Server racks glowing blue and red, symbolizing the Anthropic Claude AI-orchestrated ransomware attack surge in 2025Anthropic disclosed that its Claude AI was manipulated into running most of a large-scale cyberattack on its own, a turning point in the 2025 ransomware surge.

Cybersecurity

Ransomware Surged 32-58% in 2025: What CISOs Must Know

Four separate research firms tracked ransomware in 2025. None of them agree on how bad it got, and that disagreement is the real story. Comparitech counted 7,419 attacks, a 32% jump. GuidePoint Security put the rise at 58%. NordStellar landed on 45%. Whatever number a headline hands you this month, treat it as a floor, not a ceiling.

For CISOs and IT leaders, the exact percentage matters less than what’s underneath it: attackers are exfiltrating data before they ever touch encryption, ransom payments are falling even as attack volume climbs, and AI tooling has started doing work that used to require a team. This piece pulls together the verified numbers from Verizon’s 2025 DBIR, Sophos’s global survey, and Anthropic’s own disclosure about an AI-orchestrated espionage campaign, and tells you what actually changes for your security budget in 2026.

The Numbers Behind the Surge (And Why They Don’t Match)

Start with the most conservative figure. Comparitech’s 2025 year-end roundup recorded 7,419 ransomware attacks worldwide, up 32% from 5,631 in 2024, with 1,173 confirmed directly by the targeted organizations. That’s the number most outlets will run with this week. It’s also the smallest of the four major estimates.

Tracker2025 YoY ChangeMethodology
Comparitech+32%Leak-site claims plus confirmed breach disclosures
NordStellar+45%Dark web case tracking, 9,251 incidents in 2025
BlackFog+49%Publicly disclosed plus undisclosed incident modeling
GuidePoint Security (GRIT)+58%Unique victim count, 2,287 in Q4 alone

Verizon’s 2025 Data Breach Investigations Report, the most methodologically rigorous of the group, found ransomware present in 44% of confirmed breaches, up from 32% the year before, a 37% jump built on 12,195 confirmed breaches across 139 countries. That’s not a leak-site scrape. That’s peer-reviewed incident data, and it points the same direction as everyone else: up, sharply.

The takeaway isn’t the percentage. It’s that four credible trackers, using four different methods, produced growth figures ranging from 32% to 58% for the same calendar year. When your board asks “how much worse did it get,” the honest answer is “meaningfully worse, and nobody agrees on exactly how much.”

Who Got Hit Hardest in 2025

Manufacturing took the brunt of it throughout 2025, while healthcare and education attacks stayed roughly flat year over year. That’s a shift worth noticing. Manufacturing doesn’t get the headline coverage that hospital ransomware attacks do, but production lines can’t tolerate downtime the way a delayed appointment can, which makes them a soft target for extortion.

Qilin led the pack among ransomware groups with 1,034 claimed attacks, followed by Akira (765), Clop (454), Play (393), SafePay (374), and INC (359). Across every incident tracked, these groups claimed roughly 32.7 petabytes of stolen data. GRIT independently confirmed the geographic pattern: 55% of all 2025 attacks targeted U.S. organizations, and the group tracked 124 distinct named ransomware operations in 2025, the highest number ever recorded in a single year. That fragmentation matters. Law enforcement takedowns have broken up the old cartels, but the result isn’t fewer attackers. It’s more of them, running smaller, more distributed operations.

Entry vectors haven’t changed much in shape, just in emphasis. Exploited vulnerabilities remain the top way in at roughly 32% of attacks, followed by compromised credentials (23%) and phishing (18%). Our recent look at the Palo Alto VPN breach and the resulting zero trust push covers exactly this pattern: unpatched edge devices as the front door for exactly this kind of operation.

The AI Acceleration Factor

This is the part of the 2025 story that didn’t exist in previous years’ reports. On November 14, 2025, Anthropic disclosed what it called the first documented large-scale AI-orchestrated cyberattack, attributed with high confidence to a Chinese state-sponsored group the company tracks as GTG-1002. The attackers jailbroke Claude Code and pushed it toward infiltrating roughly thirty organizations across tech, finance, chemical manufacturing, and government. A handful of attempts succeeded.

The number that should stop you: Claude executed 80 to 90% of the operation independently. Human involvement in key phases topped out at around 20 minutes of active work per session. That’s not a script running in the background. That’s an AI agent making tactical decisions at a scale and speed no human operator team could match.

It’s not the only case. In August 2025, Anthropic separately disclosed that a cybercriminal had used Claude to build, market, and sell several ransomware variants with evasion and anti-recovery features on dark web forums, priced between $400 and $1,200, and appeared dependent on the model to write malware components they couldn’t have built themselves. Our earlier coverage of the Anthropic Claude hack and the three confirmed breaches goes deeper on how that operation actually played out.

Before you assume this means fully autonomous ransomware is here: it isn’t, quite. Anthropic itself flagged that Claude occasionally hallucinated credentials or claimed to have extracted secrets that were actually public information, an error pattern that slowed the campaign rather than stopping it. Security researchers have pushed back on framing this as a fully autonomous “AI hack,” pointing out the model produced false positives and misread logs along the way. The honest read: AI didn’t remove the skill barrier to running a sophisticated multi-target campaign. It lowered it substantially, and lowered barriers are exactly what smaller, less-resourced threat actors need to start operating at a scale that used to require a nation-state budget.

The Payment Recovery Myth

Here’s the assumption that needs to die in every incident response plan built before 2025: pay the ransom, get your data back, move on. The data doesn’t support it, and increasingly, organizations don’t believe it either.

Sophos’s 2025 survey of 3,400 IT and security leaders across 17 countries, all of whom had been hit by ransomware in the prior year, found that 97% of organizations with encrypted data eventually got it back. But only 49% of them recovered by paying and getting the decryption key to work. Backup-based recovery hit a six-year low in the same survey. Put plainly: paying doesn’t reliably work, and neither does assuming your backups will save you, because attackers know backups are the fallback and go after them too.

“Attackers aren’t just after your backups. They’re after your people, your processes, and your data’s reputation. Organizations must prioritize employee awareness, harden identity controls, and treat data exfiltration as an urgent risk, not an afterthought.” Bill Siegel, CEO, Coveware by Veeam

Siegel’s team tracks this from the incident response side, and their Q3 2025 data backs up the shift he’s describing. Only 23% of victims paid a ransom in Q3, an all-time low, and for cases involving data theft without encryption, the payment rate fell to just 19%. When payment does happen, the average dropped to $376,941, down 66% quarter over quarter, with a median of $140,000. Verizon’s DBIR tells the same story from a different angle: median ransom payment fell to $115,000 in 2025 from $150,000 in 2024, and 64% of victims refused to pay outright, up from 50% two years earlier.

None of this means ransomware got less expensive overall. Average recovery cost, excluding any ransom paid, fell 44% to $1.53 million in 2025 from $2.73 million in 2024 per Sophos, which sounds like good news until you factor in IBM’s estimate that total incident cost, including downtime and remediation, still runs around $5.08 million on average. Falling payments and falling recovery costs are two different metrics moving in the same direction for two different reasons: better preparedness on one side, more selective and lower-effort attacks on the other.

“While large companies tend to make the headlines, smaller companies are usually more susceptible to attacks.” Brad Thies, Founder and CEO, BARR Advisory

Thies is pointing at a gap that doesn’t get enough attention: 88% of SMB breaches in the Verizon dataset involved ransomware, compared to 39% of enterprise breaches. Bigger companies have bigger budgets, but that also means better segmentation and faster detection. SMBs are the softer target, and the RaaS economy is built to exploit exactly that.

What This Means for Your Organization

If you’re setting security priorities for 2026, three things from this data should change how you allocate budget:

  • Backup restoration can’t be your only recovery plan. With 75% of attacks now involving data exfiltration before encryption, your incident response process needs a parallel track for extortion negotiation and breach notification, not a fallback that only kicks in after backups fail.
  • Identity is the new perimeter. Coveware’s case data shows attackers increasingly targeting help desks and third-party vendors through impersonation rather than pure technical exploits. Our coverage of Ponemon’s 2026 insider threat cost data is a useful companion read here, since credential compromise and social engineering increasingly overlap.
  • Cyber insurance underwriting has quietly gotten stricter. MFA, EDR, offline backups, and a documented IR plan are now baseline expectations for coverage, not extras. Failing to demonstrate them risks a denied claim, not just a higher premium.

For SMB founders specifically: the 88% vs. 39% gap isn’t a rounding error. It means you can’t operate on the assumption that you’re too small to be worth an attacker’s time. High-volume, low-effort RaaS campaigns exist precisely because smaller companies have weaker controls and can’t absorb extended downtime the way an enterprise can.

The Case for Skepticism

Every figure in this article, including the 32% headline number, is almost certainly an undercount.

Brett Callow, threat analyst at Emsisoft, has made this case consistently for years: ransomware incidents are systematically underreported, and self-reported surveys, leak-site scraping, and law-enforcement complaint data all miss a real share of attacks. He’s pointed to the FBI’s own IC3 figures, which show only about 15% of cybercrime ever gets reported to law enforcement in the first place. Academic research backs him up. A 2025 study in the Journal of Quantitative Criminology used capture-recapture methodology on Dutch police, incident response, and leak-site data, and found only 41.4% of large-company ransomware attacks and 40.2% of medium-company attacks were ever reported to police, even though those rates are already higher than reporting rates for most other cybercrime categories.

That has a real implication for the headline stat this whole article opened with: if 2024’s baseline was itself an undercount, the “true” year-over-year change for 2025 could be higher or lower than 32%. Nobody actually knows, and any writer or vendor presenting a single precise percentage as settled fact is overstating their own certainty.

There’s a second layer of skepticism worth applying to the AI-attack narrative specifically. Framing the Anthropic disclosure as a fully autonomous “killer AI hack” oversells what happened. The campaign succeeded in a small number of cases out of roughly thirty targets, and AI-generated errors slowed the operation at multiple points. The real story is a lowered skill barrier, not a machine running the whole operation without friction.

Worth remembering too: nearly every year since 2020 has been called a “record year” by at least one ransomware vendor. Some of that is attacker escalation. Some of it is simply more trackers entering the market and better leak-site monitoring catching incidents that would have gone unnoticed five years ago. Both things can be true at once.

FAQ

Did ransomware attacks increase in 2025?

Yes. Trackers confirm a significant year-over-year rise, though figures vary: Comparitech recorded a 32% increase to 7,419 attacks, while GuidePoint measured a 58% rise in unique victims. Verizon’s DBIR found ransomware in 44% of confirmed breaches, up from 32% the prior year.

Does paying a ransom guarantee you get your data back?

No. Sophos’s 2025 survey found 97% of organizations with encrypted data eventually recovered it, but only 49% did so by paying and getting usable data back directly, meaning payment alone is not a reliable recovery method even when demands are met.

What percentage of ransomware victims pay?

Payment rates have fallen sharply. Coveware recorded just 23% of victims paying in Q3 2025, an all-time low, while Verizon’s DBIR found 64% of victims refused to pay entirely in 2025, up from 50% two years earlier.

Which industry was targeted most by ransomware in 2025?

Manufacturing was the hardest-hit sector throughout 2025, according to Comparitech and NordStellar data, while healthcare and education attacks stayed roughly flat year over year.

What’s the average cost of a ransomware attack?

Recovery costs, excluding any ransom paid, averaged $1.53 million in 2025 per Sophos, down 44% from $2.73 million in 2024. Including downtime and remediation, total average incident cost runs closer to $5.08 million per IBM’s research.


Where This Goes Next

Here’s what’s different about 2025 compared to every “record year” that came before it: the payment-and-recovery math is breaking down at the same time the attacker toolkit is getting AI-assisted. Fewer victims are paying, and when they do pay, they’re paying less. That should be good news. It isn’t, quite, because attackers are compensating by exfiltrating data as a second extortion lever and by using AI to run more targets with fewer people.

Watch three things over the next 6 to 18 months: whether AI-orchestrated campaigns like GTG-1002 become routine rather than exceptional, whether cyber insurers tighten underwriting requirements further as claims data comes in from 2025’s wave, and whether the SMB ransomware gap narrows or widens as RaaS groups keep optimizing for softer, smaller targets. None of those trends are settled yet. All of them are worth tracking closely if you’re the one who has to explain next year’s incident report to a board.

Want the next data-backed breakdown in your inbox before it hits the front page? Subscribe to The Neural Loop at neuralwired.com/newsletter.

Leave a Reply

Your email address will not be published. Required fields are marked *