The rapidly evolving landscape of ransomware

Zscaler's new report unveils the latest ransomware trends, highlighting an increase in extortion over encryption, the targeting of key sectors, and the importance of Zero Trust.

Zscaler, Inc. recently unveiled its annual Zscaler ThreatLabz 2025 Ransomware Report, shedding light on evolving threats in the ransomware arena. The report zeroes in on the adapting nature of these attacks, offering insights into the sectors and regions most affected and providing actionable steps for fortifying defences.

An essential takeaway from ThreatLabz’s research is the significance of a Zero Trust Everywhere strategy to mitigate the risk of ransomware attacks. This comprehensive approach safeguards against lateral movement and protects valuable user data and applications, curbing potential damage.

“Ransomware tactics continue to evolve, with the growing shift toward extortion over encryption as a clear example," said Deepen Desai, EVP Cybersecurity, Zscaler. "GenAI is also increasingly becoming part of the ransomware threat actor's play book, enabling more targeted and efficient attacks. As threats advance, security measures must keep pace. The Zscaler Zero Trust Exchange™ platform empowers organisations to shrink their attack surface, identify and block initial compromise threats, prevent lateral movement, and stop data exfiltration to shut down extortion events before they happen."

Alarmingly, Zscaler observed a 146% surge year-over-year in thwarted attack attempts, underscoring a strategic pivot towards data theft. Significant is the 92% rise in stolen data volume by ten major groups, from 123 TB to 238 TB. Emphasis on data theft leads to increased pressure placed on victims through threats of data exposure.

Industries like Manufacturing, Technology, and Healthcare bear the brunt of ransomware strikes due to data sensitivity, potential for operational disruption and reputational damage alongside regulatory pressures. The Oil & Gas sector witnessing a dramatic 900% attack spike YoY due to increased automation of important infrastructure and lax security practices.

Geographical disparities are evident as the United States absorbs half of all ransomware assaults, outpacing countries like Canada (5%) and the United Kingdom (4%). With 3,671 reported attacks, double compared to last year, the U.S. dwarfs combined reports from the top 15 other targeted nations.

In terms of major players, groups like RansomHub, Akira, and Clop have significantly intensified their activities, with RansomHub alone accounting for 833 identified victims. 34 new ransomware families were dectect in the last year bringing the number that ThreatLabz has tracks to 435

In aiming to dismantle ransomware threats, the Zscaler Zero Trust Exchange employs a cloud-native, AI-driven strategy to thwart attacks. It ensures minimised attack surfaces, prevents initial compromises, curbs lateral movement, and blocks data exfiltration. Additional advanced AI-based protections like breach prediction, phishing detection, and dynamic, risk-based policies complete this robust defence paradigm.

Proton has launched Proton Workspace, a suite of business productivity tools, alongside Proton...
New research highlights the financial impact of OT downtime in UK critical infrastructure,...
Kubus has been appointed a Diamond Partner by Verkada, joining a select group within the vendor’s...
HPE has introduced new security innovations designed to help organizations scale distributed...
Node4 has launched an AI-driven Financial Operations (FinOps) solution designed to help UK...
Smart Communications announces Satish Shenoy as Senior VP to enhance global partner strategy and...
Motive launches an integrated AI analytics platform designed to transform decision-making and...
F5 has introduced new threat intelligence resources designed to support assessment of AI model...