BlackFog Report Reveals 63% Increase in Q2 Ransomware Attacks YoY | #ransomware | #cybercrime


SAN FRANCISCO, July 16, 2025–(BUSINESS WIRE)–BlackFog, the leader in ransomware prevention and anti data exfiltration (ADX), today revealed findings from analysis of ransomware activity from April to June 2025 across publicly disclosed and non-disclosed attacks.

The data shows that over this period there was a 63% increase in publicly disclosed attack volumes, with a total of 276 incidents compared to Q2 2024. Notably, this is the highest number for this timeframe since BlackFog began tracking in 2020.

Key findings for April to June

Sharp increase in publicly disclosed attacks year on year

All three months set a new high compared with the same time period in previous years. Year on year the increases by month are:

  • A 113% increase in June with a total of 96 attacks

  • A 51% increase in April with a total of 89 attacks

  • A 40% increase in May with a total of 91 attacks

Healthcare sector the most targeted

In terms of disclosed attacks, healthcare was the most targeted sector with 52 attacks. This was followed by the government sector, which recorded 45 attacks and the services industry with 33 attacks.

Retail in the ransomware crosshairs

The retail sector recorded its highest ever Q2 attack volumes, with UK retailers in particular bearing the brunt of high-profile ransomware attacks. The number of publicly disclosed ransomware incidents in this sector jumped by 58% compared to Q1 2025.

The Construction, Hospitality and Arts and Entertainment sectors also reported the highest ever Q2 attack volumes. Across the board, the use of data exfiltration remained consistently high, with 95% of publicly disclosed attacks involving the theft of sensitive information.

Qilin dominates the global ransomware threat with a strategic shift

Amongst 53 active ransomware groups, the Qilin ransomware gang took the lead as the most active, responsible for 10% (28) of disclosed attacks and 15% of those revealed on dark web leak sites. Earlier this year, CISA issued a formal warning after Qilin struck high profile targets in the UK and US with the group labelled a major risk to critical infrastructure.

The hidden landscape: unreported incidents continue to increase

The figures also reveal that the scale of hidden activity remains significant with 80.9% of all ransomware attacks going unreported. Across Q2 there were 1,446 undisclosed ransomware attacks marking a 19% increase compared to the same quarter in 2024.

As with the first quarter of this year, the services industry was the hardest hit, accounting for 23% (337) of all undisclosed attacks in Q2.

Commenting on the findings, Dr. Darren Williams, Founder and CEO of BlackFog said: “The findings lay bare the extent of the challenge that organizations face. The past few months have been especially punishing for global retailers, with prominent high street stores falling victim and absorbing the financial and operational fallout of these attacks.



Source link

.........................

National Cyber Security

FREE
VIEW