Managed ITServices
Statistics

Ransomware Statistics 2025: The Year in Review (Updated 2026)

Ransomware cemented its position as the most disruptive cyberthreat of the decade in 2025. Attack volumes surged, new criminal groups appeared at a pace of more than one per week, and small…

Ransomware cemented its position as the most disruptive cyberthreat of the decade in 2025. Attack volumes surged, new criminal groups appeared at a pace of more than one per week, and small businesses bore a disproportionate share of the damage. At the same time, a growing number of victims refused to pay, law enforcement disrupted key infrastructure, and defenders stopped more attacks before encryption could begin.

This article pulls together the most important ransomware statistics from 2025, drawn from primary research by Chainalysis, Verizon, Sophos, Black Kite, IBM, and Cognyte. Where available, we include early 2026 data so you can see where the threat is heading next.

Key Ransomware Statistics From 2025

Ransomware Statistics 2025: The Year in Review (Updated 2026) infographic

Attack Volumes Hit Record Highs

The sheer scale of ransomware activity in 2025 was staggering. Cognyte recorded 7,809 confirmed ransomware incidents globally, a 27.3% year-over-year increase. Black Kite's separate count of 7,551 publicly disclosed victims set a new high for the fourth consecutive year.

The pace accelerated as the year progressed. The first half of Black Kite's reporting period saw 2,904 victims, while the second half jumped to 4,647, a 60% increase in monthly pace. March 2026 alone produced 861 victims, the highest single month on record.

Sixty-one new ransomware groups entered the ecosystem during the period. However, these newcomers lasted a median of just 4.9 months, down from 12.8 months for groups that appeared the year before. The market is becoming more commoditized, with groups forming, operating briefly, and dissolving or rebranding at speed.

The dominant force was Qilin, which accounted for roughly one in every five to six victims, growing from 250 victims to 1,358 across more than 50 countries. The top five ransomware groups controlled 43.6% of all disclosed victims.

Small Businesses Took the Hardest Hit

One of the most alarming findings from the 2025 Verizon Data Breach Investigations Report was the outsized impact on small and medium-sized businesses. Ransomware appeared in 88% of SMB breaches, compared to 39% at large enterprises.

This gap exists because smaller organizations typically lack dedicated security teams, maintain fewer backup systems, and run older software with unpatched vulnerabilities. Attackers have noticed. Black Kite found that the $50M to $100M revenue band climbed from 25.1% to 29.3% of victims with known revenue, confirming that mid-market companies are increasingly in the crosshairs.

The financial burden is severe. Sophos reported that median ransom demands for enterprise organizations dropped to $1.2 million in 2025, down 56% from $2.75 million in 2024. But recovery costs, excluding ransom payments, still averaged $1.84 million. For smaller businesses operating on thinner margins, these costs can be existential.

How Attackers Got In

Understanding root causes is essential for prevention. Sophos surveyed 1,733 enterprise organizations and found three nearly equal entry points:

  • Exploited vulnerabilities accounted for 29% of attacks. Unpatched software remains the single largest door that attackers walk through.

  • Phishing was responsible for 21% of incidents. Social engineering continues to bypass technical controls.

  • Compromised credentials contributed to another 21%. Stolen passwords, often harvested by infostealer malware and sold on criminal marketplaces, gave attackers direct access.

The rise of credential theft is particularly concerning. Black Kite found that stealer log exposure came back 175% higher in post-incident rescans than in initial assessments, meaning credential compromise persisted even after organizations believed an incident was resolved.

Cognyte noted a shift toward supply chain exploitation, where attackers target upstream vendors and platforms to compromise hundreds of organizations at once. The exploitation of a critical Oracle E-Business Suite zero-day vulnerability affected nearly 30 major enterprises in a single campaign.

Payments Declined Even as Attacks Rose

Perhaps the most encouraging trend in 2025 was the growing refusal to pay. Chainalysis reported $820 million in total ransomware payments, down 8% from 2024 despite attacks surging 50%. Only 28% of claimed attacks produced a payment, a record low.

Several factors drove this shift. Regulatory pressure increased globally, with Australia implementing mandatory 72-hour ransomware payment reporting in May 2025. Italy and the UK advanced legislation to criminalize ransomware payments in public and essential services. The EU's NIS2 Directive and DORA regulations emphasized preventative resilience.

Organizations also improved their defenses. Sophos found that 47% of ransomware attacks were stopped before data encryption, up from 22% in 2023. When encryption did occur, 53% of organizations recovered using backups rather than paying.

Still, the median payment size told a different story. At $59,556, the median payment rose 368% from 2024's $12,738. Fewer organizations paid, but those that did paid significantly more.

Most Targeted Industries

Manufacturing led all sectors with 1,660 victims, representing 22% of all disclosures. Professional, scientific, and technical services followed with 1,389 victims. Construction saw the fastest growth, gaining over one percentage point of share.

Cognyte reported that 33.6% of incidents targeted critical sectors including manufacturing, healthcare, energy, transportation, and finance. North America accounted for 47% to 52% of global incidents, though Europe saw significant growth. Germany's victim count rose 48% to 281, Italy surged 96% to 188, and both Spain and France grew approximately 50%.

Healthcare remained a high-value target due to the sensitivity of patient data and the operational pressure on hospitals to restore systems quickly. Downtime in a hospital setting can directly threaten patient safety, making healthcare organizations more likely to consider paying. The 76% of incidents involving data exfiltration rather than encryption alone suggests attackers are shifting toward double extortion, where stolen data becomes the primary leverage.

What Changed in 2026

Early 2026 data points to an acceleration of trends that emerged in 2025. Black Kite counted 146 active ransomware groups by June 2026, up from 127 at the close of the prior period. The ecosystem is fragmenting, with more operators competing for victims.

Recycling scams have emerged as a new tactic. Cognyte documented cases where threat actors demanded payment for previously exfiltrated data months after the initial breach, exploiting organizations' incomplete visibility into the scope of stolen information.

Regulatory momentum is building. The EU NIS2 Directive is driving stricter reporting requirements and higher fines for non-compliance. Organizations that treated cybersecurity as a cost center are now being compelled by law to invest in prevention.

The predictive power of risk scoring has also improved. Black Kite found that organizations with a ransomware susceptibility index above 0.8 were 291 times more likely to be attacked than those below 0.2, and 93.5% of victims showed a month-over-month risk score increase of 5% or more before disclosure. This means early warning is possible for organizations willing to monitor their exposure.

How Managed IT Services Can Help

The statistics paint a clear picture: ransomware is not slowing down, and the organizations most at risk are those without dedicated security resources. This is where managed IT services become essential.

A managed service provider delivers the layers of defense that ransomware statistics show matter most. Patch management closes the exploited vulnerabilities that caused 29% of attacks. Managed detection and response catches threats before encryption begins, the approach that stopped 47% of attacks in 2025. Credential monitoring and multi-factor authentication address the compromised credentials behind 21% of incidents.

For small and medium-sized businesses facing an 88% ransomware involvement rate in breaches, outsourcing security to a managed provider is no longer optional. It is the difference between a recoverable incident and a business-ending event.

Backup management, employee security training, and 24/7 monitoring round out the protections that reduce both the likelihood and the cost of a ransomware attack. The data from 2025 shows that organizations with strong defenses stopped more attacks, paid less often, and recovered faster. With 127 ransomware groups active and attack volumes climbing year after year, proactive defense is the only sustainable strategy. Managed IT services make those defenses accessible to businesses of every size, turning the statistics from a warning into a manageable risk.

Need Help With Your Security Strategy?

Get a free assessment from our team of cybersecurity experts.

Related Articles

HM

Hadley McIntosh

Updated Sep 25, 2026 · 7 min read