The rapidly evolving landscape of ransomware

Zscaler's new report unveils the latest ransomware trends, highlighting an increase in extortion over encryption, the targeting of key sectors, and the importance of Zero Trust.

Zscaler, Inc. recently unveiled its annual Zscaler ThreatLabz 2025 Ransomware Report, shedding light on evolving threats in the ransomware arena. The report zeroes in on the adapting nature of these attacks, offering insights into the sectors and regions most affected and providing actionable steps for fortifying defences.

An essential takeaway from ThreatLabz’s research is the significance of a Zero Trust Everywhere strategy to mitigate the risk of ransomware attacks. This comprehensive approach safeguards against lateral movement and protects valuable user data and applications, curbing potential damage.

“Ransomware tactics continue to evolve, with the growing shift toward extortion over encryption as a clear example," said Deepen Desai, EVP Cybersecurity, Zscaler. "GenAI is also increasingly becoming part of the ransomware threat actor's play book, enabling more targeted and efficient attacks. As threats advance, security measures must keep pace. The Zscaler Zero Trust Exchange™ platform empowers organisations to shrink their attack surface, identify and block initial compromise threats, prevent lateral movement, and stop data exfiltration to shut down extortion events before they happen."

Alarmingly, Zscaler observed a 146% surge year-over-year in thwarted attack attempts, underscoring a strategic pivot towards data theft. Significant is the 92% rise in stolen data volume by ten major groups, from 123 TB to 238 TB. Emphasis on data theft leads to increased pressure placed on victims through threats of data exposure.

Industries like Manufacturing, Technology, and Healthcare bear the brunt of ransomware strikes due to data sensitivity, potential for operational disruption and reputational damage alongside regulatory pressures. The Oil & Gas sector witnessing a dramatic 900% attack spike YoY due to increased automation of important infrastructure and lax security practices.

Geographical disparities are evident as the United States absorbs half of all ransomware assaults, outpacing countries like Canada (5%) and the United Kingdom (4%). With 3,671 reported attacks, double compared to last year, the U.S. dwarfs combined reports from the top 15 other targeted nations.

In terms of major players, groups like RansomHub, Akira, and Clop have significantly intensified their activities, with RansomHub alone accounting for 833 identified victims. 34 new ransomware families were dectect in the last year bringing the number that ThreatLabz has tracks to 435

In aiming to dismantle ransomware threats, the Zscaler Zero Trust Exchange employs a cloud-native, AI-driven strategy to thwart attacks. It ensures minimised attack surfaces, prevents initial compromises, curbs lateral movement, and blocks data exfiltration. Additional advanced AI-based protections like breach prediction, phishing detection, and dynamic, risk-based policies complete this robust defence paradigm.

GCX appoints Luca Simonelli to enhance global partnerships and lead operations in Italy, amid...
SolarWinds report suggests IT leaders underestimate the impact of broken processes and limited...
Leostream introduces a secure solution for external stakeholders, ensuring safe and efficient...
BOXX Insurance is set to join Zurich Insurance Group, continuing its mission in cyber insurance and...
Palo Alto Networks enhances its AI security portfolio by acquiring Protect AI, aiming to secure the...
Orange Cyberdefense strengthens its presence in Switzerland by acquiring Zurich-based cybersecurity...
Commvault plans to acquire Satori Cyber Ltd to bolster its data security and AI governance...
Survey data reveals AI's role as an assistive tool in cybersecurity, highlighting potential areas...