising the defenses of third-party software vendors. A successful attack on one vendor could open the door to ransomware and other crimes for many of that vendor's customers.

Moody's said stealing employee credentials is also one of the most favored techniques by cyber criminals. Citing IBM data, Moody's said the use of stolen credentials surged 71% last year compared to 2022, becoming the most common method of unauthorized access to corporate systems.

Moody's said the Trump administration may remove some regulatory obstacles that hinder wrongdoers.

"The government may revoke cybersecurity mandates and could limit the activities of the U.S. Cybersecurity and Infrastructure Security Agency," Moody's said. "This could expose issuers to higher risks of cyber attacks."

According to Leroy Terrelonge, vice president for cyber credit risk at Moody's Ratings, companies can use artificial intelligence to reduce cyber threats.

In an email responding to questions on Monday, Terrelonge said chief information security officers can use AI tools to translate cybersecurity risks into financial risks for company boards to assess.

"Cybersecurity professionals will be able to quickly examine suspicious activity using generative AI to determine key details, such as the type of attack, information about the attack's source, and possibly even learn more about the attack's targets, thereby assessing threats more quickly," he said.

"Today, these analyses require skilled practitioners using multiple tools, and often require translating between different tools' languages to get the job done," Terrelonge said.

He added that cybersecurity personnel will also be able to use generative AI to build customized security training programs, email campaigns, and other resources to inform employees about relevant risks.