Check Point Warns Global Cyberattacks Have Entered a Fundamentally New and More Dangerous Phase

Check Point’s latest threat report signals a structural shift in global cyberattacks, driven by AI, state actors, and eroding deterrence.

Check Point Warns Global Cyberattacks Have Entered a Fundamentally New and More Dangerous Phase

Cyberattacks worldwide are no longer escalating in degree — they are changing in kind. That is the central warning from Check Point Software Technologies, whose latest threat intelligence findings, reported by Calcalist Tech, describe a structural inflection point in global cyber conflict that security professionals and defense planners alike should take seriously. The company’s researchers characterize the current environment as the opening of “an entirely new phase of the digital arms race,” one driven by the convergence of artificial intelligence, increasingly aggressive state-sponsored actors, and the erosion of previously understood deterrence norms.

The assessment arrives at a moment when unconventional threats are reshaping how military and security establishments think about the battlespace. Check Point’s data shows that global cyberattacks increased by 44 percent in 2024 compared to the prior year — a figure that underscores not merely a volumetric spike but a systematic expansion of adversarial capability and ambition. Organizations worldwide averaged 1,673 attacks per week during the period analyzed, according to the Calcalist Tech report on Check Point’s findings.

a large cybersecurity operations center with illuminated monitor arrays displaying global network threat maps, workstations in the foreground, low ambient lighting

AI as Accelerant: Automation Lowers the Bar for Sophisticated Attacks

Central to Check Point’s argument is the role artificial intelligence now plays on both sides of the threat landscape. Attackers are using AI to automate reconnaissance, generate convincing phishing content at scale, and accelerate vulnerability exploitation in ways that compress the window between a flaw’s discovery and its weaponization. The company notes that AI-assisted attack tooling is no longer the exclusive domain of well-resourced nation-state actors — it has proliferated into criminal ecosystems, effectively democratizing capabilities that once required significant technical depth.

That proliferation carries direct implications for critical infrastructure and defense-adjacent industries. Check Point’s research identifies the education and research sector as the most heavily targeted vertical globally, absorbing the highest average weekly attack volume. Government and military organizations, utilities, and healthcare providers also ranked prominently among targeted sectors — a pattern consistent with adversaries seeking either intelligence value or disruptive leverage. The report does not attribute specific campaigns to named state actors, but its framing of a “digital arms race” implicitly acknowledges that geopolitical competition is a primary driver of the trend.

server rack infrastructure inside a secured data center facility, cable bundles visible along the floor, reinforced door in the background

Regional Hotspots and the Industrial Security Imperative

Geographically, Check Point’s findings show that no region is insulated. Africa recorded the highest average weekly attacks per organization, while Europe and North America saw steep year-over-year increases. The report highlights ransomware as a persistent and evolving instrument — ransomware groups publicly named victims on so-called leak sites at a rate that Check Point’s researchers describe as alarmingly consistent throughout 2024, with over 5,400 organizations listed across tracked incidents. Officials have not publicly confirmed the full attribution picture behind those campaigns.

The industrial and manufacturing sectors registered significant attack growth, a development with particular relevance to defense supply chains. As governments push domestic production of critical military hardware — a trend visible in programs from missile components to semiconductor fabrication — the cyber exposure of that industrial base becomes a strategic liability, not merely a commercial one. Defense primes and their tier-two suppliers operating legacy operational technology networks face an environment that Check Point’s researchers suggest has permanently shifted in adversary favor unless defensive investment accelerates proportionally. The company stops short of prescribing specific remediation architectures, but its overarching message is unambiguous: the threat tempo of 2024 is not an anomaly to weather but a baseline to plan against. For defense industrial partnerships and sovereign capability programs alike, securing the digital layer is now as foundational as securing the physical one.

Follow Global Defense Digest

Subscribe

To receive updates about new articles, or opt in to our daily digest!

Choose one:

We don’t spam! Read our privacy policy for more info.

Subscribe

To receive updates about new articles, or opt in to our daily digest!

Choose one:

We don’t spam! Read our privacy policy for more info.

Leave a Reply

Your email address will not be published. Required fields are marked *