Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationcybercrime-service-ecosystemransomware-tooling-evolutioncritical-infrastructure-threat

Ransomware Surge and Ecosystem Fragmentation in 2025

Updated 1mo agoFirst seen Dec 19, 20258 sources

Ransomware attacks in 2025 have escalated both in volume and sophistication, with a 34%-50% increase in incidents compared to the previous year and over 4,700 confirmed attacks globally between January and September. The ransomware ecosystem has become highly fragmented following law enforcement actions against major groups like LockBit and ALPHV/BlackCat, resulting in the emergence of 45 new groups and a record 85 active extortion operations. Attackers have adopted advanced tactics such as double and triple extortion, AI-driven phishing, and exploitation of cloud and operational technology, with critical infrastructure sectors—manufacturing, healthcare, energy, transportation, and finance—bearing the brunt of these attacks. Despite the surge in attacks, ransom payment rates have dropped to historic lows, forcing threat actors to adapt their business models and extortion strategies.

The operational landscape has also been shaped by shifting alliances and rebranding efforts among ransomware groups. Notably, the alleged alliance between Qilin, DragonForce, and LockBit has not led to a consolidation of power but rather continued the trend of ecosystem fragmentation. Analysis of data leak site activity post-alliance announcement shows no significant operational recovery for LockBit, despite renewed branding and the release of a new malware version. These developments underscore the resilience and adaptability of ransomware actors, as well as the ongoing challenges faced by defenders in tracking and mitigating the impact of increasingly decentralized and sophisticated ransomware operations.

Share:
Ransomware Surge and Ecosystem Fragmentation in 2025
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Apr 15, 20262mo ago

LockBit resurfaces with 207 claimed victims in 2026

A new analysis reported that LockBit had claimed 207 victims in 2026, indicating a public comeback after the group's apparent halt in new postings after June 2025. The development suggests renewed resilience or reactivation despite earlier signs of decline and prior disruption pressure.

LockBit Won't Die: 207 Victims in 2026 and What Ransomware Resilience Actually Looks Like
Apr 8, 20263mo ago

TRM reports 93 new ransomware variants and flat payments in 2025

TRM Labs reported that ransomware activity expanded in 2025 even as ransom payments stagnated, with leak-site victim postings up 44%, ransom payments holding near $850 million, and total ransomware-linked inflows around $1.3 billion. The firm said ecosystem fragmentation accelerated with 93 new ransomware variants in 2025, a 94% increase from 2024, while revenue remained concentrated among established groups.

New Disruption Opportunities in the Evolving Ransomware Ecosystem | TRM Blog
Mar 31, 20263mo ago

Check Point reports ransomware consolidation in Q1 2026

Check Point Research reported that ransomware activity stayed historically high in Q1 2026 with 2,122 victims posted across more than 70 leak sites, but the ecosystem shifted away from 2025 fragmentation toward consolidation. The top 10 groups accounted for 71.1% of publicly claimed victims, led by Qilin, while The Gentlemen emerged as a major actor and LockBit 5.0 showed a strong re-emergence.

The State of Ransomware - Q1 2026 - Check Point Research
Dec 19, 20256mo ago

Ransomware ecosystem fragments into more groups in 2025

By 2025, the ransomware landscape had become highly fragmented, with 85 active groups and 45 new entrants. This shift followed law enforcement disruption of major operations such as LockBit and ALPHV/BlackCat and coincided with growing use of data-only extortion and other adapted tactics.

Sep 30, 20259mo ago

KELA says half of 2025 ransomware attacks hit critical sectors

KELA reported that 2,332 ransomware incidents targeted critical infrastructure sectors between January and September 2025, a 34% increase year over year and roughly half of all recorded attacks. Manufacturing, healthcare, energy, transportation, and financial services were highlighted as top targets, with manufacturing attacks rising 61% to 838 incidents.

Half of 2025 ransomware attacks hit critical sectors as manufacturing, healthcare, and energy top global targets - Industrial Cyber

Global ransomware incidents surge through January-September 2025

Between January and September 2025, 4,701 confirmed ransomware incidents were recorded globally, representing a 34% to 50% increase over 2024. The period also saw ransom payment rates fall to roughly 23% to 25%, pushing threat actors toward new extortion models.

Sep 16, 20259mo ago

Qilin activity rises following the alliance announcement

After the September 15 alliance announcement, Qilin experienced a notable spike in activity, likely driven by increased visibility and migration of operators. DragonForce and Qilin otherwise appeared to continue growing autonomously rather than as part of a tightly integrated coalition.

Sep 15, 20259mo ago

Qilin, DragonForce, and LockBit announce an alliance

On September 15, 2025, an alliance between the ransomware groups Qilin, DragonForce, and LockBit was announced. Subsequent analysis suggests the move was largely symbolic, especially for LockBit, rather than evidence of deep operational integration.

Jul 31, 202511mo ago

Comparitech reports 65% rise in government ransomware attacks in H1 2025

Comparitech reported 208 ransomware attacks against government agencies worldwide in the first half of 2025, up 65% from the first half of 2024 and 25% from the second half of 2024. The analysis identified the United States as the most affected country and highlighted Qilin, INC, RansomHub, Funksec, Medusa, and SafePay among the groups targeting public-sector entities.

Comparitech reports 65% surge in ransomware attacks on government agencies in 2025 - Industrial Cyber
Jun 30, 20251y ago

LockBit ceases posting new claims after June 2025

The Yarix analysis states that LockBit showed no operational recovery or new victim claims after June 2025. This marked a visible decline in the group's public activity amid broader pressure on major ransomware operations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

156 LINKEDOpen in app
Affected products
7 linked
FortiproxyWindowsFortigateVmware EsxiFortiosOnedriveOracle E-Business Suite
Organizations
78 linked
OracleFortinetMicrosoft CorporationCoinbaseBitdefenderVerizon CommunicationsChange HealthcareCl0pSafepayAccellionLockBitAkiraQilinRansomHubDragonForceINC RansomFortraALPHV/BlackCatHuntersSalesforceCheck Point Software TechnologiesVmwareCisco SystemsfbiNational Health ServiceNational Cyber Security CentreUnitedHealth GroupBlackSuitMcDonald’sMetropolitan Police ServiceZscalerBridgestoneRhysidaThe Walt Disney CompanyWorldLeaksKELAScattered Lapsus$ HuntersPalo Alto NetworksCISASnowflakeSYNLABIngram MicroEsetProgress SoftwareHBO MaxJaguar Land RoverToyota Motor CorporationLynx Software TechnologiesbabukCleoCrowdStrikeHarrodsSynnovisSunflower Medical GroupCitrix SystemsMedusaAustralian Cyber Security CentreQantasShinyHuntersPlayBitsightKing's College Hospital NHS TrustHiveScattered SpiderPlay RansomwareOptumGentlemenAmerican Medical AssociationWineLabASDNikki-Universal Co. LtdOCRSault Ste. Marie Tribe of ChippewaGuy's and St Thomas' NHS Foundation TrustTRM LabsGoogleMarks & SpencerCo-op
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.