2025 Ransomware: Business as Usual, Business is Booming


Getting an edge on your adversaries involves understanding their behaviors and their mindset. Rapid7 Labs took a look at internal and publicly-available ransomware data for Q1 2025 and added our own insights to provide a picture of the year thus far—and what you can do now to reduce your attack surface against ransomware.

The data highlights that businesses can’t afford to take their foot off the gas pedal when it comes to proactively tackling ransomware. Established threat actors and relative newcomers are taking an “if it ain’t broke, don’t fix it” approach, shunning unpredictability for proven revenue generation techniques. And, in almost all cases, the name of the game is data exfiltration and blackmail via leak site posts.

Read more…
Source: Rapid7


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise

    October 8, 2026

    The credential-hijacking Shai-Hulud worm has struck again, this time burrowing its way into a popular AI agent platform SDK. Multiple security researchers reported Thursday that they had detected Shai-Hulud infection in a recent release of the npm package for version 0.5.144 of Tensorlake’s SDK. That package has somewhere in the neighborhood of 12,000 downloads per week, ...

  • UK and Germany launch joint-partnership to counter sabotage and cyber attacks

    October 8, 2026

    Prime Minister Andy Burnham will travel to Berlin today for talks with Chancellor Friedrich Merz, as the UK and Germany work together on technologies and industries that will drive growth in every UK postcode, and build resilience against shared threats. The UK and Germany are Europe’s two largest economies and biggest investors in defence and today ...

  • Attackers uses poem to infect thousands of servers with malware

    October 8, 2026

    Somewhere in the trackless wastes of cyberspace, a digital Robert Langdon is decoding an ancient poem to find the location of his masters and receive instructions on his next steps. I might be exaggerating a bit, but this is the gist of a rather bizarre story on cyberattacks and cryptocurrency mining. Cybersecurity researchers from Lumen’s Black ...

  • Attackers hijack country-code domains to impersonate Google and other services

    October 8, 2026

    According to Google, attackers compromised infrastructure behind three country-code domain namespaces—.gh (Ghana), .sl (Sierra Leone), and .as (American Samoa)—and used it to obtain unauthorized HTTPS certificates for Google domains and other organizations. These domain endings aren’t limited to sites serving those countries, so the risk can extend to users elsewhere. This wasn’t a break in encryption, ...

  • Asos customers receive ‘hack’ notification threatening to leak data

    October 6, 2026

    Asos is investigating after users of its mobile app received a notification claiming hackers had “fully compromised” the online fashion retailer’s data. The value of Asos’s shares on the London Stock Exchange dived more than 14% after thousands of customers received a notification titled “Asos hacked” with a link that sent them to the Telegram messaging ...

  • Blinder Tunnel Campaign Targets Iraqi Infrastructure

    October 6, 2026

    Palo Alto Unit 42 discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Unit 42 tracks the activity as CL-STA-1178. This activity includes a campaign they call “Blinder Tunnel,” that targeted Iraqi critical infrastructure in March 2026, following infrastructure staging ...