The rapidly evolving landscape of ransomware

Zscaler's new report unveils the latest ransomware trends, highlighting an increase in extortion over encryption, the targeting of key sectors, and the importance of Zero Trust.

Zscaler, Inc. recently unveiled its annual Zscaler ThreatLabz 2025 Ransomware Report, shedding light on evolving threats in the ransomware arena. The report zeroes in on the adapting nature of these attacks, offering insights into the sectors and regions most affected and providing actionable steps for fortifying defences.

An essential takeaway from ThreatLabz’s research is the significance of a Zero Trust Everywhere strategy to mitigate the risk of ransomware attacks. This comprehensive approach safeguards against lateral movement and protects valuable user data and applications, curbing potential damage.

“Ransomware tactics continue to evolve, with the growing shift toward extortion over encryption as a clear example," said Deepen Desai, EVP Cybersecurity, Zscaler. "GenAI is also increasingly becoming part of the ransomware threat actor's play book, enabling more targeted and efficient attacks. As threats advance, security measures must keep pace. The Zscaler Zero Trust Exchange™ platform empowers organisations to shrink their attack surface, identify and block initial compromise threats, prevent lateral movement, and stop data exfiltration to shut down extortion events before they happen."

Alarmingly, Zscaler observed a 146% surge year-over-year in thwarted attack attempts, underscoring a strategic pivot towards data theft. Significant is the 92% rise in stolen data volume by ten major groups, from 123 TB to 238 TB. Emphasis on data theft leads to increased pressure placed on victims through threats of data exposure.

Industries like Manufacturing, Technology, and Healthcare bear the brunt of ransomware strikes due to data sensitivity, potential for operational disruption and reputational damage alongside regulatory pressures. The Oil & Gas sector witnessing a dramatic 900% attack spike YoY due to increased automation of important infrastructure and lax security practices.

Geographical disparities are evident as the United States absorbs half of all ransomware assaults, outpacing countries like Canada (5%) and the United Kingdom (4%). With 3,671 reported attacks, double compared to last year, the U.S. dwarfs combined reports from the top 15 other targeted nations.

In terms of major players, groups like RansomHub, Akira, and Clop have significantly intensified their activities, with RansomHub alone accounting for 833 identified victims. 34 new ransomware families were dectect in the last year bringing the number that ThreatLabz has tracks to 435

In aiming to dismantle ransomware threats, the Zscaler Zero Trust Exchange employs a cloud-native, AI-driven strategy to thwart attacks. It ensures minimised attack surfaces, prevents initial compromises, curbs lateral movement, and blocks data exfiltration. Additional advanced AI-based protections like breach prediction, phishing detection, and dynamic, risk-based policies complete this robust defence paradigm.

NAKIVO's latest update brings multilingual support and enhanced disaster recovery capabilities.
Discover how Precisely's latest updates integrate master data management with data governance to...
Almaviva partners with OVHcloud to enhance compliant and sovereign digital solutions across...
11:11 Systems unveils research revealing IT leaders' overconfidence amidst cyber threats, with...
Rebranding to Hammer Distribution, the company renews its commitment to distinguished service and...
Lenovo unveils GPU Advanced Services to help companies enhance workload performance and streamline...
Virgin Media O2 launches Scam School to help over-65s navigate digital risks and enhance online...
Horizon3.ai celebrated partner excellence at the EMEA Partner Conference, showcasing advancements...