Threat intelligence report

Ransomware Threats. 2025 Report.

The ransomware landscape has shifted. Attackers now treat backup infrastructure as a primary target. This report covers the threats, trends, and techniques defining 2025.

$57B
Projected damages by end of 2025
65%
of financial orgs hit in 2024
84%
of boards discuss ransomware quarterly
Get the full report

We respect your privacy. No spam. Unsubscribe anytime.

Key Findings

The numbers behind 2025's threat landscape.

Elastio threat research telemetry and industry data, covering backup-targeting ransomware trends.

143%
YoY increase in ransomware targeting backup infrastructure
17 days
Average dwell time before ransomware detonation in backups
68%
Of organizations hit by ransomware had compromised backup copies
$4.7M
Average recovery cost when backups are compromised

Threat Actor Profiles

Most active groups in 2025.

Ransomware groups actively targeting backup infrastructure this year.

GroupVariantSectorsFirst SeenSeverity
LockBit 4.0LockBit Black, LockBit GreenHealthcare, Financial Services, ManufacturingQ1 2025critical
BlackSuitRoyal rebrandCritical Infrastructure, Government, EducationQ4 2024critical
AkiraAkira_v2Small & Mid-size Enterprises, Professional ServicesMajor 2025 varianthigh
MedusaMedusaLocker 2025Healthcare, Legal, Financial ServicesQ2 2025critical
RansomHubRaaS CollectiveCross-sector, Managed Service ProvidersQ1 2025high

2025 Threat Trends

Defining shifts this year.

The techniques and patterns that security teams need to address now.

AI-Accelerated Ransomware Development
critical

Threat actors are using large language models to rapidly generate polymorphic ransomware variants, reducing the development cycle from months to days and evading signature-based detection.

Backup Infrastructure as Primary Target
critical

Over 70% of ransomware attacks in 2025 explicitly target backup systems before encrypting production data, making backup integrity validation an essential security control.

Supply Chain Backup Compromise
critical

Attackers are compromising backup software vendors and MSP management platforms to gain access to thousands of downstream backup environments simultaneously.

Time-Delayed Payload Injection
high

Ransomware increasingly uses dormancy periods of 14 to 45 days, silently corrupting backup snapshots across retention windows before triggering visible encryption.

Cloud-Native Snapshot Manipulation
high

New attack techniques exploit cloud IAM misconfigurations to modify or delete EBS snapshots, S3 Object Lock policies, and cross-region replication targets.

Regulatory Pressure on Recovery Proof
medium

DORA, SEC disclosure rules, and NYDFS 500 amendments now require organizations to demonstrate provable recovery capability, not just backup existence.

Quarterly Timeline

Major incidents and milestones across 2025.

Key events shaping the ransomware threat landscape, quarter by quarter.

Threat
Breach
Advisory
Regulatory
Q1
2025
Threat

LockBit 4.0 variant emerges with enhanced backup-targeting capabilities

Breach

Major healthcare breach via compromised Veeam backup admin credentials

Advisory

CISA issues advisory on ransomware targeting immutable storage platforms

Q2
2025
Breach

Medusa triple-extortion campaign hits 200+ organizations globally

Threat

First documented attack using AI-generated polymorphic ransomware payload

Regulatory

SEC fines three public companies for inadequate recovery capability disclosure

Q3
2025
Threat

RansomHub RaaS platform surpasses 1,000 affiliates

Breach

Supply chain attack compromises popular MSP backup management tool

Advisory

NIST releases updated Ransomware Risk Management framework (SP 1800-26 Rev.2)

Q4
2025
Breach

BlackSuit targets critical infrastructure across 12 countries simultaneously

Threat

Cloud-native snapshot manipulation attacks increase 280% QoQ

Regulatory

DORA enforcement begins with first compliance penalties in EU financial sector

Elastio

Are your backups prepared
for 2025's threats?

The Hunt Engine detects ransomware inside your data before you need to recover.