Site navigation

Active Ransomware Groups Dwindle, But Victim Numbers Rise

Elizabeth Greenberg

,

ransomware groups
The number of active ransomware groups may be dropping, but victim numbers were up in the last quarter of 2025.

Despite a decline in the number of ransomware groups actively operating across the globe, the number of victim organisations climbed year on year and quarter on quarter in the last quarter of 2025.

This is according to ReliaQuest’s Ransomware and Cyber Extortion in Q4 2025 report, which found that the last three months of 2025 saw ransomware victims increase by 50% compared to the third quarter, and rose 40% compared to the same time span in the previous year.

The research suggested that while the amount of ransomware groups dwindled, the most advanced and organised syndicates are increasing their activity.

To achieve maximum impact with minimum risk, ransomware groups have been focussing on infiltrating networks and executing ransomware quickly to avoid detection.

To put further pressure on targeted organisations to pay ransom, threat actors are commonly releasing snippets of stolen data on the dark web as part of their persuasion tactics.

ReliaQuest found that the most prolific ransomware groups in the last quarter of 2025 were Qilin, Akira, and Sinobi.

With over 450 victims, Qilin accounted for the most compromised organisations in the last three months of 2025, with big ticket targets including Japanese beer company Asahi.

Akira ransomware followed behind, with over 200 victims in the same time period.


Recommended reading


Sinobi, which saw a 300% increase in its targets in quarter four of 2025, became the third most active ransomware group in Q4 2025. The group likely started in 225 as a spin off from the Lynx ransomware group, which is still active.

Outside of the top three, the report noted that the Clop ransomware group claimed 116 victims despite little activity in the previous quarter.

ReliaQuest noted that ransomware in this time period relied on established tactics and persistent weaknesses – slow vulnerability patches, a lack of enforced access controls, and poor data exfiltration detection efficiency.

Organisations are advised to harden their remote access controls to prevent the exploitation of edge devices, strengthen their data exfiltration monitoring by tailoring detections and alerts, and secure high-impact shared infrastructure to prevent ransomware from proliferating into an enterprise-wide outage.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data