Ransomware Increases 126% in Q1 25

Ransomware attacks have reached a record high in Q1 2025. Check Point Research's latest State of Ransomware report reveals an increase 126% per yearwith 2.289 published victims in 74 ransomware groups — the most ever recorded in a single quarter. Named victims across 74 ransomware groups – the most ever recorded in a single quarter.jpg ransomware

The trends:

See more articles from iGuRu.gr when you search for news on Google.

Cl 0 p led Q1 activity with 392 victims , exploiting zero-day flaws in Cleo file transfer tools , abandoning encryption in favor of data theft and extortion. 83% of its victims were in North America and 33% were from the consumer goods and services sector – reflecting strategic supply chain targeting.

RansomHub , LockBit ’s successor , featured 228 victims , driven by aggressive affiliate recruitment and generous profit sharing, which allowed it to inherit the abandoned share of LockBit ’s criminal activity.

- The dust Bjorka and FunkSec publish systematically recycled or false claims about the number of victims (167 victims for the dust Bjorka and over 170 victims for the FunkSec), blurring the data and inflating their reputation, while at the same time attracting collaborators and pressuring victims. The FunkSec is also suspected of being used malware developed with artificial intelligence, lowering the barriers to entry for attackers and blurring the lines between

The where and the why:

– The US remains the top target of ransomware, with nearly 50% of victims , due to the greater likelihood of ransomware payments.

– In the United Kingdom , Medusa ransomware accounted for 9% of local victims , five times its global share.

– In Germany , Safepay dominated with 17,5% of reported incidents – suggesting deliberate, regional targeting.

Looking at this geographic distribution, ransomware groups don't cast wide nets – they make surgical, strategic decisions based on local infrastructure, legal systems, and payment capabilities.

While victim disclosures are skyrocketing, actual ransomware payments have fallen by 35% according to Chainalysis . This widening gap suggests two worrying trends: either victims are increasingly refusing to pay, or some “victims” may not be real at all.

The evolution of Ransomware into non-encryption extortion—combined with groups faking attacks using old or public data—means that reputational damage, not decryption, is now the primary driver of pressure. Traditional metrics based on leak site disclosures no longer provide an accurate picture. This also makes it much harder for defenders, regulators, and even law enforcement to accurately track threat actors or understand the true scale of the risk.

Sergey Shykevich, Threat Intelligence Group Manager at Check Point Software, said:

“The 126% increase in ransomware is more than a number, it’s a signal. It suggests smarter, faster, and harder-to-detect campaigns and groups trying to manipulate our minds. Artificial intelligence tools, false victim claims, and regionally tailored tactics mean organizations must move beyond reactive defenses and embrace proactive, information-driven security.”


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).