Published analysis places legacy VPNs as the entry point in 73% of verified ransomware intrusions in 2025, against 38% in 2023. Treat the precise figures with the caution any vendor-derived statistic deserves; the direction is stark enough to act on regardless.
Concentration Cuts Both Ways
A threat landscape where most intrusions share one entry category is, in one sense, good news. Defensive effort has an obvious focus, and an organisation that fixes one control class addresses the majority of its realistic exposure.
It is also an indictment. The category has been known, discussed and advised on for years, and its share has roughly doubled in two.
Why The Box Is Still There
Remote-access appliances persist because replacing one is a project, not a purchase. It touches every remote worker, every site-to-site link and frequently a set of legacy applications that only work through it.
Meanwhile the appliance keeps working. There is no operational signal prompting replacement — no outage, no user complaint, no failing metric. It quietly ages out of support while continuing to authenticate people successfully every morning.
The Awkward Part For Vendors
Several of the appliances in this category are sold by security companies. That is not hypocrisy — building software that terminates untrusted connections is genuinely difficult — but it does undercut a common assumption that a security vendor’s product is inherently a safer place to put a control.
The practical question for anyone reading this: what is the support status of the device terminating your remote access, and when was its management interface last reachable from the internet?
This is an analysis file built on published research, listed below. Figures are vendor-derived and methodology varies between sources; we treat the trend as the finding. Corrections: corrections@forensicpost.com.