The 2025 Ransomware Landscape: Record Claims, Fragmented Gangs, and What It Means for Everyone
The 2025 Ransomware Landscape: Record Claims, Fragmented Gangs, and What It Means for Everyone
What a record year tells us about the ransomware ecosystem — and what operators should be doing about it.
Executive Summary
2025 was the most active year on record for ransomware victim publication. Comparitech recorded 7,419 victim claims globally — a 32% increase over 2024's 5,631. Bitsight independently logged 6,883 claims across 115 leak sites (~20% increase). Emsisoft identified 126-141 active ransomware groups, up from ~70 in 2023. Manufacturing became the dominant target sector with attacks surging 56%. The average ransom demand declined 26% to $1.04M, though manufacturer-specific demands more than doubled to ~$1.16–$1.2M.
The variation (6,883–7,902 claims across sources) reflects methodological differences: Comparitech manually categorizes confirmed and unconfirmed claims; Bitsight uses AI extraction from dark web leak sites; ransomware.live records all listings. BlackFog estimates ~86% of attacks went undisclosed — meaning the true total is likely 50,000+ incidents.
RansomHub Collapse Triggered Mass Affiliate Redistribution
RansomHub's shutdown in April 2025 was a structural event, not an organic decline. Over 280 affiliates redistributed to Qilin, Akira, Play, SafePay, and other groups overnight — directly driving the 32% year-over-year surge that followed.
Manufacturing: The Converging Target
Manufacturing accounted for the largest share across every independent tracker:
- Comparitech: 1,466 manufacturing victim claims (+56% YoY), 23.3% of all business-sector claims
- Bitsight: Manufacturing: 1,553 attacks (28% of total)
- Dragos: 68% of industrial ransomware incidents were in manufacturing (Q1 2025)
Manufacturing's unique vulnerability comes from the convergence of high operational dependency (production lines cannot halt), unsophisticated security investment, and increasing digitization of OT environments.
The Double-Extortion Standard
Attackers exfiltrate data before encrypting it, then publish on dedicated leak sites if ransom is not paid. Multi-extortion now includes: financial pressure, data publication threat, DDoS attacks against customers/partners, legal/regulatory pressure through notification obligations, and supply-chain leverage.
Ecosystem Fragmentation
The top 10 gangs' share of victims declined from 71% in Q1 to 56% in Q3 — market fragmentation accelerated by RansomHub's collapse. New entrants include The Gentlemen (90/10 affiliate split), Worldleaks, Sinobi, and LockBit5.
Geographic Distribution
The United States accounted for 51.4% of global claims. South Korea saw the steepest increase: +540%. Germany rose 62%, Canada 31%, France 39%.
Major Case Studies
Nevada State Government Ransomware (August 2025): A full-scale attack affecting 60+ state agencies including DMV, social services, law enforcement, payroll, and health. Total recovery cost: $1.5M covered by $7M cyber insurance. Recovery in 28 days — below the national average for government entities (27.8 days). Key lesson: prior investments in IR planning and cyber insurance enabled rapid recovery without paying ransom.
Dollar Tree / INC Ransom: INC claimed infiltration of Dollar Tree's systems, stealing over 1.2 TB of data. Dollar Tree publicly disputed the claim — suggesting legacy data from a defunct discount chain rather than current operations.
What This Means for Operators
- Backups alone are no longer sufficient. Multi-extortion means data publication is always a risk. Continuous monitoring (SOC) is the only reliable detection mechanism.
- Manufacturing environments need OT-specific defenses. The operational impact of ransomware in production lines dwarfs pure IT considerations.
- Insurance is table stakes — not a strategy. Nevada proved that cyber insurance plus IR planning beats paying or going dark.
- Market fragmentation means less predictable threat intelligence. Too many small gangs to maintain a unified ATT&CK model — segment defense by likely attack vector, not just by gang name.
Sources
Comparitech; Bitsight; Canadian Centre for Cyber Security; UK NCSC; Dragos; Barracuda Blog; Halcyon Research; BlackFog; Fortinet; CISA; Searchlight Cyber; SOC in a Box; Fluet Law.