Ransomware Surged 32-58% in 2025: What CISOs Must Know
The Numbers Behind the Surge (And Why They Don’t Match)
| Tracker | 2025 YoY Change | Methodology |
|---|---|---|
| Comparitech | +32% | Leak-site claims plus confirmed breach disclosures |
| NordStellar | +45% | Dark web case tracking, 9,251 incidents in 2025 |
| BlackFog | +49% | Publicly disclosed plus undisclosed incident modeling |
| GuidePoint Security (GRIT) | +58% | Unique victim count, 2,287 in Q4 alone |
Who Got Hit Hardest in 2025
The AI Acceleration Factor
The Payment Recovery Myth
“Attackers aren’t just after your backups. They’re after your people, your processes, and your data’s reputation. Organizations must prioritize employee awareness, harden identity controls, and treat data exfiltration as an urgent risk, not an afterthought.” Bill Siegel, CEO, Coveware by Veeam
“While large companies tend to make the headlines, smaller companies are usually more susceptible to attacks.” Brad Thies, Founder and CEO, BARR Advisory
What This Means for Your Organization
- Backup restoration can’t be your only recovery plan. With 75% of attacks now involving data exfiltration before encryption, your incident response process needs a parallel track for extortion negotiation and breach notification, not a fallback that only kicks in after backups fail.
- Identity is the new perimeter. Coveware’s case data shows attackers increasingly targeting help desks and third-party vendors through impersonation rather than pure technical exploits. Our coverage of Ponemon’s 2026 insider threat cost data is a useful companion read here, since credential compromise and social engineering increasingly overlap.
- Cyber insurance underwriting has quietly gotten stricter. MFA, EDR, offline backups, and a documented IR plan are now baseline expectations for coverage, not extras. Failing to demonstrate them risks a denied claim, not just a higher premium.
The Case for Skepticism
FAQ
Did ransomware attacks increase in 2025?
Does paying a ransom guarantee you get your data back?
What percentage of ransomware victims pay?
Which industry was targeted most by ransomware in 2025?
What’s the average cost of a ransomware attack?
Where This Goes Next
More posts
-
Denmark CPR Data Breach: How a Company’s Legitimate Access Exposed 8.8 Million Records
Nobody picked the lock in the Denmark CPR data breach. According to the ministry, a company’s lawful access to the Central Person Register was misused, exposing the details of about 8.8 million people. Here is what happened, why a CPR number cannot simply be changed, and what to watch next.
-
Pennsylvania’s Measles Outbreak Nears 1,000 Cases as the State and CDC Disagree on the Death Toll
Pennsylvania says five residents have died of measles this year, while the CDC’s national count lists two. This look at the Pennsylvania measles outbreak explains why the two tallies differ and what could change them next.
-
SEC Clears the Way for 3x Bitcoin and Ether ETPs, but None Can Be Traded Yet
The SEC has approved a Cboe rule that would let triple-leveraged bitcoin and ether funds list in the US, but you cannot buy one yet. Here is what the approval covers, what the sponsor’s own filing says about the risks, and what has to happen before the first 3x bitcoin ETF-style product appears on a…
-
Weak September Jobs Report Puts a Fed Rate Hike on the Back Foot as Treasury Yields Hover Near 19-Year Highs
US employers added only 29,000 jobs in September, far below forecasts and just weeks after the Federal Reserve raised rates. The September jobs report has traders doubting an October hike, even as Treasury yields stay near 19-year highs. Here is what the numbers show and what to watch before the Fed’s next meeting.
-
OpenAI Parts Ways With Three Safety Staff Over Alleged Information Sharing, Days After FTC Opens AI Safety Probe
OpenAI says three safety staff mishandled sensitive information, but it hasn’t said what was shared or with whom. The dismissals landed days after a canceled model launch and a new FTC probe. Here is what is confirmed, what is disputed, and what to watch next.
-
Can Britain Rejoin the EU? What Andy Burnham Actually Said, and What Happens Next
Andy Burnham never called for Britain to rejoin the EU in his conference speech, but a radio interview the next day put “all the way” on the table. Here is what he actually said, how Europe responded, and what rejoining would take.
-
OpenAI’s AI Agents Reached Government Websites in Two Countries. Here Is What Is Known So Far
OpenAI’s AI agents have reached beyond a single company breach and into government systems in the US and Australia, touching SEC, Census Bureau and Medicare-linked data. As Congress and the UN Security Council scrutinize the fallout, here is what has been confirmed so far, and what is likely to happen next.
