Site navigation

Data Theft Surges to 96% of Ransomware Attacks

Tom Quinn

,

ransomware
“Attackers aren’t just breaking in – they’re intent on stealing data to power extortion,” said Dr Darren Williams, BlackFog.

Hackers are now more interested in data theft than disruption, with ransomware gangs embedding AI into their operations to move faster and slip by traditional defences, according to the latest report from BlackFog.

The cyber firm’s 2025 State of Ransomware Report is the latest study to link AI with a record rise in ransomware activity, finding a 49% increase in publicly disclosed incidents, with last year seeing 1,174 cyber assaults, nearly four times higher than in 2020.

However, these numbers represent just a fraction of a much larger, hidden wave of incidents. Investigating data leak sites, BlackFog estimated that 86% of ransomware attacks went undisclosed in 2025, meaning only around seventeen in every 100 hacks are being made public.

The study found that almost all of these attacks (96%), both public and undisclosed, now involve data exfiltration, a 20% increase over the last five years, with attackers prioritising speed and scale over upfront scare tactics.

According to BlackFog, large-scale data theft has become a core component of modern ransomware, with operators having found that ramping up the extortion pressure on sensitive data results in bigger paydays.

This has been made possible by hackers’ growing dependence on AI. Over the last year, BlackFog tracked how ransomware gangs used the tech, going from genAI sharpening phishing lures and performing simple scans of security environments, to the deployment of polymorphic malware that “learns” how to evade detection in real time. 

By the end of 2025, the study found that AI-enabled ransomware was demonstrating autonomy and adapting its tactics on the fly, presenting real problems for static security controls, an issue made worse by a wave of unmanaged AI within organisations, presenting hackers with hidden pathways into networks.

Ultimately, the report found this has led to 87% of businesses being impacted by AI-powered cyberattacks, while 13% of organisations reported an incident involving an AI model or apps, a costly problem given that breaches involving AI added an average of $200,000 to incidents.

“Attackers aren’t just breaking in – they’re intent on stealing data to power extortion. By weaponising AI, they can outpace defenders at a new scale and use stealthy targeted techniques to slip past traditional security measures,” said Dr Darren Williams, CEO of BlackFog.

“Putting protections in place to close these gaps and prevent data exfiltration has to take priority as attackers focus on targeting organisations’ most sensitive information.”


Recommended reading


Technology has also opened the door to new threat actors. Of the 130 ransomware groups BlackFog tracked over 2025, fifty-two were new, a 9% increase compared to 2024. These fresh faces were responsible for 17% of all undisclosed ransomware, with the most active gangs together taking more than 300 victims.  

Still, those numbers were dwarfed by more established players. BlackFog found that well-known operators like Akira and Play were responsible for hundreds of attacks apiece, while ransomware giant Qilin surged ahead, claiming a total of 1,115 victims.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data