When it comes to cyber threats emerging from the dark web, the United States sits squarely in the crosshairs. A recent report by threat intelligence company SOCRadar found that more than four out of five (82%) dark web threats targeting North America over the past 12 months were aimed at U.S. organizations.
The report’s findings point to one key factor — America’s large digital footprint. In other words, the country’s massive online presence, high-value industries, and interconnected systems make it an especially attractive target for cybercriminals.
Ransomware: A Persistent and Lucrative Problem
The study revealed that 88% of ransomware attacks targeting North America were directed at U.S.-based organizations. SOCRadar’s analysis suggests that “high-value businesses, extensive digital networks, and larger financial opportunities” are what draw these attackers in.
While Canada (9.7%) and Mexico (1.8%) saw far fewer incidents, the report warns that no country is immune from these threats. All must remain vigilant and continuously strengthen cybersecurity defenses.
Grant Leonard, field CISO for Lumifi Cyber, explained that the United States’ technological advancement is part of the problem. “The U.S. is a sophisticated, tech-savvy nation with millions of users conducting business online. That makes it an enormous pool of potential targets,” he said.
Another factor is the willingness of some U.S. organizations to pay ransoms, often due to cyber insurance policies. “Sadly, many U.S.-based organizations still pay ransoms,” noted Damon Small, board member of Xcape. “We may soon follow other countries by prohibiting ransom payments and enforcing stronger security measures. Ironically, insurance companies are already pushing for better security before they underwrite cyber policies.”
Why the U.S. Appeals to Cybercriminals
The United States’ strong financial infrastructure is another magnet for cyber extortionists. Jason Hogg, executive chairman of Cypfer, pointed to the “connectivity between crypto wallets and fiat currency” that allows criminals to monetize their efforts more quickly.
Hogg also emphasized two additional factors:
-
The high concentration of large, lucrative companies in the country.
-
The vast size and complexity of these organizations’ operations, which creates more entry points for attackers.
Regulatory pressure and the reputational risks of a breach also incentivize many victims to pay quickly in order to resolve incidents.
According to John Wilson of Fortra, the very strengths that make the U.S. a leader in technology and business are its “Achilles’ heel” in cyberspace. “The USA innovates faster, adopts quicker, and scales bigger than anyone else — which is exactly why it’s getting hammered by hackers worldwide,” he explained.
The U.S. Leads in Phishing Incidents
Another troubling trend is phishing. The SOCRadar report shows the U.S. leads North America in phishing attacks, accounting for more than 61% of all cases. By comparison, Canada experiences about 38% and Mexico a mere 0.41%.
Perhaps more surprising is the fact that 71.1% of phishing sites now use HTTPS, the secure web protocol. While the padlock symbol in a browser once indicated a safe website, cybercriminals now exploit this trust to trick victims into sharing sensitive information.
Darren Guccione, CEO of Keeper Security, warned that phishing in the U.S. is becoming more targeted, using social engineering and AI to create convincing campaigns. The rise of “phishing-as-a-service” platforms has also lowered the barrier for entry, enabling more criminals to deploy sophisticated scams.
Deepfake videos are another emerging threat, as AI makes it faster and cheaper to create convincing impersonations. Guccione stressed that stronger identity verification methods, such as multi-factor authentication (MFA) and biometrics, will be essential to defend against these evolving attacks.
AI and the Future of Cyber Threats
Cypfer’s Hogg noted that as cybercriminals scale their own AI capabilities, social engineering attacks will continue to rise. This makes it vital for individuals to be cautious about the information they share publicly, whether on social media or other platforms.
Small added that many U.S. companies still view cybersecurity as a “cost center” rather than an essential investment. According to the report, 58.4% of dark web threat activity involves selling stolen data, tools, or services. Without proper investment, organizations risk losing valuable information that criminals know how to monetize.
John Watters, CEO of iCounter, warned that traditional security approaches are no longer enough. “To effectively defend against AI-driven, targeted attacks, organizations need more than just intelligence. They need AI-powered analysis of attack trends and insights into their own unique vulnerabilities.”
The Bottom Line
The SOCRadar report makes it clear: the United States is not just a frequent target for cybercrime, it is the main one. From ransomware and phishing to AI-driven social engineering, the threats are growing more sophisticated every year.
Businesses and individuals alike must recognize that cybersecurity is not optional — it is a fundamental part of operating in today’s interconnected world. Strong defenses, employee education, and investment in advanced threat detection are no longer “nice to have” — they are non-negotiable.


