Why cybercriminals are targeting MSPs first | #cybercrime | #infosec


The growth of supply chain attacks in 2025 has reshaped breach economics. Instead of targeting organisations one by one, cybercriminals are increasingly exploiting centralised third-party platforms to gain access to entire customer ecosystems.

In practice, this means risk is moving upstream. When trusted service layers are compromised, incidents rarely stay contained and can spread across multiple customer environments – raising the bar for security, visibility and resilience at the provider level.

Recent warnings from the UK government underline how quickly evolving technologies – particularly AI – are supercharging attackers’ ability to locate and exploit access points at scale. MSPs have become an attractive point of entry, making their security practices the focus of customers and regulators alike.

Group-IB’s High Tech Crime Trends research highlights how threat actors are increasingly prioritising access to high-trust sectors such as financial services, SaaS platforms and MSP environments. For MSPs, this shifts the risk profile significantly, with phishing, ransomware and credential theft remaining a persistent challenge.

Why attackers are targeting MSP ecosystems

Modern organisations depend on MSPs not just for operational efficiency, but for secure access management, infrastructure resilience and regulatory alignment. MSP platforms sit at the intersection of customer networks, cloud services, SaaS applications and identity environments. This position makes MSPs stewards of inherited trust across entire business ecosystems – when that trust is compromised, the consequences extend far beyond a single organisation.

Rather than targeting organisations individually, attackers are increasingly focusing on centralised environments. These platforms offer a multiplier effect, allowing a single compromise to impact multiple downstream clients. Remote monitoring and management platforms, multi-tenant administration consoles and aggregated identity systems have become high-leverage entry points for threat actors. Once inside, attackers can move laterally, harvest credentials, conduct reconnaissance and deploy payloads across multiple customer environments.

In practice, this type of access allows attackers to observe customer environments over extended periods. With this intelligence, threat actors can identify high-value targets and tailor follow-on attacks with greater precision. In some cases, compromised MSP credentials have been used to disable security tools or deploy malicious updates under the guise of legitimate maintenance activity.

Campaigns attributed to groups such as DragonForce demonstrate how exploitation of MSP tooling can enable credential theft, data exfiltration and ransomware deployment at scale. Group-IB’s close collaboration with international law enforcement bodies, including INTERPOL and Europol, has played a key role in tracking and disrupting campaigns of this nature.

The industrialisation of cybercrime meets the managed services model

The convergence between industrialised cybercrime and the managed services model reflects a broader shift in how cybercrime operations are structured and scaled. In practice, this means the creation of affiliate programmes, service platforms and monetisation strategies designed to maximise efficiency. Attackers have adopted the same logic as managed services: centralise access, standardise operations and scale efficiently.

For attackers, this presents a significant opportunity. For MSPs, it raises the stakes considerably. This shift shortens the window MSPs have to identify and stop attacks. Industrialised cybercrime relies on speed and standardisation. If one approach proves effective in one MSP environment, it can be rapidly replicated elsewhere – exploiting the shared tools and models that underpin managed services.

The priority for MSPs becomes breaking attack patterns before they can be replicated across multiple customer environments. As cybercrime operations gain speed, the margin for error narrows significantly.

How expectations of MSP security are changing

As threat exposure grows, customers are becoming more discerning about the security practices of their MSPs.

Customers are increasingly evaluating MSPs based on governance transparency, identity security controls, incident readiness and third-party risk management practices. Regulatory frameworks such as NIS2 are reinforcing expectations around operational accountability and supply chain oversight. Security is no longer just a technical feature – it is increasingly treated as a business-wide issue. Resilience maturity is becoming the dividing line between strategic MSPs and commodity providers.

Forward-looking MSPs are strengthening privileged access controls, monitoring behavioural anomalies across multi-tenant environments, segmenting client infrastructures and conducting continuous supply chain risk assessments. These measures help reduce risk and limit the potential impact of compromise across customer environments.

What this means for MSPs going forward: Intelligence-led defence

As digital environments become more interconnected, reactive security models are proving insufficient. MSPs should adopt an adversary-centric approach, using threat intelligence to monitor how specific attacker groups operate, which tools they exploit and how campaigns typically unfold.

This approach enables earlier detection of suspicious behaviour and faster disruption of attack chains before compromise spreads downstream. It also allows MSPs to anticipate emerging risks across their customer base, rather than responding only after incidents occur.

Critically, this intelligence must be both global and locally relevant. Gathering local intelligence from teams located across the regions they operate in enables the translation of global adversary intelligence into region-specific insights with those who know the market best. For MSPs serving local markets, this ensures threat intelligence is directly applicable to their operating environment and customer base allowing them to better track and respond to threats.

Those MSPs that adapt to this model will be better positioned to operate in an increasingly complex threat landscape.

MSPs are no longer just managing infrastructure – they are safeguarding access, visibility and the control layers that modern business depends upon.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW