While the summer months invite relaxation and well-earned rest, for cybercriminals, this period represents a peak of opportunity rather than a pause. The phrase “cybersecurity doesn’t take a holiday” has never rung truer. Attackers are aware that many organisations operate with reduced teams during this time, and vigilance may be lower, making this season especially attractive for launching certain types of attacks.
If your defences take a holiday, your risk doesn’t—it compounds.
Fresh data shows the risk is real. 86% of organisations hit by ransomware reported being targeted on a weekend or public holiday (survey across the US, UK, France and Germany). In Europe we see the fastest year‑on‑year growth in cyber attacks in Q2 2025—right as summer cover thins. This isn’t a perception problem; it’s a staffing and timing problem that attackers know how to exploit. In this article I explore the cybersecurity risks that organisations need to watch out for during vacation. Read on if you want to learn from the costly mistakes of others and take proactive steps to ensure your organisation’s security posture is resilient this summer..
The Summer Period: Fertile Ground for Cyberattacks
The reduction in personnel, particularly within IT and cybersecurity teams, is one of the main factors that weakens an organisation’s security posture during the holiday season. With fewer experts available, detection and response times tend to increase, giving attackers a greater opportunity to inflict damage. This situation is exacerbated by the fact that remaining staff may lack the specialist knowledge or historical context needed to make swift, effective decisions in response to alerts.
Recent data highlights this trend alarmingly. The first half of 2025 saw a 49% rise in ransomware incidents compared to the same period in 2024, with the United States being the primary target. June 2025, in particular, was a month of intense activity, including attacks on critical supply chains like that of United Natural Foods (UNFI), the main distributor for Whole Foods, which had its operations brought to a halt.

Preferred Attack Tactics During Holiday Periods
Cybercriminals adapt their tactics to exploit seasonal vulnerabilities:
- Holiday-Themed, Evolved Phishing: Phishing campaigns continue to use holiday themes, but with increasing sophistication. In June 2025, the “StringRipper” campaign grew fifteenfold, becoming one of the most prolific. The latest techniques include AI-generated flawless emails, voice and video deepfakes used to authorise transfers, and “quishing” (QR code-based phishing). Read about other common AI-powered cybersecurity risks.
- Exploiting Out-of-Office Replies: Auto-replies remain a goldmine for attackers. They can provide cybercriminals with names and contact details for social engineering and Business Email Compromise (BEC) campaigns.
- Relentless Ransomware: Ransomware not only persists but evolves. In June 2025, the Qilin group exploited Fortinet device vulnerabilities. Furthermore, new groups like Fog and Anubis introduced stealthier, more destructive methods. Attacks on local governments (e.g., in Ohio and Oklahoma) and critical sectors such as healthcare (Kettering Health) and media (Lee Enterprises) demonstrated that no sector is immune. The industrial sector also saw a 46% increase in ransomware attacks from late 2024 to early 2025.
- Targeting Infrastructure and Supply Chains: The disruption of UNFI in June 2025 is a clear example of the impact on the food supply chain. In the same month, retail brands like The North Face and Cartier were victims of data breaches, often linked to groups such as Scattered Spider.
Lessons from the Past and Preparedness Strategies
Examples of Cyberattacks in Europe during Holidays:
- UK – Easter period (April 2025): Marks & Spencer suffered a major cyber incident that forced the retailer to pause online orders and disrupted in‑store services around the Easter period, with knock‑on effects lasting into the summer.
- Italy – August 2021: Lazio regional administration was hit by ransomware, disrupting the COVID‑19 vaccination booking portal for days.
- UK – August Bank Holiday 2017: Copeland Borough Council sustained a zero‑day ransomware attack over the August bank holiday weekend, with the timing extending attacker dwell time before discovery and response.
How to Mitigate the Cybersecurity Risks during Holidays
Analysing recent incidents provides valuable insights. To mitigate risks, organisations must take a proactive approach.

Let’s take a deeper look at each mitigation strategy:
1. Holiday-Specific Planning: It’s vital to develop and review incident response plans tailored to reduced staffing scenarios.
2. Vulnerability and Patch Management: The exploitation of known vulnerabilities, such as those in Fortinet devices used by Qilin, underlines the need for timely, rigorous patch management.
3. Credential Management and Authentication Hardening: The M-Trends 2025 report revealed a significant shift – stolen credentials (16%) became the second most common initial access vector, overtaking phishing (14%). This makes implementing multi-factor authentication (MFA) and strong password hygiene more critical than ever.
4. Continuous Training and Awareness: Training should be updated to include newer tactics like “quishing” and AI-generated deepfakes. Staff should also be instructed to set generic out-of-office messages.
5. Monitoring and Alerting: Keeping security teams alert – even remotely – and ensuring monitoring systems are finely tuned to detect suspicious activity is essential.
6. Leverage Automation: As attackers adopt AI, defences must evolve too. Technologies such as Security Orchestration, Automation and Response (SOAR) and AI/ML-powered solutions are instrumental in managing alert volumes, performing initial triage, and compensating for reduced human resources.
Conclusion: Constant Vigilance as a Strategic Imperative
Cybercriminals don’t follow conventional holiday calendars. On the contrary, they view these periods as windows of opportunity. For cybersecurity professionals, this means they have to remain vigilant. Robust, well-adapted security planning during holiday periods is not a formality – it’s a necessity. By learning from recent incidents and implementing proactive measures, organisations can significantly reduce risk, protect assets, and ensure business continuity – even when most of the team is enjoying a well-earned break.
Summer is peak season for opportunists. Combat fatigue with automation.
It is time to turn awareness into action and ensure your defences, like your adversaries, never take a holiday.
Don’t let your organisation’s security take a holiday!
Contact Devoteam today and discover how to build your cyber resilience all year round.
