S-RM’s annual Cyber Incident Insights Report, analysing 800 incidents globally, finds 24% of ransomware victims ended up paying out in 2025.
This figure reflects a significant increase from just 14% in 2024, and creeps closer to the peak of 2022, when 27.6% of ransom requests were settled.
Ransomware remains the biggest threat to organisations, the report found, but the ecosystem is changing.
The Threat Landscape
The US continues to be at most risk of cyber-attacks, accounting for 60% of incidents, with Asia-Pacific also seeing an increase in attacks. Over 760 organisations across the Asia-Pacific region were named on ransomware leak sites, a 59% increase on the previous year. Despite this, researchers expect the US to remain the most targeted country due to its scale and regulatory environment.
The UK itself saw a 5% increase in cyber-victims from 2024 to 2025.
In 2025, organisations encountered 67 different threat actors, an increase of 16% from the previous year. The average ransom paid was $296,000, with S-RM’s highest recorded payment totalling an eye-watering $1,900,000.
“We are moving into uncharted territory where the speed and sophistication of cyber-attacks are out manoeuvring traditional defenses. What once took weeks now takes days, and what took days, now takes hours” Jamie Smith, Global Managing Director, Cyber Security at S-RM commented.
“Threats are becoming specific and more personalised, designed to maximise the victim’s fear and willingness to pay.”
Highly established groups such as Akira and Qilin remain the biggest threat to organisations, accounting for 45% of cyber-incidents.
Despite their prevalence, there is a level of understanding and familiarity which comes from facing these established groups. The emergence of new threat actors could be more of a cause for concern due to their vastly varying degrees of effectiveness and sophistication, the report posits.
Organisational Preparedness & Weak Spots
Organisations are becoming savvy to data decryption, with 88% of affected organisations having backups in place. This has created a shift wherein data exfiltration has become the default for threat actors, occurring in 80% of cases, enabling them to ‘double-extort’ their victims.
While organisations are able to access their backed up data, ransomware gangs are able to exploit the exfiltrated data for ransom to prevent them from selling the data for a higher price or leveraging the data for further attacks.
Gaps in basic cyber hygiene are leaving organisations exposed. Only 22% of victim organisations had rolled out and actively monitored endpoint detection and response (EDR) across their estate and 47% of business email compromise (BEC) victims had not enforced multi-factor authentication (MFA) in their M365 environment.
Recommended reading
- Data Theft Surges to 96% of Ransomware Attacks
- Comment | The History of Ransomware
- Ransomware “Supergroups” Emerge After Record‑Breaking Year of Attacks
VPNs are also reported to be creating significant vulnerabilities in systems, with 68% of ransomware cases targeting VPN devices as their source of entry.
In BEC cases, credential phishing remains by far the most common method of entry, accounting for 80% of cases where method of entry was confirmed. Robust implementation, configuration, training and active monitoring is key to safeguarding.
Single-factor remote access solutions (39%) and vulnerabilities in public-facing infrastructure (27.6%) remained the top methods of entry amongst ransomware threat groups in 2025. Whilst in 16% of cases the source remained unconfirmed 2025, this a decrease from 27.3% in 2024 suggesting an improvement in organisations’ and defense teams’ abilities to identify routes in.
The sectors reporting the most cases were financial services (12.7%), professional services (11.7%), construction and real estate (10.9%), healthcare services (9.6%), and industrials and manufacturing (9.2%). Perceived wealth, volume of datasets, and the potential to cause disruption were cited as the main reasons certain industries were targeted over others.
Jenny Davey, Global Co-Head of FGS Global’s Crisis & Issues Management Practice, commented: “In today’s complex and rapidly evolving environment, organisations who treat security posture, operational resilience and stakeholder engagement as one, with a holistic, agile and tested approach, will fare better and maintain trust when they’re hit with the inevitable”.





