Close Menu
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Teen Hacker and Ransomware Leader Arrested in Major Cyber Crime Crackdown

October 1, 2026

WordPress Backdoor Reinstates via Files, Database, Shared Memory

October 1, 2026

Attackers Exploit ScreenConnect for Remote Access Breaching

October 1, 2026
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance
Home » Ransomware Surge Hits Businesses and Manufacturing Hard Amid Declines in Government and Healthcare
Cybercrime and Ransomware

Ransomware Surge Hits Businesses and Manufacturing Hard Amid Declines in Government and Healthcare

Staff WriterBy Staff WriterOctober 3, 2025No Comments4 Mins Read6 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

Fast Facts

  1. Ransomware attacks in 2025 have increased by 36% compared to 2024, reaching 5,186 incidents, with a quarterly rise of 6%.
  2. The manufacturing sector remains the most targeted industry, with a 13% increase in attacks from Q2 to Q3 2025, totaling 296 incidents.
  3. Attack patterns show a shift towards healthcare-related entities like medical device manufacturers and billing providers, with a 60% surge in targeting these non-clinical healthcare companies.
  4. The most active ransomware gangs are Qilin, Akira, INC, and Play, with Qilin and INC leading in confirmed attacks, and over 335 terabytes of data stolen across all incidents.

Key Challenge

Recent data from Comparitech reveals a distressing surge in ransomware attacks so far in 2025, with over 5,186 incidents reported, marking a 36% increase compared to the same period in 2024. These attacks have mainly targeted businesses, manufacturing firms, and increasingly third-party vendors rather than traditional sectors like healthcare and government, which have seen declines in recent quarters. Notably, ransomware gangs such as Qilin, INC, and Akira have been the most active, claiming hundreds of attacks and stolen data exceeding 335 terabytes. High-profile incidents include cyberattacks on European airports via Collins Aerospace, Swedish municipal data breaches affecting over a million people, and major data thefts from healthcare and financial companies, often through exploiting vulnerabilities in third-party vendors or supply chains. The aggressive rise in attacks, especially on manufacturing and healthcare-related entities that handle vast amounts of sensitive data without directly providing patient care, underscores hackers’ growing focus on leveraging less obvious targets to maximize disruption and data theft, with average ransom demands soaring into millions of dollars. These trends, reported by Anna Ribeiro, indicate a dangerously escalating cyber threat landscape that is affecting a broad spectrum of industries and highlighting the importance of enhanced cybersecurity measures across the board.

Risks Involved

In 2025, ransomware attacks surged globally, with over 5,186 incidents reported—an alarming 36% rise from 2024—highlighting escalating cyber risks that threaten diverse sectors and disrupt essential services. While attacks on government entities decreased by 31%, they remain significant, with a total of 274 incidents so far this year, including multi-million-dollar ransom demands averaging $3.57 million per attack. The healthcare sector continues to be heavily targeted, especially organizations indirectly involved in healthcare delivery, such as medical device manufacturers and pharma companies, which are exploited for their access to extensive health data, leading to widespread breaches impacting millions. Manufacturing remains the most targeted industry, experiencing a 13% increase, with cybercriminal gangs like Qilin and INC leading the assault, stealing hundreds of terabytes of data. These attacks not only threaten operational continuity but also result in substantial financial losses, data thefts exceeding 335 terabytes, and mass disruptions, exemplified by incidents impacting European airports, multinational municipalities, and international corporations. The pattern indicates a shift towards sophisticated, high-volume, data-rich attacks that pose profound risks to data integrity, economic stability, and national security.

Possible Next Steps

In an era where digital infrastructure underpins almost every aspect of operation, swift and effective remediation is crucial, especially as the recent 36% spike in ransomware attacks disproportionately affects businesses and manufacturing sectors, while government and healthcare systems experience declines. Prompt action can prevent devastating financial loss, protect sensitive data, and ensure continuity of operations amid increasing cyber threats.

Mitigation Steps:

  • Implement advanced endpoint security solutions
  • Conduct regular cybersecurity training
  • Develop robust backup protocols
  • Enforce strict access controls
  • Monitor network activity continuously

Remediation Steps:

  • Isolate infected systems immediately
  • Collaborate with cybersecurity experts for incident response
  • Remove malicious software thoroughly
  • Restore data from secure backups
  • Conduct post-incident analysis to prevent future attacks

Explore More Security Insights

Discover cutting-edge developments in Emerging Tech and industry Insights.

Understand foundational security frameworks via NIST CSF on Wikipedia.

Disclaimer: The information provided may not always be accurate or up to date. Please do your own research, as the cybersecurity landscape evolves rapidly. Intended for secondary references purposes only.

Cyberattacks-V1

Businesses CISO Update Comparitech critical infrastructure cyber attacks cyber threats Cybersecurity Government healthcare manufacturing MX1 Ransomware threat landscape
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTop 10 Supply Chain Security Leaders of 2025
Next Article Alert: New Threat Group Hijacks IIS Servers for SEO Fraud
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

WordPress Backdoor Reinstates via Files, Database, Shared Memory

October 1, 2026

Attackers Exploit ScreenConnect for Remote Access Breaching

October 1, 2026

MetaMask breach targets Ethereum validator security vulnerabilities

October 1, 2026

Comments are closed.

Latest Posts

Kimwolf v7 Android Botnet: Cloaking DDoS Traffic as Legitimate Browsing

September 28, 2026

Attackers Exploit SharePoint Authentication Bypass Post-PoC Release

September 25, 2026

Apple Alerts: 110 Countries at Risk of Spyware Attacks

September 22, 2026

Urgent: Exploitation of SAP Commerce Cloud CVE-2026-58231 Sparks Immediate Threat

September 19, 2026
Don't Miss

WordPress Backdoor Reinstates via Files, Database, Shared Memory

By Staff WriterOctober 1, 2026

Quick Takeaways A sophisticated WordPress backdoor named "SC" employs multiple persistent, self-healing components across files,…

Attackers Exploit ScreenConnect for Remote Access Breaching

October 1, 2026

MetaMask breach targets Ethereum validator security vulnerabilities

October 1, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Teen Hacker and Ransomware Leader Arrested in Major Cyber Crime Crackdown
  • WordPress Backdoor Reinstates via Files, Database, Shared Memory
  • Attackers Exploit ScreenConnect for Remote Access Breaching
  • MetaMask breach targets Ethereum validator security vulnerabilities
  • Clico cyber tool reveals Czech firms’ security weaknesses
About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Teen Hacker and Ransomware Leader Arrested in Major Cyber Crime Crackdown

October 1, 2026

WordPress Backdoor Reinstates via Files, Database, Shared Memory

October 1, 2026

Attackers Exploit ScreenConnect for Remote Access Breaching

October 1, 2026
Most Popular

Gefährliche Angriffe: Wie Cyberkriminelle Ihre Identität angreifen

January 29, 2026235 Views

CISA Alerts: Critical Vulnerability in Splunk Enterprise Under Active Attack

June 19, 2026212 Views

Salesforce Disables Klue App After Data Breach from Token Abuse

June 19, 2026210 Views

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025

Categories

  • Compliance
  • Cyber Updates
  • Cybercrime and Ransomware
  • Editor's pick
  • Emerging Tech
  • Events
  • Featured
  • Insights
  • Most Read
  • Threat Intelligence
  • Uncategorized
© 2026 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.