Ransomware Statistics
2025-2026

 

How we track ransomware activity.

Ransomware remains a significant and growing threat—unique attacks rose nearly 25% in 2024 SOTU. We examine ransomware attacks by extracting posts from ransomware-dedicated leak sites (DLS) and then use generative AI to identify the victim, their location, and sector. Contact us for a detailed analysis tailored to your company—covering ransomware groups, attack patterns, and strategies to protect your extended attack surface. Below, explore ransomware attack statistics from 2025 and beyond, updated monthly.

Ransomware attacks 2025-2026

Bitsight CTI observed a major increase in the total number of ransomware attacks in Q4 2025 in comparison with Q3 2025. Similar to Q3, the most heavily targeted region in Q4 remained North America (79% of attacks), with the Manufacturing sector the top sector for attacks in Q4 (27%). The most active ransomware groups in Q4 were Qilin,  Akira, and Sinobi. In Q4 2025, Bitsight CTI identified 6 new RaaS programs seeking affiliates or collaborators on cybercrime forums, Telegram, or their own leak sites.

Most active ransomware groups

In the past 12 months, ransomware has been on the rise and led by Qilin with an estimated 1139 attacks. Below are the top ransomware victims per group.

Top ransomware victims per country

In the past 12 months, United States led all countries with 4069 attacks, or 34.8% of the total. Below are the top ransomware victims per country.

Top 10 countries

Top ransomware victims per sector

In the past 12 months, Manufacturing led all sectors with 1688 attacks, or 27.6% of the total. Below are the top ransomware victims per industry.

More signal, less noise. Latest ransomware headlines from Bitsight Pulse.

  • 2026-02-10 | Beasley & Gilkison Llp Attacked By Akira Ransomware Group
    The Akira ransomware group has targeted Beasley & Gilkison LLP, a legal services firm based in East Central Indiana. The attacker…
  • 2026-02-10 | Carroll County Cannabis Co. Attacked By Qilin Ransomware Group
    The Qilin group has targeted Carroll County Cannabis Co. in a ransomware attack. The attack has potentially compromised sensitive…
  • 2026-02-10 | Anabuki Kosan Attacked By Qilin Ransomware Group
    The Qilin group has announced a ransomware attack on Anabuki Kosan, a company that has been targeted and had its data compromised…
  • 2026-02-09 | Langley Twigg Law Attacked By Anubis Ransomware Group
    The Anubis ransomware group has targeted Langley Twigg Law, a legal firm, in a ransomware attack. This is the second part of the …
  • 2026-02-09 | Getly Attacked By Killsecurity Ransomware Group
    The KillSecurity group has listed a new victim, Getly, on their ransomware dedicated leak site. This indicates that Getly has bee…

Bitsight Pulse consolidates the latest cybersecurity news, ransomware events and data breaches from hundreds of deep web, dark web, social and OSINT sources. Using Bitsight AI, Bitsight Pulse filters and personalizes these news events to your interests.

Free threat assessment

Get up-to-date threat data for your organization

Attacks start long before the breach. Understand the signals attackers use—uncover ransomware activity, leaked credentials, and exposed vulnerabilities mapped to your organization using real threat intelligence from Bitsight.