Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

February 6, 2026

Here’s what you should know

February 6, 2026
Facebook X (Twitter) Instagram
Friday, February 6
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Top Ransomware Trends of 2025
News

Top Ransomware Trends of 2025

Team-CWDBy Team-CWDDecember 23, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The past year was much quieter than 2024 in ransomware takedown and anti-cybercrime law enforcement operations.

Additionally, less organized collectives such as Scattered Spider, Lapsus$ and ShinyHunters grabbed many of the headlines in 2025.

However, traditional ransomware syndicates continued to be active throughout the year.

According to ransomware tracking website Ransomware.live, 306 groups were active over the past year, listing 7902 victims at the time of writing. This is significantly higher than the 6129 victims listed in 2024 and the 5336 victims listed in 2023.

However, these statistics are based solely on listings from data leak sites and could misrepresent the true scale of attacks, as many incidents go unreported or undetected and some claims by ransomware groups are false.

Qilin, the group that claimed the cyber-attack on brewing giant Asahi in September, was the most prolific ransomware group, with 1001 victims listed on its data leak site according to Ransomware.live and 973 according to competitor RansomLook.

Both ransomware intelligence websites put Akira as the group with the second most victims claimed, while Clop took the third place.

Top 10 of the most active ransomware groups in 2025 by their listings on data leak sites according to Ransomware.live (top) and RansomLook (bottom). Source: Ransomware.live, RansomLook

Ransomware groups were the most active in February of 2025, with 1014 claims in the shortest month of the year, while June had the least victims claimed at 502.

Victims claimed by ransomware groups in 2025 per month. Source: Ransomware.live
Victims claimed by ransomware groups in 2025 per month. Source: Ransomware.live

RansomLook’s analysis showed that the Russian-linked ransomware group Clop was particularly active in the first quarter of 2025, activity then slowed during the summer months until a small peak of activity around October. Meanwhile, Qilin and Akira showed consistent activity throughout the whole year with less peaks and troughs.

US Ransomware Victims Made Half of 2025’s Total

In 2025, ransomware groups targeted a wide range of industries, with Ransomware.live reporting victims for at least 10 sectorial categories.

The highest number of victims came from the manufacturing sector (930), followed by technology (893) and healthcare (529).

The geographical breakdown, however, was less balanced, with US victims representing almost half of the total number of ransomware group-listed victims in 2025 (3328).

The second most targeted country, Canada, represented a far lower number with 358 listed victims over the past year. Germany had 318, the UK 251 and France, 172.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleA Browser Extension Risk Guide After the ShadyPanda Campaign
Next Article Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More
Team-CWD
  • Website

Related Posts

News

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026
News

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

February 6, 2026
News

Chinese-Made Malware Kit Targets Chinese-Based Edge Devices

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

Why LinkedIn is a hunting ground for threat actors – and how to protect yourself

January 16, 2026

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

Chronology of a Skype attack

February 5, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.