Quick Takeaways
- Ransomware attacks surged in Q3 2025, with a 36% increase from the previous year, targeting critical sectors like healthcare, government, and tech, which accounted for over half of the incidents.
- Publicly disclosed attacks peaked in July with a 50% rise, while undisclosed attacks also increased by 21%, highlighting the escalating scale and severity of ransomware activity.
- The Qilin group remained the most active ransomware gang, responsible for 20 incidents, with new groups like DEVMAN emerging and engaging in large-scale, region-specific campaigns, including a $91 million demand against Shimao.
- Attackers increasingly focus on geopolitically and economically strategic regions, tailoring campaigns to exploit local vulnerabilities, leverage regional language and software, and target supply chains, maximizing financial and geopolitical gains.
The Issue
BlackFog’s recent analysis reveals a disturbing escalation in global ransomware activity during July to September 2025, with a 36% increase compared to the same period the previous year, marking a new record with 270 publicly known attacks and a significant surge in undisclosed incidents. These assaults primarily targeted high-stakes sectors such as healthcare, government, and technology—leading to widespread disruptions like grounded aircraft and halted manufacturing processes—affecting organizations across 93 countries. The attacks were often orchestrated by a shifting landscape of over 50 ransomware groups, with the notorious Qilin gang leading in activity, and highlighted a disturbing trend: as ransomware operations become more sophisticated and geographically strategic, attackers are increasingly focusing on regions and industries where legal deterrents are weaker, maximizing their impact through tailored campaigns and supply-chain breaches.
The report emphasizes that data theft remains a core tactic, with exfiltrated volumes reaching over 500GB per incident, and about 40% of attacks still unlinked to any known group, showcasing the complexity and anonymity of the threat landscape. High-profile cases, like the September attack on a UK nursery and a US$91 million ransom demand against China’s Shimao Group, underscore the expanding scope and audacity of cybercriminals. BlackFog attributes this uptick to the evolving business models of ransomware gangs, which leverage ransomware-as-a-service and affiliate networks to target lucrative and vulnerable regions, driven by the economic, social, and legal incentives specific to each geography. Overall, the report underscores the urgent need for organizations worldwide to reinforce defenses and safeguard data, as cybercriminals increasingly match precision with audacity in their relentless pursuit of profit and disruption.
What’s at Stake?
BlackFog’s recent analysis highlights a significant escalation in global ransomware activity during July to September 2025, characterized by a 36% increase from the previous year and a surge in both disclosed and undisclosed attacks across 93 countries. The impact has been profound, disrupting critical sectors such as healthcare, government, and manufacturing—leading to grounded aircraft, halted production lines, and compromised sensitive data, including personal information of children, parents, and carers. Notably, threat actors like the Qilin gang remain highly active, responsible for a quarter of attacks, with many incidents involving extensive data theft—averaging over 500GB per breach—and a growing trend towards targeted, geographically focused campaigns that exploit regional vulnerabilities, financial leverage, and supply chain dependencies. This evolving landscape underscores the urgent need for organizations worldwide to bolster defenses, protect data assets rigorously, and mitigate the incentives for cybercriminals to continue their disruptive operations.
Possible Action Plan
In an era where digital vulnerabilities are increasingly exploited, addressing ransomware threats swiftly and effectively is crucial to safeguard sensitive information and maintain operational continuity, especially as targeted sectors face record highs.
Preventive Measures
- Implement advanced threat detection tools
- Regularly update and patch systems
- Enforce strong, unique passwords and multi-factor authentication
Response Strategies
- Activate comprehensive incident response plans
- Isolate infected devices immediately
- Notify authorities and cybersecurity experts
Recovery Processes
- Restore data from secure backups
- Conduct forensic analysis to understand breach
- Review and strengthen security policies
Stay Ahead in Cybersecurity
Stay informed on the latest Threat Intelligence and Cyberattacks.
Understand foundational security frameworks via NIST CSF on Wikipedia.
Disclaimer: The information provided may not always be accurate or up to date. Please do your own research, as the cybersecurity landscape evolves rapidly. Intended for secondary references purposes only.
Cyberattacks-V1
