Almost half of all the ransomware groups listing victims last year were new entrants to the ‘threatscape’, according to the latest research from Searchlight Cyber.
The cybersecurity firm’s new report, Same Game, New Players: Ransomware in 2025, found a grand total of 94 ransomware groups posting victims in 2024, a 38% increase on 2023, with 49 new groups observed operating, reflecting the fracturing and increasing complexity of the ransomware landscape.
According to Searchlight Cyber, the five most prolific ransomware groups of 2024 were RansomHub, LockBit, Play, Akira and Hunters International, representing a major change in the ecosystem, with only LockBit active for more than three years and RansomHub – the most prolific group of the year – emerging in February 2024.
Meanwhile, major groups such as BlackCat and Cl0p – ranked second and third respectively in 2023 – dropped out of the rankings altogether.
The report also outlines the impact of global law enforcement operations on these major ransomware actors. Most significantly, as a result of the EU and UK led Operation Cronos, LockBit saw its victim count in 2024 drop to 494, less than half that of 2023, sparking what the report calls a short-lived trend of an increasing number of splintered groups, but overall less victims.
Unfortunately, despite such actions, the victim counts rebounded over the second half of 2024, with last year seeing a total of 5,728 victims posted on data leak sites, an 11% increase from 2023, and new-player RansomHub becoming the top operator with 611 victims.
Although RansomHub may be appear to be a new entrant, the report points out that the group has ties to more established actors, including Knight, BlackCat, and LockBit, with this pedigree, combined with an ‘affiliate friendly’ Ransomware-as-a-Service (RaaS) model, going some way to explain how it has risen to prominence so quickly.
That model has allowed for smaller groups to take hold, with the report claiming that RansomHub’s RaaS offerings are increasing the capabilities of those lacking technical expertise, and creating more challenges for security teams in defending against a dynamic threat landscape.
One other notable change observed in the past year is the emergence of politically motivated groups, with hacktivist groups seen deploying ransomware as a new tactic, alongside the usual methods of phishing, defacement and wiper malware.
According to the report, this new trend blurs the lines between cybercrime and cyberwarfare, requiring organisations to consider another dimension in their threat assessments. Now, in addition to monitoring financially motivated actors, security teams may need to expand their list of adversaries to include those that might target them for ideological reasons.
Recommended reading
- ‘Big Game’ Ransomware Tactics Drives Spike in Attacks
- UK Proposes Ban on Public Sector Ransomware Payments
- Ransomware Payouts Plummet by £350M in 2024
“While we have observed disruption to some of the biggest ransomware groups, there has been an influx in smaller players, which creates challenges for security teams that are constantly trying to assess and prepare for emerging threats,” said Luke Donovan, head of threat intelligence at Searchlight Cyber.
“In this increasingly busy landscape, it becomes even more vital for organisations to actively apply threat intelligence to inform their defences.
“Firstly, to identify commonalities in how these groups operate and prepare for the most common attack techniques. Secondly, to help them narrow down their adversaries to the four or five groups they are most likely to face, based on their activity and victimology.”





