Ransomware Attacks Surge to Record Levels in 2025 Amid Evolving Tactics
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Ransomware activity surged in 2025, with a total of 4,737 claimed attacks, the highest recorded in the dataset. This increase occurred despite the collapse of significant criminal groups, such as RansomHub, which shut down in April 2025, and LockBit, which failed to recover from law enforcement actions in late 2024. Following these disruptions, former affiliates quickly joined other groups, leading to a rapid return of attack volumes.
New ransomware groups gained prominence during this period, with Akira and Qilin each responsible for 16% of claimed attacks, while Inc and Safepay accounted for 6% each. The emergence of DragonForce, which contributed 5% of claims, illustrates the fluidity of affiliate movements within the ransomware ecosystem.
One notable trend is the rise of extortion campaigns that do not depend on encryption. In 2025, total extortion incidents reached 6,182, a 23% increase from the previous year. These attacks often involve data theft and threats to publish stolen information, with the Cl0p ransomware operation playing a significant role in exploiting vulnerabilities in enterprise software.
Social engineering tactics have become a primary method for gaining access to systems, particularly through impersonation and credential harvesting. Groups like ShinyHunters and Scattered Spider have successfully used these methods to manipulate employees into authorizing malicious applications, leading to significant data breaches.
Additionally, a new ransomware strain known as Warlock has drawn attention for its use of espionage-related tooling and a zero-day vulnerability in Microsoft SharePoint. This strain highlights the overlap between ransomware and long-standing espionage campaigns, where financial and operational goals intersect.
Understanding the Evolving Ransomware Landscape
The study emphasizes that ransomware attack chains remain consistent, with actors utilizing living-off-the-land techniques to minimize detection. Tools like PowerShell and remote management software are frequently employed for lateral movement and credential access, often delaying the deployment of malware until critical stages of data theft or encryption.
This evolving landscape of ransomware and extortion tactics underscores the need for heightened vigilance among organizations and individuals. As the techniques become more sophisticated, understanding these trends is crucial for maintaining cybersecurity and protecting sensitive information.
Key Takeaways
- Regularly update software and systems to protect against known vulnerabilities exploited by ransomware actors.
- Implement strong access controls and monitor for unusual activity, especially in cloud environments.
- Educate employees about social engineering tactics to prevent unauthorized access through manipulation.
- Consider data encryption and backup strategies to mitigate the impact of potential ransomware attacks.
- Review and strengthen incident response plans to address evolving ransomware threats effectively.
Key Terms & Concepts
- Ransomware: In this article, ransomware refers to malicious software that encrypts data and demands payment for its release.
- Extortion: In this context, extortion involves threatening to publish stolen data unless a ransom is paid.
- Social Engineering: Social engineering refers to tactics used by attackers to manipulate individuals into divulging confidential information.
- Zero-Day Vulnerability: A zero-day vulnerability is a security flaw that is exploited by attackers before the vendor has released a fix.
- Cl0p: Cl0p is a ransomware operation known for its data theft and extortion tactics.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.