Ransomware activity surged sharply in 2025, highlighting how cyber risk is becoming a persistent operational threat rather than a sporadic crisis. According to newly released NordStellar data, 9,251 ransomware cases were recorded on dark web monitoring channels last year, up 45% from 6,395 incidents in 2024. The growth was not confined to a single spike or campaign, but reflected steady escalation across the year, culminating in a pronounced surge in the final quarter.
Smaller Organizations and Industry Become Prime Targets
One of the clearest shifts in the 2025 data is the concentration of attacks on small and medium-sized businesses. Companies with up to 200 employees and annual revenues below $25 million experienced the highest volume of ransomware incidents, reflecting attackers’ growing focus on organizations with limited security resources and less mature incident response capabilities.
Manufacturing remained the most targeted sector, with 1,156 recorded ransomware incidents in 2025, a 32% increase year over year. These attacks accounted for 19.3% of all reported cases, edging slightly higher than in 2024. Other heavily affected sectors included IT services, which saw 524 incidents (up 35%), professional, scientific, and technical services with 494 cases (up 30%), and construction, which recorded 443 incidents, a 24% increase.
Within manufacturing, exposure was not uniform. Machinery and industrial equipment producers were frequently targeted, a pattern Noreika links to expanding digitalization and remote connectivity across production environments. Appliance and electronics manufacturers also faced elevated risk, driven by complex supplier integration and increasing reliance on cloud-based systems to coordinate design, sourcing, and production workflows.
Geography and Criminal Scale Are Expanding in Parallel
Geographically, the United States remained the primary target, accounting for 3,255 ransomware cases in 2025, a 28% increase from the previous year and nearly two-thirds of all recorded incidents. Canada followed with 352 cases, up 46%, while Germany saw one of the sharpest increases, with incidents nearly doubling to 270. The United Kingdom recorded 233 cases, a modest 2% rise, and France logged 155 incidents, up 46%.
At the same time, the ransomware ecosystem itself is becoming more crowded. NordStellar traced 2025 incidents to 134 distinct ransomware groups, a 30% increase from the 103 groups identified in 2024. This expansion points to lower barriers to entry and greater specialization within the criminal landscape, with newer groups rapidly adopting established tools, infrastructure, and extortion tactics.
The pace intensified late in the year. Ransomware cases peaked in the fourth quarter of 2025, with 2,910 incidents recorded, a 38% increase compared with the same period in 2024 and nearly 50% higher than the July–September quarter. December alone set a two-year monthly record, with 1,004 incidents logged.
When Ransomware Becomes a Continuity Issue
One consequence that is easy to overlook in rising ransomware volumes is how quickly cyber risk migrates into operational dependency risk. As recent industry advisories and insurance disclosures show, attackers increasingly time intrusions around maintenance windows, production slowdowns, and holiday staffing gaps, not just software vulnerabilities. That pattern suggests that resilience is now shaped as much by workforce coverage, supplier access controls, and operational visibility as by perimeter defenses. Organizations that treat ransomware strictly as a technical threat may harden systems yet remain exposed through process handoffs, remote access privileges, or lightly governed third parties that sit directly inside daily operations.