Google Cloud’s December 2024 cybersecurity forecast expected more AI-assisted phishing and deepfake-enabled fraud in 2025, alongside continuing risks to manufacturing’s operational technology (OT). It also pointed to credentials and identity as critical targets. For readers, the practical lessons are to verify unusual requests through a separate trusted channel, understand how suppliers connect to industrial systems, and consider passkeys as a phishing-resistant sign-in option. These were forecasts, not a measured scorecard of what happened in 2025.
What Google Cloud predicted for 2025
Google Cloud’s December 2024 forecast anticipated that attackers would use artificial intelligence and large language models more often to create convincing phishing, voice phishing (vishing), SMS attacks and other social-engineering lures. It also expected cyber-espionage and cybercrime actors to experiment with AI for reconnaissance, vulnerability research, code development and information operations. These are the forecast’s expectations, not evidence of how prevalent each technique became.
The forecast also expected ransomware and multifaceted extortion to persist, and infostealer malware to remain consequential. Its infographic said ransomware or extortion had affected more than 100 countries “to date in 2024”; that is Google Cloud’s statement, not an independently validated count here. It anticipated that stolen credentials would continue to matter, especially where multifactor authentication (MFA) was not enforced.
How deepfakes can strengthen phishing
A voice or video impersonation can add apparent authority to a request that already depends on urgency, secrecy or pressure. In Google Cloud’s forecast, deepfakes could support identity theft and fraud, including attempts to bypass know-your-customer checks. The forecast does not quantify what share of 2025 phishing used deepfakes, so it cannot support a prevalence estimate.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
As a practical safeguard, treat an unusual request to move money, disclose credentials or grant access as something to verify independently—even if the voice or face seems familiar. Use a contact method already on file, such as a known phone number or established internal channel, rather than replying to the message or calling a number it provides. Authentication should not depend on recognizing a face or voice alone.
Why operational technology is a cybersecurity target
Operational technology controls or monitors physical processes, including industrial systems used in manufacturing and critical infrastructure. Google Cloud’s manufacturing commentary forecast that geopolitical pressures and state-backed activity could complicate manufacturers’ threat environment. It connected the convergence of IT and OT, interconnected technologies and data-driven operations with more potential routes for attackers.
Vinod D’Souza, head of manufacturing and industry in Google Cloud’s Office of the CISO, wrote that “The convergence of IT and OT systems for manufacturing, along with increased reliance on interconnected technologies and data-driven processes, will create new vulnerabilities for attackers to exploit.” The commentary anticipated risks including disruption to critical infrastructure, theft of intellectual property, and targeted ransomware affecting production lines or supply chains. These are attributed predictions, not confirmed attack counts.
Suppliers and remote access are part of the exposure
A manufacturer’s security depends in part on the systems and connections it relies on beyond its own organization. Google Cloud’s commentary warned that smaller suppliers and third-party vendors could be targeted as a route into larger manufacturing networks. For an organization, that makes supplier access, remote connections and the visibility of assets across IT and OT useful areas to review alongside the operational impact of a disruption.
Rank #3
CISA’s January 13, 2025 joint OT procurement guidance adds a procurement perspective: it describes critical infrastructure and industrial control systems as prime targets and warns that OT components may be targeted as products, not only through attacks on the organizations operating them. It advises operators to prioritize manufacturers that address security. Procurement decisions should therefore consider how a component is secured and supported, as well as how it fits operational safety and uptime needs.
What passkeys do—and what they do not guarantee
A passkey is a credential based on public-key cryptography. According to the FIDO Alliance, it is unique and bound to the online service it is used with. That service binding is the basis of passkeys’ phishing resistance: a passkey intended for one site cannot simply be used to sign in to a fake lookalike site.
Rank #4
Passkeys can be synced across devices through a provider, or bound to an individual device. A hardware security key can store a device-bound passkey. A passkey reduces exposure to password theft and phishing, but does not automatically eliminate account takeover: the service’s implementation and account-recovery process still matter.
Choose a passkey approach that fits your devices and recovery plan
| Option | Phishing resistance | Using multiple devices | Loss and recovery planning |
|---|---|---|---|
| Synced passkey | Service-bound and designed to resist phishing; implementation and recovery still matter. | Can be available on multiple devices through the provider that syncs it. | Plan around access to the syncing provider and the service’s recovery process. |
| Device-bound passkey | Service-bound and designed to resist phishing; implementation and recovery still matter. | Tied to a particular device rather than synced across devices. | Plan for loss or replacement of that device and confirm the account’s recovery route. |
| Hardware security key | A device-bound passkey stored on a hardware key offers service-bound phishing resistance. | Requires the key to be available when signing in; check which services support the method. | Consider a spare key or another recovery method before relying on one key. |
FIDO’s deployment guidance treats phishing resistance as a journey that includes improving both login and recovery, rather than a one-step switch. Before depending on any passkey method, check whether the important services you use support it and how you would regain access if a device or key were lost. A FIDO2-compatible hardware security key is optional; it is not required to start using passkeys.
Recommended Free Tools
Best Value
What the 2025 materials suggest organizations should review
Microsoft’s 2025 Digital Defense Report recommends investing in people and workforce upskilling, planning for breaches, considering AI’s effect on threat models, inventorying cryptographic use in preparation for post-quantum standards, reviewing entry points such as partners and online services, and sharing information across sectors. Microsoft also says exposed web assets and remote services remained common targets in its reporting. These are Microsoft’s recommendations and observations, not a universal checklist or a guarantee that any particular measure prevents an incident.
For organizations operating industrial systems, the forecast and guidance point to practical questions rather than a ranked list of products:
- Identity and recovery: Which accounts can reach critical systems, how are they authenticated, and can they be recovered securely?
- Supplier access: Which third parties can connect to business or industrial networks, and is that access understood and managed?
- IT and OT visibility: Can teams inventory relevant assets and understand connections between business systems and operational environments?
- Operational resilience: What would a disruption mean for safety and uptime, and how would critical operations be restored?
- Staff practice: Do employees know how to pause and verify urgent requests involving money, credentials or access?
- Procurement: How does a supplier address product security, and can the organization maintain and update a component without unacceptable operational risk?
What the sources can—and cannot—say about 2025
Google Cloud’s report was published in December 2024 as a forecast of expected developments. Microsoft’s 2025 report provides Microsoft’s own observations and recommendations; CISA’s January 2025 announcement addresses OT procurement; and FIDO’s material explains passkeys and their deployment. None of these sources supplies a comprehensive, independent scorecard showing whether every Google Cloud prediction came true.
Two FIDO Alliance figures offer context on why password alternatives matter, but they are survey responses rather than audited breach statistics. In an April 2025 survey of 1,389 respondents in the United States, United Kingdom, China, South Korea and Japan, 36% said they had experienced at least one account compromise due to weak or stolen passwords, and 48% said they had abandoned an online purchase because they forgot a password. The figures are self-reported and apply to the surveyed respondents, not all internet users.
Microsoft separately reported that its systems screened an average of 5 billion emails daily to protect users from malware and phishing, and processed 100 trillion security signals daily. These figures describe Microsoft’s own operations and telemetry, not global totals. They are not directly comparable to FIDO’s survey results.

