logo

Ransomware Attack 2025 Recap – From Critical Data Extortion to Operational Disruption

ID: bda790c6-cb20-5a41-8567-deece357b165

STIX ID: report--bda790c6-cb20-5a41-8567-deece357b165

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-19

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Executive summary:** The 2025 ransomware landscape saw record attack volumes (4,701 confirmed incidents Jan–Sep; 6,330 leak-site cases by October) while ransom payment rates collapsed to ~23–25%, driving fragmentation into ~85 active extortion groups (notably Qilin, Cl0p, LockBit, Play, Scattered Spider) that leveraged zero-days, supply-chain exploits (MOVEit, GoAnywhere, Cleo), AI-enhanced phishing, and cross-platform payloads to target critical infrastructure, healthcare, cloud/ESXi environments and inflict systemic operational and societal impacts including large-scale data theft, service disruption, and at least one confirmed death linked to an attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.