ReliaQuest

82 stats7 reports

All Statistics

The Gentlemen surged 588% quarter-over-quarter to 179 posts in Q1.

RansomwareThreat ActorsThe GentlemenActor Activity

The Gentlemen posted 101 victims in April, 77 in May, and 122 in June.

RansomwareActor ActivityThe Gentlemen

Deadlock emerged in June 2026 with 75 named victims in a single month.

RansomwareThreat ActorsDeadlock

The quickest data exfiltration attack in 2025 took just 6 minutes versus over 4 hours in 2024.

Data Exfiltration

80% of ransomware groups use AI, automation, or both in their attacks.

RansomwareAI in CybercrimeAutomation

BoaLoader malware is a factor in nearly 20% of incidents observed in the calendar year.

MalwareBoaLoader

44% of true-positive security alerts from cloud security tools in Q3 2025 were driven by identity-related weaknesses.

Cloud SecurityIdentity ManagementSecurity alerts

52% of all confirmed identity-based alerts were due to identity-related privilege escalation.

Cloud SecurityIdentity Management

99% of cloud identities were found to be over-privileged, creating significant security risks.

Cloud SecurityIdentity Management

Akira has already listed 15% more victims in the first half of 2025 than it did throughout the entirety of 2024.

RansomwareAkira

Retail trade accounted for only 4% of total ransomware victims in Q2 2025.

RansomwareRetail

The US remained the most targeted country by ransomware, accounting for 67% of the total organizations named on ransomware data-leak sites in Q2.

RansomwareUSData leak site

Two-thirds of critical hands-on-keyboard incidents involved legitimate software like remote access tools last year.

ReliaQuestAnnual Cyber-Threat Report·1y ago

Compromised service accounts were present in 85% of breaches last year.

ReliaQuestAnnual Cyber-Threat Report·1y ago

80% of ransomware attacks in the last year focused on data exfiltration only.

ReliaQuestAnnual Cyber-Threat Report·1y ago

The mean time to contain (MTTC) attacks using manual incident containment strategies is 8 hours and 12 minutes.

"Akira" more than doubled its Q3 count and listed 71 organisations on data-leak sites in December alone.

LockBit's victim count decreased from 176 in May 2024 to only five in December.

Roughly 20% of the domains registered by Scattered Spider imitated Gateway and Network Infrastructure.

The average breakout time in 2024 was 48 minutes, which is 22% faster than in 2023.

66% of customer ransomware incidents in 2024 involved initial access likely purchased from an IAB.

Deadlock was absent from public data-leak sites for 11 months before emerging publicly.

RansomwareThreat ActorsDeadlockData Leak Site

Qilin fell from 111 data leak posts in April to 79 in June, a 29% decrease.

RansomwareThreat ActorsQilin

The top 11 tracked ransomware groups accounted for 1,368 victim claims across 99 countries in Q2.

RansomwareThreat IntelligenceThreat Actors

Ransomware attacks spread across 90 ransomware groups and 99 countries.

Ransomware

Ransomware groups posted 2,252 victims in Q2, down 15% from Q1 and up about 51% year over year.

Ransomware

The Gentlemen posted 300 victims in Q2, edging out Qilin with 289 victims.

RansomwareThreat ActorsThe Gentlemen

DragonForce dropped from 65 data leak posts to 27 posts, a 58% decrease.

RansomwareThreat ActorsDragonForce

Coinbase Cartel collapsed from 45 data leak posts to 4 posts, a 91% decrease.

RansomwareThreat ActorsCoinbase Cartel

PSTS led sector targeting for the fifth consecutive quarter.

RansomwareThreat ActorsPSTS

The US absorbed 1,094 ransomware victim data leak posts in Q2, roughly 49% of observed activity and nine times the volume of the next country.

USRansomwareData Leak Site

Professional, Scientific, and Technical Services (PSTS) recorded 437 ransomware victim posts across the top 11 groups and accounted for 32% of tracked activity.

RansomwarePSTSSector Risk

Threat actors utilizing AI and automation tools can achieve lateral movement within an organization in as little as 4 minutes, 85% faster than the previous year.

Lateral MovementAI in CybercrimeAutomation

On average, lateral movement within an organization takes 34 minutes, 29% quicker than the 48 minutes recorded in 2024.

Lateral MovementThreat Actor Tactics

Organizations leveraging AI and automation can contain threats within 4 minutes versus up to 16 hours with manual efforts.

Incident ResponseAI SecurityThreat Containment

33% of raw CSPM alerts were identity-related, contributing to the operational burden on security teams.

Cloud SecurityIdentity ManagementCSPM

As of October 2025, there are over 14,700 Jenkins servers exposed to the internet that remain vulnerable to CVE-2024-23897.

VulnerabilitiesCloud Security

71% of critical vulnerability alerts in Q3 2025 originated from just four legacy CVEs.

VulnerabilitiesCloud SecurityCVEs

Germany rose to second most targeted country by ransomware in Q2 2025, climbing two spots from fourth in Q1 2025.

RansomwareGermany

Spain and other Spanish-speaking countries each accounted for less than 4% of Qilin's total victim volume in Q2.

RansomwareQilinSpain

DragonForce emergence: December 2023.

RansomwareDragonForce

DragonForce activity was up 119% between Q1 and Q2 2025.

RansomwareDragonForce

Lynx experienced a 41% drop in activity between Q1 and Q2 2025.

RansomwareLynx

80% of the organizations named by Qilin in Q2 were based in the US.

RansomwareQilin

In Q1 2025, Clop named 389 victims on its data-leak site in February alone.

RansomwareClop

Qilin showed an 80% increase in activity in Q2 compared to Q1 2025.

RansomwareQilin

SafePay's activity increased by 42% in Q2 2025 compared to Q1 2025.

RansomwareSafePay

LockBit named just 24 organizations on its data-leak site in Q2 2025. This figure represents only 11% of its Q2 2024 victim count.

RansomwareLockBit

Q2 2025 saw a 31% decrease in named ransomware victims compared to the previous quarter, marking a return to more typical levels.

Ransomware

Akira listed approximately 130 organizations to its data-leak site each quarter in 2025.

RansomwareAkira