Ransomware Attacks Rose 32% in 2025. Here’s the Real Reason
In September 2025, thousands of Oracle E-Business Suite customers got the same email. No encrypted files. No ransom note dropped on their desktop. Just a message from a group calling itself Clop, saying it already had their data, and it wanted to talk about payment.
That single campaign helps explain why global ransomware attacks jumped 32% in 2025, according to Comparitech’s year-end roundup, which counted 7,419 attacks worldwide, up from 5,631 the year before. If you run security for a mid-market or enterprise organization, the number itself matters less than what changed underneath it: attackers increasingly don’t need to touch your endpoints at all. They just need one valid login.
The 32% Number, and Why It’s Only Part of the Story
Start with a caveat, because the headline stat gets thrown around more confidently than it deserves. Comparitech’s 32% figure comes from tracking dark web leak sites, and it’s not the only count out there. GuidePoint Security’s GRIT team put 2025 growth at 58%. NordStellar measured 45%. Same year, wildly different numbers, because each tracker watches a different slice of the leak-site ecosystem and none of them are independently audited.
The one number built on forensic data instead of leak-site scraping tells a related but distinct story. Verizon’s 2025 Data Breach Investigations Report, drawn from 12,195 confirmed breaches across 139 countries, found ransomware present in 44% of confirmed breaches, up from 32% the year before, a 37% jump. That’s not the same metric as attack counts, but it points the same direction: ransomware’s share of the breach landscape is genuinely growing, not just getting louder on Telegram.
The Attack Pattern: Clop’s Oracle Playbook
Here’s where the story gets specific. Mandiant, Google Cloud’s incident response arm, traced Clop’s data theft from Oracle E-Business Suite customers back to August 2025, weeks before any extortion email went out. The vulnerability behind it, CVE-2025-61882, was an unauthenticated remote-code-execution flaw. Oracle had shipped a partial fix in its July 2025 Critical Patch Update, but the real patch for the zero-day didn’t land until early October.
That gap is the whole point. Organizations that patched on schedule were still compromised, because the exploitation happened before the fix that would have stopped it existed.
“Clop has been sending extortion emails to several victims since last Monday. However, please note they may not have attempted to reach out to all victims yet.” Charles Carmakal, CTO, Mandiant (Google Cloud), Help Net Security
The FBI’s cyber division moved fast on this one, publicly telling organizations to stop everything and patch.
“This is ‘stop-what-you’re-doing-and-patch-immediately’ vulnerability. The bad guys are likely already exploiting in the wild, and the race is on before others identify and target vulnerable systems.” Brett Leatherman, Assistant Director, FBI Cyber Division, The Record
If this playbook sounds familiar, it should. Clop ran nearly the identical operation against Accellion FTA in 2020 and 2021, Fortra GoAnywhere in 2023, MOVEit Transfer in 2023 (which hit more than 2,600 organizations and over 93 million individuals), and Cleo’s file transfer tools in December 2024. The pattern doesn’t change: find or buy a zero-day in widely used enterprise software, compromise as many instances as possible before anyone notices, exfiltrate data at scale, then skip encryption and extort directly. It’s efficient, it’s repeatable, and apparently it still works.
Why Identity, Not Malware, Is the Real Entry Point
The bigger shift isn’t Oracle specifically. It’s what Coveware, the ransomware negotiation firm now owned by Veeam, is seeing across its entire caseload. In its Q4 2025 report, Coveware found 94% of incidents involved data exfiltration, and framed the shift bluntly: attacks today are “less about persistence and more about speed to impact.”
Translate that out of vendor-speak: attackers aren’t spending weeks quietly living inside your network anymore. They’re grabbing a valid credential, moving fast, pulling data, and leaving. Encryption, once the whole point of a ransomware attack, is turning into an optional add-on rather than the main event.
That shift is also showing up in how fragmented the ransomware “market” has become. GuidePoint’s GRIT team tracked 124 distinct named ransomware groups active in 2025, a 46% jump over 2024 and the most ever recorded in a single year. Check Point counted 85 active extortion groups in just the third quarter. The top 10 groups accounted for 56% of published victims in 2025, down from 71% at the start of the year. Law enforcement takedowns keep knocking out the biggest names, LockBit’s disruption and the BlackSuit takedown in August 2025 among them, but the affiliates behind those groups don’t retire. They just rebrand and reattach to smaller operations, which is why volume keeps climbing even as any one group’s dominance shrinks.
Why Paying Doesn’t Guarantee Recovery
This is the part that gets buried under headline attack counts, and it’s arguably more useful to a CISO than the 32% figure itself.
Sophos surveyed 3,400 IT and cybersecurity leaders across 17 countries who’d been hit by ransomware in the prior 12 months. The result: 97% of organizations that had data encrypted in 2025 eventually got it back through some combination of methods. But only 49% of those who actually paid the ransom received a fully working decryption key in return. Roughly half the organizations that paid still didn’t get clean, usable data back for that payment alone.
| Metric (2025) | Figure | Source |
|---|---|---|
| Orgs eventually recovering encrypted data (any method) | 97% | Sophos |
| Payers who got a fully working decryption key | 49% | Sophos |
| Victims using backups to recover data | 54% (six-year low) | Sophos |
| Median ransom payment, Q4 2025 | $325,000 | Coveware / Veeam |
| Average ransom payment, Q4 2025 | $591,988 | Coveware / Veeam |
| Victims refusing to pay outright | 64% | Verizon DBIR |
Backup-based recovery told a similar story: only 54% of 2025 victims restored data from backups, a six-year low, even as full-blown encryption itself became less common. Put those two numbers together and the picture isn’t “ransomware got easier to survive.” It’s that both traditional recovery paths, paying for a key and restoring from backup, got less reliable at the same time.
Payment amounts tell their own story about who’s still getting squeezed hardest. Coveware’s Q4 2025 data shows the median payment at $325,000 while the average sits at $591,988, a gap that’s widened sharply quarter over quarter. That divergence means a small number of large, carefully chosen targets are paying enormous sums, while broader, lower-value attacks are being priced to close fast. By Q1 2026, the median had eased slightly to $300,750, a modest 7% drop from the prior quarter, per Veeam’s analyst report.
Here’s the mechanism behind all of it. When Coveware says 94% of incidents now involve data exfiltration rather than encryption, that changes what “recovery” even means. There’s no decryption key to test against, no technical proof the attack is over. Recovery becomes a matter of trusting a criminal’s word that stolen data was actually deleted, which by definition can’t be verified. That’s a fundamentally different risk than a locked file server, and it’s why the FBI’s IC3 report logged $32.32 million in 2025 ransomware losses, a 259% jump from 2024’s $12.47 million, while separately noting that figure almost certainly undercounts the real cost once downtime, legal exposure, and reputational damage get factored in.
Who Actually Got Hit Hardest
Manufacturing held its position as the most targeted sector for the second year running, accounting for roughly 19.3% of all recorded 2025 cases by leak-site tracking. But that ranking flips depending on whose data you trust. The FBI’s IC3, working from complaint volume rather than leak-site scraping, found healthcare led critical infrastructure sectors with 460 ransomware reports, ahead of manufacturing, financial services, and IT. Different methodology, different answer, and both are defensible depending on what you’re trying to measure.
Geographically, the US remained the single most targeted country by a wide margin (3,810 tracked attacks), followed by Canada and Germany, the latter up 62% year over year. The most dramatic relative spike came from South Korea, where attacks jumped 540% year over year, largely traced to Qilin’s breach of a shared third-party asset management provider, a reminder that a single well-placed supply-chain compromise can distort a country’s entire annual number.
The Skeptic’s Case
Not everyone buys the “record year” framing at face value, and they have a point worth sitting with.
Check Point Research found leak-site victim disclosures up 126% year over year in Q1 2025 alone, but flagged something uncomfortable underneath that number: certain groups, including Babuk-Bjorka and post-takedown LockBit, have posted fabricated or recycled victim data specifically to inflate their own activity and pressure new targets into paying faster. Some share of “record” attack volume is marketing, not new crime.
There’s a second layer worth questioning too. Vendors have called nearly every year since 2020 a record year for ransomware. Some of that is genuine escalation. Some of it is simply more trackers entering the market and catching incidents that would have gone unreported five years ago. Both things can be true at once, which is exactly why no single annual statistic should be treated as a clean trendline.
And the falling-payment-rate data (64% refusing to pay, per Verizon) shouldn’t be read as pure good news either. It could just as easily mean attackers are deliberately setting lower, more “affordable” demands to get more victims to pay quickly, a volume play rather than evidence that defenses are winning. Coveware’s own average-versus-median gap in Q4 2025 supports that read: sophisticated attackers are still extracting enormous sums from a handful of high-value targets, while everyone else is being priced for a fast close.
What Security Teams Should Actually Do
If your incident response plan still assumes the choice is “restore from backup, or pay for a decryption key,” it needs an update. With 94% of Coveware’s Q4 2025 caseload involving exfiltration rather than pure encryption, most organizations now need a parallel breach-notification and negotiation track that doesn’t assume encryption happens at all.
The Oracle EBS campaign is also a clean argument against treating patch cadence as sufficient on its own. Clop had already stolen data in August using a flaw that wasn’t fully patched until October. Organizations that patched exactly on schedule were still compromised before the fix existed. That’s the case for building compromise assessment into your standing operating rhythm for any internet-facing enterprise software, ERP, file transfer, CRM, rather than something you only do after an alert fires.
And on the budget side: falling payment rates and falling average payouts don’t mean falling risk. They mean attackers are compensating with volume, more groups, more parallel targets, and with exfiltration-based leverage that doesn’t require a successful encryption run to still hurt you. That’s a reasonable argument for shifting security budget conversations away from “ransomware insurance premium” and toward data exfiltration detection and identity hardening, particularly since insurers are already tightening underwriting around MFA, EDR, and documented incident response plans as baseline requirements rather than nice-to-haves.
Curious how AI-assisted tooling is lowering the skill barrier for attackers running these campaigns? We covered that angle in our earlier look at the 2025 ransomware surge.
Frequently Asked Questions
Did ransomware attacks increase in 2025?
Yes. Comparitech recorded 7,419 attacks worldwide in 2025, up 32% from 5,631 in 2024. Verizon’s 2025 DBIR separately found ransomware present in 44% of confirmed breaches, up from 32% the year before, a 37% jump based on forensic data across 12,195 breaches.
Does paying a ransom guarantee you get your data back?
No. Sophos’s 2025 survey of 3,400 organizations found 97% eventually recovered encrypted data through some method, but only 49% of those who paid got a fully working decryption key. Payment alone isn’t a reliable recovery method, even when demands are fully met.
What percentage of ransomware victims pay the ransom?
Payment rates keep falling. Verizon’s 2025 DBIR found 64% of victims refused to pay outright, up from 50% two years earlier. Coveware’s direct case data showed payment rates as low as 19 to 23% in individual 2025 quarters for exfiltration-only attacks.
What is the average ransomware payment in 2025?
Coveware’s Q4 2025 data shows a median payment of $325,000, up 132% from Q3, and an average of $591,988, up 57% from Q3, reflecting attackers concentrating on fewer, higher-value targets rather than broad low-value extortion.
How did the Clop ransomware group exploit Oracle in 2025?
Clop exploited CVE-2025-61882, a zero-day remote-code-execution flaw in Oracle E-Business Suite, stealing data from victims starting in August 2025 before sending mass extortion emails in late September, without ever deploying encryption.
Which industry was hit hardest by ransomware in 2025?
Private trackers like Comparitech identify manufacturing as the hardest-hit sector for the second consecutive year. The FBI’s IC3, using complaint data rather than leak-site tracking, instead found healthcare led in reported ransomware complaints among critical infrastructure sectors.
What is the average cost of a ransomware attack in 2025?
Recovery costs excluding any ransom paid averaged $1.53 million in 2025, down 44% from $2.73 million in 2024, according to Sophos. That figure excludes downtime, legal exposure, and reputational damage, which push total incident cost well higher in other estimates.
Where This Goes Next
The number that matters going into 2026 isn’t 32%. It’s 94%, the share of ransomware cases now built around stolen data rather than locked files. That single shift rewrites what recovery means, what insurance should cover, and what an incident response plan is actually supposed to do when the attacker never touches your endpoints at all.
Watch three things over the next 6 to 18 months: whether Q1 2026’s slightly softer median payment ($300,750) holds as a real trend or was a one-quarter blip, whether more RaaS groups follow Clop toward exfiltration-only extortion as the default rather than the exception, and whether regulators start treating “we didn’t confirm data deletion” as a reportable gap in its own right rather than an unresolved footnote.
Want the next Oracle-style campaign flagged before it hits your inbox? Subscribe to The Neural Loop for weekly breakdowns like this one.
