Site icon techcoffeehouse.com

Kaspersky: APAC breaches hide undetected for months

Advertisements

Cyberattacks across Asia Pacific are going undetected for months at a time, according to a new report from the Kaspersky Compromise Assessment division. The report found that in 31% of incidents analysed, malicious activity had persisted for more than three months before discovery, while 52% of high-severity compromises were only uncovered after 90 days. The oldest incident identified over the past year remained undetected for as long as four years.

“You cannot defend what you cannot see,” said Adrian Hia, Managing Director for APAC, Kaspersky. He said one of the region’s biggest cybersecurity challenges is that AI-backed attackers are moving faster than organisations can see, understand and respond to them, as speed and connectivity reshape enterprises and widen blindspots across IT and operational technology (OT) environments.

AI-native attacks widen the visibility gap

Kaspersky said it detected and blocked half a million unique malicious files daily last year, 7% higher than in 2024, and pointed to recent incidents showing the divide between online and physical systems has largely disappeared. A cyberattack on Nichirei Corp disrupted its logistics network, while India’s manufacturing sector has become an APAC hotspot for industrial ransomware, with attackers repeatedly paralysing factory floors and industrial IT services.

“AI agents introduce a new supply chain layer — this year alone, Kaspersky has identified over 15,000 malware samples disguised as agentic AI software,” said Hia. “As threats become AI-native and defenses AI-powered, APAC organisations must look beyond just stopping attacks and ask whether they actually have visibility into what’s already happening inside their environments.”

Because AI agents dynamically depend on third-party frameworks, APIs and plugins, Kaspersky warned that a single compromised upstream dependency can cascade across downstream systems, widening the surface for cyber sabotage and cyberespionage. The findings point to a broader gap in security operations: many organisations have invested in security technology, but technology alone cannot compensate for gaps in monitoring, detection and operational readiness.

Building AI-powered SOCs to restore visibility

“Our recent report highlights why a modern, unified SOC is becoming business-critical,” Hia said. “When organisations rely on reactive security practices or lack continuous monitoring, attackers gain valuable time to move laterally, escalate privileges, and compromise critical assets. A mature SOC shortens that window by providing the visibility, expertise, and operational discipline needed to detect threats before they become major incidents.”

Kaspersky has been building machine learning models since 2004, trained on anonymised global telemetry collected from millions of endpoints worldwide. “AI isn’t an add-on at Kaspersky. For the past 20 years, AI has been embedded across our entire technology stack, enabling faster detection, smarter automation, and consistent protection,” Hia said, describing the company’s approach as “HuMachine Intelligence” — combining AI with human expertise rather than treating them as alternatives.

Enterprises managing complex IT infrastructures can draw on the Kaspersky Next product line for real-time protection, threat visibility and EDR/XDR investigation and response, with generative AI models built in to convert raw data into actionable intelligence for security teams. Kaspersky also offers managed services including Compromise Assessment, Managed Detection and Response (MDR), Incident Response and SOC Consulting, covering the full incident management cycle from threat identification through to remediation.

Author

Exit mobile version