Threat Intelligence, Cloud Security

Attackers focus on recovery systems in cloud environments

Major cloud platforms targeted by TRIPLESTRENGTH hacking operation. (Adobe Stock)

Google Cloud's latest Cloud Threat Horizons Report H2 2025 highlights the rising sophistication of cyber threats targeting cloud environments and warns that attackers are increasingly focusing on recovery and backup systems, according to Security Brief Australia.

Credential compromise remains the top threat vector, responsible for 47.1% of incidents, while misconfigurations and API or user interface compromises contributed to 29.4% and 11.8%, respectively. The report notes a surge in backup sabotage, with attackers deleting routines, corrupting data, and manipulating permissions to amplify ransom leverage. Advanced social engineering is enabling multi-factor authentication bypass, particularly by North Korea-aligned group UNC4899, which targets cryptocurrency platforms. Attackers are also abusing trusted cloud services like Google Drive, GitHub, and Dropbox to host decoy files that silently deploy malware. Google Cloud advises a multi-layered defense, including robust identity and access management, credential hygiene, isolated recovery environments, and supply chain security validation. "Recovery systems are now primary targets, signalling an urgent need for stronger defensive posture across identity, access, and infrastructure resilience," the report states.

An In-Depth Guide to Cloud Security

Get essential knowledge and practical strategies to fortify your cloud security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds