Several cybersecurity reports show ransomware activity rising, but they measure different things. Public victim claims and vendor datasets are up; the UK government’s survey found a lower share of businesses reporting ransomware. The evidence supports a qualified surge—not the claim that ransomware increased everywhere or by one consistent amount.
What the reports counted—and what they found
The figures below should be read as separate indicators, not combined into a single global rate. They cover different periods and populations, and some count public claims rather than independently confirmed attacks.
| Source | Period and geography | What was counted | Reported result |
|---|---|---|---|
| Black Kite, 2025 report | 2025; geography not stated in the cited figures | Victims in its dataset | 6,046 victims, a 24% year-over-year increase; 96 active groups |
| ThreatDown, 2025 report | July 2024–June 2025; geography not stated in the cited figures | Ransomware incidents in its reporting | 25% year-over-year increase; more than 1,000 incidents in February 2025 |
| NCC Group, 2026 report | 2025; reported as global | Ransomware attack volume | 50% increase during 2025. NCC Group called it a “record-breaking year for ransomware activity globally.” |
| GuidePoint Security GRIT, 2026 report | December 2025 compared with December 2024; geography not stated in the cited figures | Victims claimed publicly | 814 claimed victims in December 2025, up 42% year over year |
| UK Cyber Security Breaches Survey, 2026 | UK businesses; 2025/26 compared with the two preceding survey years | Share of surveyed businesses reporting ransomware | 1% in 2025/26, down from 3% in both 2024/25 and 2023/24 |
The survey result is not a contradiction of the public-claim figures: it estimates the proportion of a defined business sample reporting an incident, while the other reports count incidents, victims or claims gathered through different systems. Together, the reports show rising activity in several tracked datasets, alongside a decline in the UK survey’s measure.
Why ransomware reports disagree
“Ransomware attacks” can mean an organization reporting an incident, a victim named on a leak site, an insurance claim, or an event detected in a vendor’s telemetry. Those units are not interchangeable. Geography, reporting period, collection method and disclosure coverage also matter.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- World’s First 6TB 2.5” Portable Hard Drive
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- Surveys estimate the share of organizations in a sample that say they experienced ransomware. They depend on the sample, question wording and respondents’ awareness of incidents.
- Leak-site trackers and public-claim counts capture victims disclosed by extortion groups. They can miss victims who are not named publicly, and a claim is not the same as independent confirmation.
- Insurance analyses describe claims from an insurer’s policy population, not every organization or attack.
- Vendor telemetry reflects activity visible to that provider’s systems and customers; it is not a census of all attacks.
For that reason, a 50% increase in a report’s attack-volume measure cannot be directly compared with a 1% survey prevalence estimate or treated as a universal increase in confirmed victims. The useful question is what changed within each dataset over its stated period.
What may be contributing to the rise
The reports identify several risk indicators, but they do not establish that any single factor caused the increases across all datasets.
Rank #2
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
- A broader criminal ecosystem: Black Kite counted 96 active groups in its 2025 dataset. Its report also said 67% of breaches in that dataset involved third parties, pointing to supplier and partner exposure as a concern.
- Remote access: At-Bay’s 2026 report, based on 2025 data, found that 73% of ransomware attacks in its analysis began with a VPN.
- Faster exploitation: Check Point warns that the interval between vulnerability disclosure and exploitation is narrowing, increasing pressure to identify and patch exposed systems quickly.
- Automation and AI: In CrowdStrike’s survey of 1,100 security leaders, 76% said becoming fully prepared is getting harder; nearly half worried they could not detect or respond as quickly as AI-driven attacks execute.
ENISA’s 2026 Threat Landscape describes ransomware as “the most short-term impactful type of incident.” That assessment speaks to its impact, not to a single measured global growth rate.
Rising activity does not mean every victim pays
At-Bay’s 2026 report, using 2025 data, put the average ransom demand near $1 million and said 68% of cases in its analysis involved no payment. A demand is not the same as money received: the figure describes what attackers requested, not what victims paid on average.
Rank #3
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Separately, Check Point reported more than $820 million in on-chain ransomware payments during 2025. That is a payment-volume estimate based on on-chain activity; it is not a count of victims, attacks or total losses. These figures illustrate different parts of the economics and should not be conflated.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What organizations can do
No control guarantees that an organization will avoid ransomware. A layered program can reduce the chance of compromise and limit disruption if attackers get in.
Quick Recap
Best Value
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Rank #4
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
- Make recovery dependable. Keep offline or otherwise resilient backups, restrict attackers’ ability to alter them, and rehearse restoration so teams know how long recovery takes and what must be restored first.
- Protect identity and access. Use phishing-resistant multifactor authentication where available, secure administrator accounts, and review who can access sensitive systems.
- Harden VPN access. Apply strong authentication, remove unused accounts and access paths, monitor remote connections, and prioritize updates to VPN appliances.
- Patch exposed systems quickly. Maintain an inventory of internet-facing assets, track relevant vulnerability disclosures, and set a rapid process for assessing and applying security fixes.
- Practice detection and response. Test alerting, containment decisions, communications and incident-response plans; include suppliers and other third parties where their access could affect recovery.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

