2 Sources
[1]
Kaspersky Releases 2025 Ransomware Report Ahead of Anti-Ransomware Day
The Commonwealth of Independent States sees a smaller share of users encountering ransomware attacks. However, hacktivist groups such as Head Mare, Twelve and others active in the region often use ransomware such as LockBit 3.0 to inflict damage on target organizations. Manufacturing, government
[2]
Kaspersky State of Ransomware Report-2025: Global and Regional Insights for International Anti-Ransomware Day
With International Anti-Ransomware Day approaching on May 12, Kaspersky presents its annual report on the evolving global and regional ransomware cyberthreat landscape. The purpose of Anti-Ransomware Day is to raise global awareness about the threats posed by ransomware and to promote best
Share
Copy Link
Kaspersky's latest report highlights the evolving ransomware landscape, including the rise of AI-powered attacks, regional vulnerabilities, and emerging trends in cybercrime tactics.

Kaspersky's 2025 Ransomware Report, released ahead of International Anti-Ransomware Day on May 12, provides crucial insights into the evolving cyberthreat landscape. The report reveals that the share of users affected by ransomware attacks globally increased by 0.1% from 2023 to 2024
1
. While this percentage may seem small, it reflects the targeted nature of ransomware attacks, which often focus on high-value targets rather than mass distribution.The Middle East, Asia-Pacific (APAC), and African regions lead in the share of users attacked by ransomware, followed by Latin America, the Commonwealth of Independent States (CIS), and Europe
2
. This distribution is attributed to varying levels of digital transformation, cybersecurity maturity, and economic factors across regions.In APAC, rapid digital transformation and expanding attack surfaces have made enterprises prime targets, particularly in countries with growing economies and new data privacy laws
2
. Africa, despite lower overall digitization, is seeing an increase in ransomware attacks, especially in South Africa and Nigeria, targeting manufacturing, financial, and government sectors2
.The report highlights the increasing use of AI tools in ransomware development. A notable example is FunkSec, a ransomware group that emerged in late 2024 and quickly gained notoriety
1
. FunkSec's operations showcase:The RaaS model continues to dominate the ransomware landscape, lowering the technical barrier for cybercriminals
1
. In 2024, platforms like RansomHub thrived by offering malware, technical support, and affiliate programs, enabling less-skilled actors to execute sophisticated attacks1
.Related Stories
Looking ahead to 2025, Kaspersky anticipates several developments in ransomware tactics:
2
2
2
2
The CIS region sees a smaller share of ransomware attacks, but faces threats from hacktivist groups like Head Mare and Twelve, which often use ransomware such as LockBit 3.0
1
. Manufacturing, government, and retail sectors are the most targeted in this region1
.Europe, while consistently targeted, benefits from robust cybersecurity frameworks and regulations that deter some attackers
1
. Sectors such as manufacturing, agriculture, and education are often targeted, but mature incident response and awareness limit the scale of attacks1
.As ransomware threats continue to evolve, the report underscores the importance of global awareness and the implementation of best practices for prevention and response across all regions and sectors.
Summarized by
Navi
31 Jul 2024

08 Oct 2024•Technology

15 Oct 2024•Technology

1
Technology

2
Technology

3
Science and Research
