Sustainability report 2024-2025

  • Download center
  • Sitemap
  • History
  • Download PDF page
На русском ru
На русском ru

How we combat cybercrime

GRI 3-3

As we scale security, we develop global cooperation with law enforcement agencies and the professional community, enhancing our expertise and helping improve anti‑cybercrime legislation.

We cultivate international cooperation to combat digital offenses

Modern cybercrime knows no boundaries. No single country or organization can cope with this threat alone. A unified effort is required to fight it. That's why we actively cooperate with international organizations, government bodies and law enforcement agencies, helping protect people and companies from cyberthreats.

Kaspersky brings transparency and accountability to this cooperation. Our internal policies establish a clear procedure for handling requests from law enforcement and government bodies. Each request undergoes a legal review according to established criteria and, if necessary, may be rejected or challenged. Moreover, we never provide access to our infrastructure or systems storing user data.

Key documents

  • Kaspersky's internal policy governing how law enforcement requests are to be handled (approved in September 2021 by the Company's top managers)
  • Agreement with INTERPOL on jointly combating cybercrime under the Gateway project
  • Agreement with AFRIPOL on cooperation in preventing and combating cybercrime
  • Memorandums of cooperation with various cybersecurity agencies and law enforcement agencies

We conduct joint operations with INTERPOL and AFRIPOL

Kaspersky has been cooperating with INTERPOL in the fight against cybercrime since 2014. In 2019, we also signed an agreement to join the Gateway project.

The support we provide to law enforcement organizations includes:

  • exchange of expert information on the latest types of malware and cyberattack methods
  • participating in joint operations around the world to identify and combat cybercrime
  • cybersecurity training and consulting for INTERPOL and other law enforcement agencies

In 2024, we also formalized our collaboration with AFRIPOL by signing a five‑year agreement to combat cybercrime in Africa.

Results of joint operations

> 2,600
suspected criminals arrested in 2024–2025

During the reporting period, Kaspersky announced the results of seven joint operations with INTERPOL and AFRIPOL, which resulted in the arrest of over 2,600 suspected criminals.

We expand our partner ecosystem

Together with INTERPOL, Kaspersky provided cybersecurity for major events.

  • 2024 Summer Olympics in Paris — Our experts helped detect phishing attacks and other fraudulent activity. We provided cyberthreat intelligence to INTERPOL as part of Project Stadia, INTERPOL's initiative to protect major international events.
  • Singapore Grand Prix, as part of the 2025 Formula One World Championship — We provided cyberthreat intelligence to protect participants from digital risks.

In addition to INTERPOL and AFRIPOL, our partners in combating cybercrime include:

  • No More Ransom (jointly with Europol) — Over nine years of work, this alliance has helped more than 6 million users recover their data without paying ransom
  • Coalition Against Stalkerware
  • Geneva Dialogue
  • Paris Call for Trust and Security in Cyberspace
  • Council of Europe
  • World Internet Conference (member of the High Level Advisory Council)
  • International Telecommunication Union
  • International Organization for Standardization (ISO)
  • Smart Africa Alliance and many other organizations
We expand our partner ecosystem

In 2025, the Company became a member of the International Telecommunication Union's Telecommunication Development Sector (ITU‑D) and actively participated in global cybersecurity forums.

We research targeted attacks and advanced threats

According to our Kaspersky Managed Detection and Response (MDR) report, in 2025, advanced targeted attacks (APTs) were detected in 25% of companies and accounted for 43% of all high‑severity incidents. APTs were detected in all sectors except telecommunications, with IT and the public sector being the hardest hit.

Moreover, the number of APTs has increased significantly —
by   74 %
compared to 2023

In 2025, we identified and helped fix a critical zero‑day vulnerability in Google Chrome (CVE‑2025‑2783) used in Operation ForumTroll, a series of sophisticated cyberattacks against Russian organizations. During the research, experts from Kaspersky GReAT discovered for the first time that spyware created by the Italian company Memento Labs (formerly HackingTeam) was being used in real‑world attacks.

Additionally, Kaspersky GReAT experts discovered a new PassiveNeuron cyberespionage campaign targeting Windows Server systems in government, financial, and industrial organizations in Asia, Africa and Latin America (from December 2024 to August 2025).

Key trends in cyberthreat landscape

Phishing and spam campaigns

In 2024–2025, we blocked more than 1.4 billion clicks on phishing and scam links worldwide. Attackers prolifically create fake pages impersonating major brands in order to steal users' credentials and money.

Threats in the financial sector and sophisticated attacks

In 2025, the financial sector faced multilayered threats: attacks on users’ smartphones with banking Trojans as well as NFC-relay attacks, attacks through instant messaging apps and telephone fraud and supply chain attacks.

Increased financially‑motivated crime

In 2025, the number of unique financial‑sector users encountering ransomware increased by 35.7% compared to 2023 Data for the period November 2024 to October 2025 compared to November 2022 to October 2023. .

Automated attacks and the use of AI

Attackers actively use machine learning and automation to spread malware more efficiently and evade detection by security solutions.

Threats to mobile devices

The number of Trojan banker attacks on Android smartphones increased by 56% in 2025 compared to 2024.

Supply chain attacks

Almost 19,500 malicious packages were found in open‑source projects by the end of 2025, representing a 37% increase compared to the end of 2024.

We help develop legislation

With our extensive expertise in critical infrastructure protection, cybercrime, and data protection, we regularly participate in working groups and public consultations to develop international and national regulations aimed at ensuring global cybersecurity.

Kaspersky was an active participant in the development of the UN Convention against Cybercrime, the first‑ever universal international treaty on information security, adopted in December 2024. In October 2025, Eugene Kaspersky spoke at a panel discussion on global cooperation in cybersecurity capacity‑building programs, which was held as part of the convention signing ceremony in Hanoi.

We also presented our proposals during discussions of the UN Global Digital Compact (adopted in September 2024), focusing on improving digital literacy, training specialists, the safe use of AI and countering stalkerware.

We help develop standards

Kaspersky contributes to the development of international and national standards related to cybersecurity and the secure development of digital solutions.

During the reporting period, Kaspersky experts helped develop an ISO international standard for the Internet of Things.

It describes the key factors that contribute to the reliability and trust of IoT devices and establishes the basis for more secure and sustainable development of IoT ecosystems.

We share our expertise

We are passionate about sharing our cybersecurity expertise by speaking at major events and organizing our own conferences, such as the Security Analyst Summit, with representatives from law enforcement agencies, government bodies and the academic community. We publish information about cyberthreats in our own blog, threat intelligence reports, malware research, APT analysis and statistics via our securelist blog and conduct free webinars on cybersecurity.

In 2024–2025, our experts participated in numerous cybersecurity forums and conferences, including:

  • UN Open‑Ended Working Group on Information and Communication Technologies (within an informal dialogue under the auspices of the Chair of the OEWG)
  • consultations of the UN Ad Hoc Committee to Elaborate a Comprehensive International Convention on Countering the Use of Information and Communications Technologies for Criminal Purposes.
  • UN Internet Governance Forum, UN Global Digital Compact
  • African Cyber Defense Forum.
  • Geneva Dialogue working groups
  • INTERPOL expert working groups
  • World Internet Conference (China)
  • Cyber Security Summit (China)
  • it‑sa Expo&Congress (Germany)
  • Singapore International Cyber Week (Singapore)

From November 2025 to March 2026, Kaspersky experts conducted the “Security Operations and Threat Hunting” online training course for around 40 law enforcement officers from 23 AFRIPOL member states.

Results of work combating threat actors

In 2025, Kaspersky's cyberthreat detection systems detected an average of 500,000 malicious files per day—7% more than in 2024 See the Kaspersky Security Bulletin 2025. The statistics in the report cover the period from November 2024 to October 2025. .

Number of malicious files detected each day by Kaspersky, thousands
202120222023202420255004003002001000380400411467500
Results of work combating threat actors
  • GReAT has uncovered evidence linking the HackingTeam successor, Memento Labs, to a new wave of cyberespionage attacks using Dante spyware. The discovery stems from an investigation into Operation ForumTroll, an Advanced Persistent Threat (APT) campaign that exploited a zero‑day vulnerability in Google Chrome. The research was presented at the Security Analyst Summit 2025, taking place in Thailand.
  • Kaspersky Threat Research expertise center has discovered a new data‑stealing Trojan, SparkCat, active in AppStore and Google Play since at least March 2024. This is the first known instance of optical recognition‑based malware appearing in AppStore. SparkCat uses machine learning to scan image galleries and steal screenshots containing cryptocurrency wallet recovery phrases.
  • Kaspersky’s Global Research and Analysis Team (GReAT) have uncovered an ongoing cyberespionage PassiveNeuron campaign, that targets Windows Server systems in government, financial and industrial organizations across Asia, Africa and Latin America. The activity has been observed since December 2024 and continued through August 2025.
  • Kaspersky’s Global Emergency Response Team has identified a previously unseen ransomware strain in active use, deployed in an attack following the theft of employee credentials. The ransomware, dubbed “Ymir,” employs advanced stealth and encryption methods. It also selectively targets files and attempts to evade detection.

Our plans for 2026

  • Help shape the legal framework for combating cybercrime.
  • Train and upskill experts, conduct training sessions on relevant cybersecurity topics.
  • Collaborate with external organizations and establish partnerships with government institutions to share information on cyberthreats.
  • Regularly update software and technology for reliable protection against cyberthreats.