Quick Summary
The Securityish Brief
According to Emsisoft’s 2025 State of Ransomware in the US report, ransomware attacks have continued to rise, with more than 8,000 claimed victims logged globally, marking a 50% increase compared to 2023. This surge occurred despite significant law enforcement actions, including the takedown of the BlackSuit ransomware group in August 2025. The report indicates that the number of active ransomware gangs has climbed to well over 100, contrasting with just a few dozen in previous years.
The increase in ransomware activity is attributed to a more fragmented landscape, where numerous smaller groups have emerged, complicating efforts to combat these threats. Well-known ransomware brands such as Qilin, Akira, Cl0p, and Play have consistently appeared on extortion sites, indicating that while some gangs may be dismantled, their members often regroup under new identities.
Interestingly, the methods employed by these ransomware groups are evolving. While vulnerabilities and exposed services remain a factor, there is a notable shift towards traditional techniques like phishing and social engineering. Groups such as Scattered Lapsus$ Hunters are increasingly bypassing perimeter defenses to gain access to systems.
Emsisoft’s threat intelligence analyst, Luke Connolly, emphasizes that the ongoing churn of affiliates and the effectiveness of social engineering tactics are key reasons for the persistence of ransomware attacks. As long as these factors remain, the number of victims is likely to keep rising.
Understanding the Ransomware Landscape
The ransomware landscape in 2025 is characterized by a multitude of active groups, with many operating under different names as affiliates shift between them. This dynamic environment makes it challenging for law enforcement to achieve lasting impacts on ransomware prevalence.
Organizations and individuals must remain vigilant, as the tactics used by attackers are becoming more sophisticated. The reliance on social engineering means that users must be cautious about sharing sensitive information and clicking on links in unsolicited communications.
Key Takeaways
- Regularly update software and systems to protect against known vulnerabilities.
- Implement multi-factor authentication to enhance account security.
- Educate employees about phishing and social engineering tactics to reduce the risk of successful attacks.
- Monitor network activity for unusual behavior that may indicate a ransomware attack.
- Develop and regularly test an incident response plan to quickly address potential ransomware incidents.
Key Terms & Concepts
- Ransomware: In this article, ransomware refers to malicious software that encrypts data and demands payment for its release.
- Emsisoft: Emsisoft is a security firm that provides insights and reports on ransomware trends and statistics.
- Phishing: Phishing is a tactic used by cybercriminals to trick individuals into providing sensitive information by posing as a trustworthy entity.
- Social Engineering: Social engineering involves manipulating individuals into divulging confidential information through deceptive tactics.
- BlackSuit: BlackSuit is a ransomware group that was targeted and dismantled by law enforcement in August 2025.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.