In 2025, Luxembourg is facing an explosion in cybercrime. Attacks against Luxembourg companies have increased by 59%, far exceeding the global average. Major incidents, such as the DDoS attack against government websites in January, have exposed the vulnerability of critical infrastructures. How can this growing threat be explained?

Cybercrime is no longer the work of a few lone hackers operating from their garages. It has evolved into a true global business model—democratised, professionalised, and accessible to anyone with a computer and a cryptocurrency wallet. This industrialisation, known as Cybercrime-as-a-Service (CaaS), represents one of the most significant threats of our time.

The underground ecosystem: a well-organised market

The Dark Web operates like a genuine marketplace. Sellers, brokers and buyers interact in structured spaces with reviews, reputations and escrow systems. Two main categories of offers coexist: passive products (stolen data, compromised accounts) and active services (pre-compromised access, malicious infrastructures, RaaS, DDoS).

Prices reflect this professionalisation: Ransomware-as-a-Service (RaaS) from a few dozen dollars per month, phishing kits from €50 to €300, banking databases from a few dollars to several hundred depending on their value, Initial Access Brokers (IAB) ranging between €500 and €10,000, and DDoS attacks from $10 to $40 for basic packages up to several thousand for large-scale assaults.

From RaaS to DDoS: ready-to-use criminal services

Ransomware-as-a-Service has become the most profitable model. Inspired by traditional SaaS, it allows developers to rent their ransomware to “affiliates” without advanced technical skills, who then deploy it against companies. The developers receive a share of the ransom—a strict business logic applied to crime.

These platforms offer what no cybercriminal could once have imagined: user-friendly interfaces, manuals, technical support, and structured affiliate programmes. Some even include “premium” subscriptions with regular updates and assistance.

On-demand DDoS attacks follow a similar model. Booters and stressers offer subscription-based control panels enabling users to flood targeted servers by exploiting millions of compromised IoT devices. Cloudflare reported an exceptional rise in such attacks in 2024-2025, with record peaks measured in terabits per second.

he more sophisticated and affordable the offer, the more frequent and diverse the attacks become
Nicolas Pelletier

Nicolas Pelletier SOC EngineerCBTW

Why is this threat accelerating?

This accessibility creates a vicious circle: the more sophisticated and affordable the offer, the more frequent and diverse the attacks become. Whereas solid technical skills were once required to develop malware, a few hundred dollars are now enough to acquire a powerful digital arsenal. The Dark Web dramatically lowers the barrier to entry, attracting not only seasoned criminal organisations but also opportunistic or amateur actors.

This professionalisation goes hand in hand with an acceleration of incidents. Luxembourg companies are no exception, and the 2025 figures confirm it. Faced with ever more numerous and organised attackers, traditional defences struggle to keep pace.

most incidents still exploit human error or known vulnerabilities. A multi-layered cybersecurity approach is therefore crucial
Nicolas Pelletier

Nicolas Pelletier SOC EngineerCBTW

Protecting yourself through an integrated and proactive approach

Despite the increasing sophistication of attackers, most incidents still exploit human error or known vulnerabilities. A multi-layered cybersecurity approach is therefore crucial:

Multi-Factor Authentication (MFA): a simple yet highly effective barrier against unauthorised access.

Isolated and encrypted backups: ensure rapid recovery without giving in to ransom demands.

AI-based advanced detection: identifies abnormal behaviour before escalation.

Strict patch management: limits exploitation of known vulnerabilities.

Continuous awareness training: phishing remains the number-one attack vector—training your staff drastically reduces risks.

Regular simulations and audits: testing your defences reveals weaknesses before attackers do.

When combined within a coherent strategy tailored to your environment, these measures are essential to limit the impact of modern attacks. Added to this is a Zero Trust philosophy: never grant implicit trust, systematically verify every user, device and data flow, whether internal or external. This approach significantly reduces the attack surface and strengthens resilience against breaches.

When the Akira ransomware paralyses a company in Luxembourg

An international group operating in Luxembourg recently fell victim to the Akira ransomware, following an intrusion via a vulnerable VPN. The compromised access had likely been sold by an Initial Access Broker on the Dark Web. The entire IT infrastructure was encrypted, paralysing operations.

Supported by CBTW, the company was able to restore its systems within two days thanks to its isolated and encrypted backups. Although some tools operated in degraded mode for two weeks, data was progressively recovered. Beyond this crisis, CBTW deployed a strengthened Network Detection and Response (NDR) solution and implemented 24/7 monitoring of their security alerts.

Act now

Despite the growing sophistication of attackers, most incidents still exploit human error or known vulnerabilities. At CBTW, we help organisations strengthen their resilience by combining innovative technologies, human expertise and strategic guidance. Our teams support you in deploying robust solutions, testing your defences and raising employee awareness.

Contact CBTW’s experts to protect your critical assets and build a cybersecurity framework that matches your ambitions.