Ransomware activity continued its upward climb in the third quarter of 2025, according to cybersecurity firm BlackFog. The company’s Q3 2025 State of Ransomware Report shows a 36% year-over-year increase in ransomware attacks, marking five consecutive years of growth.
A total of 270 ransomware incidents were publicly disclosed between July and September, compared with 198 during the same period in 2024. July led the quarter with a 50% jump in attacks year-over-year. BlackFog noted that the actual number of incidents is far higher — estimating that 1,510 attacks went unreported, an increase of 21% from last year. Nearly 85% of all ransomware attacks remain undisclosed.
Healthcare was again the hardest-hit industry, accounting for 86 of the quarter’s reported attacks, which represents roughly one-third of all known incidents. Government and technology sectors followed with 28 each. When undisclosed activity is included, manufacturing took the top spot, making up 22% of hidden attacks, followed by the services and construction industries.
Law firms saw a notable increase, too, suffering 79 ransomware incidents, the highest number ever recorded for the sector. BlackFog’s researchers also identified 18 new ransomware groups in Q3, bringing the total number of active double-extortion groups to 80.
The Qilin ransomware group maintained its position as the most active operator, responsible for 20 disclosed and an estimated 242 undisclosed attacks. Other active groups included INC and Akira. A new group, Devman, quickly gained notoriety after launching 19 attacks across four continents and issuing the largest ransom demand of the year — $91 million — against China’s Shimao Group.
Data exfiltration remains almost universal among modern ransomware operations. BlackFog reports that 96% of all Q3 attacks involved data theft, with an average of 528 gigabytes of data stolen per victim.
“The fallout of cyberattacks has continued to have a long and lasting impact,” said Darren Williams, CEO of BlackFog. “The best option for organizations is to make it as hard as possible for cybercriminals to take advantage of them — protecting data so that they have no leverage for extortion and, critically, no incentive to return.”2025-Q3-State-of-Ransomware-Rep…
The report also highlighted the evolving nature of ransomware tactics, noting that many groups are now skipping encryption entirely in favor of data theft and extortion.




