KELA

42 STATS5 REPORTS

All Statistics

In 2025, 70.4% of ransomware attacks, totaling 3,310 incidents, were distributed across other regions.

Ransomware

In 2025, five countries accounted for 1,391 ransomware events, representing nearly 30% of all recorded ransomware attacks.

Ransomware

In 2025, Germany experienced 102 ransomware incidents, representing 2.2% of all attacks.

RansomwareGermany

In 2025, 50% of all ransomware attacks are projected to target critical infrastructure, highlighting the urgent need for enhanced cyber resilience strategies.

Ransomwarecritical infrastructure

Manufacturing has been the #1 targeted industry for ransomware attacks for four consecutive years, according to the IBM X-Force 2025 Threat Intelligence Index.

Ransomwaremanufacturing

In 2025, 5.9% of ransomware attacks were attributed to Qilin, 5.9% to Clop, 5.0% to Akira, 2.9% to Play, and 2.7% to SafePay.

RansomwareRansomware groups

Between January and September 2025, KELA observed 4,701 ransomware incidents, representing a 34% year-over-year increase compared to the same period in 2024.

Ransomware

In 2025, ransomware events against critical industries increased by 34% compared to the previous year.

Ransomwarecritical industries

The top five ransomware groups — Qilin, Clop, Akira, Play, and SafePay — were responsible for 938 incidents, accounting for nearly 25% of all ransomware attacks in 2025.

RansomwareRansomware groups

In 2025, there were 103 distinct ransomware threat actors observed targeting critical infrastructure.

RansomwareRansomware groups

Out of 103 active ransomware groups, five groups accounted for nearly 25% of global ransomware incidents.

RansomwareRansomware groups

In 2025, 2,332 ransomware incidents targeted critical infrastructure, accounting for 50% of all incidents, compared to 1,745 incidents, which accounted for 54%, in 2024.

RansomwareCritical infrastructure

Qilin was responsible for 248 incidents, Clop for 246 incidents, Akira for 209 incidents, Play for 120 incidents, and SafePay for 115 incidents in 2025.

RansomwareRansomware groups

From January 1 to September 1, 2025, there were 4,701 recorded ransomware incidents, with 2,332 incidents (50%) targeting critical sectors such as manufacturing, healthcare, energy, transportation, and financial services.

Ransomwarecritical infrastructuremanufacturing

From January 1 to September 1, 2024, there were 3,219 total recorded ransomware incidents, with 1,745 incidents (54%) targeting critical sectors.

Ransomwarecritical infrastructure

Ransomware attacks against the manufacturing sector surged from 520 incidents in 2024 to 838 incidents in 2025, marking a 61% increase.

Ransomwaremanufacturing

In 2025, Italy experienced 74 ransomware incidents, representing 1.6% of all attacks.

RansomwareItalyGeography

In 2025, 77.7% of ransomware attacks were attributed to other actors outside the top five groups.

RansomwareRansomware groups

In 2025, the United States experienced 21.3% of all ransomware attacks, totaling approximately 1,000 incidents.

RansomwareUnited States

In 2025, Canada experienced 139 ransomware incidents, accounting for 3.0% of all attacks.

RansomwareGeographyCanada

In 2025, half of all ransomware attacks worldwide targeted essential sectors such as manufacturing, healthcare, energy, transportation, and finance, indicating a shift from opportunistic crime to systemic disruption.

Ransomware

Ransomware attacks in the manufacturing sector surged by 61% from 520 incidents to 838 incidents year-over-year, marking the steepest growth among all sectors.

Ransomwaremanufacturing

In 2025, the United States accounted for roughly 1,000 ransomware incidents targeting critical infrastructure, representing 21% of all global ransomware attacks.

RansomwareGeographycritical infrastructure

In 2025, the United Kingdom experienced 76 ransomware incidents, accounting for 1.6% of all attacks.

RansomwareUK

Both infostealer infections and compromised credentials are on track to surpass 2024 figures, which saw over 4.3 million machines infected with approximately 330 million compromised credentials. This indicates a 24% increase YoY in these areas.

InfostealerCompromised credentials

3,662 ransomware victims were tracked globally by KELA in the first half of 2025. This represents a 54% increase year-over-year (YoY) compared to the first half of 2024, as KELA tracked a total of 5,230 victims in all of 2024.

Ransomware

The United States accounted for over half of all ransomware victims in H1 2025.

RansomwareUS

Clop ransomware experienced a 2,300% increase in victim claims, which was driven by the exploitation of a vulnerability in Cleo software.

RansomwareClop

2.67 million machines were infected by infostealer malware in H1 2025. This led to more than 204 million compromised credentials being observed.

InfostealerCompromised credentials

Among the roles most vulnerable to credential theft, 28% were in Project Management, followed by Consulting (12%) and Software Development (10.7%).

CredentialsCredential theft

Credentials for victims of the Play, Akira, and Rhysida ransomware groups were found on cybercrime marketplaces between 5 and 95 days prior to the reported attack.

CredentialsCredential theftRansomwareThreat group

Infostealer activity has surged by 266% in recent years.

Infostealer

The average time between credentials being found and the reported ransomware attack was 2.5 weeks

CredentialsCredential theftRansomware

KELA's platform recorded a 200% increase in mentions of malicious AI tools and tactics in 2024.

AI

There was a 52% increase in discussions related to jailbreaking methods on cybercrime forums in 2024 compared to the previous year.

Jailbreaking

KELA found a 200% surge in cybercriminals seeking AI to launch attacks.

AICyber attack

KELA found a 200% surge in cybercriminals seeking AI to launch attacks.

AICyber attack

Over 330 million compromised credentials were linked to infostealer malware.

The top three infostealer malware strains (Lumma, StealC, and RedLine) were responsible for over 75% of infected machines.

3.9 billion credentials were shared in the form of credentials lists (ULP files).

Over 200 new hacktivist groups emerged, conducting more than 3,500 distributed denial-of-service (DDoS) attacks

3.9 billion credentials were shared in the form of credentials lists (ULP files).