In brief: Ransomware attacks increased by 236 percent in 2025, with new actors like Qilin and Akira taking the lead, and Germany ranking among the most affected countries worldwide with 433 cases.
The number of successful ransomware attacks increased by 236 percent in 2025, while overall cyber risk declined slightly. Germany ranks third globally with 433 documented cases, after the USA and Canada.
According to the TrendAI Cyber Risk Report 2026, the ten most active ransomware groups recorded a total of 5,096 confirmed victim organizations in 2025 — an increase of 236 percent compared to the previous year. The Cyber Risk Index itself declined on average to 35.8 points (2024: 38.5 points), but was subject to considerable fluctuations: from 34.6 points in January to 37.4 points in April and 34.1 points in July. Organizations of all sizes and sectors remain in the medium risk range.
Significant shifts marked the ransomware landscape: The Qilin group recorded an increase of 1,270 percent and now leads the ranking with 1,262 documented victims. The Akira group follows with 857 cases (increase: 708 percent). Five new groups — INC Ransom, SafePay, Lynx, DragonForce and Sinobi — established themselves in the top ten, while formerly leading actors such as LockBit lost significance. In 2025, Germany was the third most affected country globally with 433 ransomware attacks; only the USA (4,893 attacks) and Canada (520 cases) recorded more successful incidents.
By sector, elevated risks were evident: Mining led with an index value of 42.5, followed by healthcare and agriculture (40.3 points each), telecommunications (39.9 points), education (39.8 points), and government and public institutions (39.7 points). Particularly critical is the finding regarding micro-enterprises: although these have the lowest absolute risk overall, their risk class was the only one whose index increased — an indication that they are increasingly being exploited as entry points for supply chain attacks.
Primary entry points arise from insufficiently secured cloud applications and outdated or non-multi-factor-authenticated accounts in Microsoft Entra ID. For the first time, Zero Trust violations also rank among the five most common risk events. Unpatched security vulnerabilities represent the most common starting point with over 2.3 million identified attack paths, followed by password spraying and guessing attacks (over two million paths). Approximately 33,000 user accounts are targeted daily — nearly twice as frequently as physical endpoints.
For vulnerability management, it becomes clear that CVSS ratings alone are often insufficient: Three of the ten most frequently unpatched vulnerabilities had medium severity but, in combination with critical vulnerabilities, enabled complex attack chains. Virtual patching protected systems on average 115 days before official manufacturer updates.
Source: www.it-daily.net · Published July 14, 2026
Lumi AI News — AI-assisted curation according to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.