Despite a decline in the number of ransomware groups actively operating across the globe, the number of victim organisations climbed year on year and quarter on quarter in the last quarter of 2025.
This is according to ReliaQuest’s Ransomware and Cyber Extortion in Q4 2025 report, which found that the last three months of 2025 saw ransomware victims increase by 50% compared to the third quarter, and rose 40% compared to the same time span in the previous year.
The research suggested that while the amount of ransomware groups dwindled, the most advanced and organised syndicates are increasing their activity.
To achieve maximum impact with minimum risk, ransomware groups have been focussing on infiltrating networks and executing ransomware quickly to avoid detection.
To put further pressure on targeted organisations to pay ransom, threat actors are commonly releasing snippets of stolen data on the dark web as part of their persuasion tactics.
ReliaQuest found that the most prolific ransomware groups in the last quarter of 2025 were Qilin, Akira, and Sinobi.
With over 450 victims, Qilin accounted for the most compromised organisations in the last three months of 2025, with big ticket targets including Japanese beer company Asahi.
Akira ransomware followed behind, with over 200 victims in the same time period.
Recommended reading
- Cyber-attacks Forcing Enterprises Offline Up to Two Weeks
- Quorum Cyber: AI & Ransomware Are Industrialising Cyber Crime
- Major Banks Hit by Vendor Cyber-attack
- UK Firms Warned to Prepare Now for Russian DoS Attacks
Sinobi, which saw a 300% increase in its targets in quarter four of 2025, became the third most active ransomware group in Q4 2025. The group likely started in 225 as a spin off from the Lynx ransomware group, which is still active.
Outside of the top three, the report noted that the Clop ransomware group claimed 116 victims despite little activity in the previous quarter.
ReliaQuest noted that ransomware in this time period relied on established tactics and persistent weaknesses – slow vulnerability patches, a lack of enforced access controls, and poor data exfiltration detection efficiency.
Organisations are advised to harden their remote access controls to prevent the exploitation of edge devices, strengthen their data exfiltration monitoring by tailoring detections and alerts, and secure high-impact shared infrastructure to prevent ransomware from proliferating into an enterprise-wide outage.





