The number of active ransomware groups reached an all-time high in the second half of 2025, according to new figures from Searchlight Cyber, with ransomware groups listing a record 7,458 victims on dark web leak sites.
The cyber firm’s latest report, Ransomware’s Record Year: Tracking a Volatile Landscape in H2 2025, found that victim numbers jumped 30% last year, more than twice 2024’s rate, evidence that the “velocity of victimisation” is accelerating.
Searchlight researchers identified a record 93 active ransomware groups in H2’25, with new players flooding the dark web as a more complex and fragmented threat landscape emerges.
According to the report, 2025 saw 124 active groups in total, more than any previous year recorded. More than seventy new ransomware operators were identified throughout the year, with thirty-eight appearing over H2 alone.
One of these, Sinobi, surged into the top ranking ransomware operators within months of its debut, utilising a Ransomware-as-a-Service (RaaS) structure to claim 180 victims.
“2025 was a record year for ransomware, driven by a professionalised ecosystem that remains devastatingly effective despite increased pressure from global law enforcement,” said Luke Donovan, head of threat intelligence at Searchlight Cyber.
“The landscape continues to fragment; large monolithic syndicates are fracturing into smaller, agile cells, and with the number of active groups at an all-time high, the threat landscape has become more complex and difficult to track than ever before.”
But while newcomers looked to gain a foothold by using AI to automate malware development and conduct hyper-personalised social engineering, veteran crews pushed their attacks further than ever.
Among the most prolific ransomware groups by victim count over H2’25 were Akira (384 victims), IncRansom (213), and Play (164), but it was Qilin that dominated the scene with a staggering 420% year-over-year increase in victims, hitting 697 organisations.
Recommended reading
- Data Theft Surges to 96% of Ransomware Attacks
- Comment | The History of Ransomware
- UK Firms Warned to Prepare Now for Russian DoS Attacks
Qilin’s coalition with the Dragonforce and LockBit was also evidence of a developing trend in the emergence of ransomware “supergroups”, with Searchlight tracking the formation of high-profile collaborations, such as Scattered Lapsus$ Hunters, where threat actors pool their talents to scale operations.
To stay ahead of these creative new threats, the report emphasises the need for preemptive defence, including methods to combat the Initial Access Broker (IAB) ecosystem and identify sensitive data in third-party ransomware leak files before an attack is deployed.
“In the high-stakes game of ransomware in 2026, the only way to truly win is to ensure you aren’t an eligible target in the first place,” said Donovan. “Organisations must adopt a preemptive strategy, maintaining visibility and mitigating exposures to neutralise threats before they escalate into full-blown attacks.”





