ReliaQuest

62 STATS5 REPORTS

All Statistics

44% of true-positive security alerts from cloud security tools in Q3 2025 were driven by identity-related weaknesses.

ReliaQuestToo Much Trust: The Danger of Over-Privileged Cloud Identities ·Nov 4, 2025
Cloud SecurityIdentity ManagementSecurity alerts

52% of all confirmed identity-based alerts were due to identity-related privilege escalation.

ReliaQuestToo Much Trust: The Danger of Over-Privileged Cloud Identities ·Nov 4, 2025
Cloud SecurityIdentity Management

99% of cloud identities were found to be over-privileged, creating significant security risks.

ReliaQuestToo Much Trust: The Danger of Over-Privileged Cloud Identities ·Nov 4, 2025
Cloud SecurityIdentity Management

33% of raw CSPM alerts were identity-related, contributing to the operational burden on security teams.

ReliaQuestToo Much Trust: The Danger of Over-Privileged Cloud Identities ·Nov 4, 2025
Cloud SecurityIdentity ManagementCSPM

As of October 2025, there are over 14,700 Jenkins servers exposed to the internet that remain vulnerable to CVE-2024-23897.

ReliaQuestToo Much Trust: The Danger of Over-Privileged Cloud Identities ·Nov 4, 2025
VulnerabilitiesCloud Security

71% of critical vulnerability alerts in Q3 2025 originated from just four legacy CVEs.

ReliaQuestToo Much Trust: The Danger of Over-Privileged Cloud Identities ·Nov 4, 2025
VulnerabilitiesCloud SecurityCVEs

The US remained the most targeted country by ransomware, accounting for 67% of the total organizations named on ransomware data-leak sites in Q2.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareUSData leak site

Spain and other Spanish-speaking countries each accounted for less than 4% of Qilin's total victim volume in Q2.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareQilinSpain

DragonForce emergence: December 2023.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareDragonForce

DragonForce activity was up 119% between Q1 and Q2 2025.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareDragonForce

Lynx experienced a 41% drop in activity between Q1 and Q2 2025.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareLynx

80% of the organizations named by Qilin in Q2 were based in the US.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareQilin

Qilin showed an 80% increase in activity in Q2 compared to Q1 2025.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareQilin

Akira has already listed 15% more victims in the first half of 2025 than it did throughout the entirety of 2024.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareAkira

Germany rose to second most targeted country by ransomware in Q2 2025, climbing two spots from fourth in Q1 2025.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareGermany

Q2 2025 saw a 31% decrease in named ransomware victims compared to the previous quarter, marking a return to more typical levels.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
Ransomware

In Q1 2025, Clop named 389 victims on its data-leak site in February alone.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareClop

SafePay's activity increased by 42% in Q2 2025 compared to Q1 2025.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareSafePay

Akira listed approximately 130 organizations to its data-leak site each quarter in 2025.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareAkira

LockBit named just 24 organizations on its data-leak site in Q2 2025. This figure represents only 11% of its Q2 2024 victim count.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareLockBit

Retail trade accounted for only 4% of total ransomware victims in Q2 2025.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareRetail

Construction was the third most targeted sector by ransomware in Q2 2025.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareConstruction

Akira showed a 348% rise in the number of organizations named in Q2 2025 compared to the same period last year.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareAkira

Qilin emerged as the top ransomware threat in Q2 2025.

ReliaQuestRansomware and Cyber Extortion in Q2 2025 ·Jul 3, 2025
RansomwareQilin

80% of ransomware attacks in the last year focused on data exfiltration only.

ReliaQuestAnnual Cyber-Threat Report·Feb 25, 2025

After initial access, "breakout time" typically takes just 48 minutes, with some groups achieving lateral movement in as little as 27 minutes.

ReliaQuestAnnual Cyber-Threat Report·Feb 25, 2025

Exfiltration-only ransomware attacks are 34% faster than those involving encryption.

ReliaQuestAnnual Cyber-Threat Report·Feb 25, 2025

A quarter of active intrusions started with exploitation of public-facing applications.

ReliaQuestAnnual Cyber-Threat Report·Feb 25, 2025

Compromised service accounts were present in 85% of breaches last year.

ReliaQuestAnnual Cyber-Threat Report·Feb 25, 2025

Two-thirds of critical hands-on-keyboard incidents involved legitimate software like remote access tools last year.

ReliaQuestAnnual Cyber-Threat Report·Feb 25, 2025

"Akira" more than doubled its Q3 count and listed 71 organisations on data-leak sites in December alone.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

The fastest recorded lateral movement occurred in just 27 minutes.

ReliaQuestRacing the Clock: Outpacing Accelerating Attacks·Jan 1, 2025

Roughly 20% of the domains registered by Scattered Spider imitated Gateway and Network Infrastructure.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

Only a small fraction (0.02%) of alerts led to lateral movement, meaning attacks are getting faster.

ReliaQuestRacing the Clock: Outpacing Accelerating Attacks·Jan 1, 2025

LockBit's victim count decreased from 176 in May 2024 to only five in December.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

Initial access listings on cybercriminal platforms surged by 142% in the same period.

ReliaQuestRacing the Clock: Outpacing Accelerating Attacks·Jan 1, 2025

66% of customer ransomware incidents in 2024 involved initial access likely purchased from an IAB.

ReliaQuestRacing the Clock: Outpacing Accelerating Attacks·Jan 1, 2025

Approximately 15% of domains registered by Scattered Spider imitated VPN and Secure Access.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

The average breakout time in 2024 was 48 minutes, which is 22% faster than in 2023.

ReliaQuestRacing the Clock: Outpacing Accelerating Attacks·Jan 1, 2025

Newcomers in Q4 like “SafePay” and “FunkSec” quickly ramped up their activity, claiming 45 and 82 victims, respectively.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

Ransomware attacks reached an all-time high in December 2024.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

In Q4 2024, there was the highest jump of the year with 13 new ransomware groups emerging.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

There was a >50% increase in infostealer logs posted on the dark web in 2024 compared to 2023.

ReliaQuestRacing the Clock: Outpacing Accelerating Attacks·Jan 1, 2025

17% of incidents involved voice phishing for initial access, indicating help-desk scams.

ReliaQuestRacing the Clock: Outpacing Accelerating Attacks·Jan 1, 2025

The number of active ransomware groups increased from 60 in 2022 to almost 100 last year.

ReliaQuestRacing the Clock: Outpacing Accelerating Attacks·Jan 1, 2025

Attack speed increased by 22% in 2024 compared to 2023.

ReliaQuestRacing the Clock: Outpacing Accelerating Attacks·Jan 1, 2025

The median ransom payment rose from $199,000 in 2023 to $1,500,000 in 2024.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

Nearly half of the 1,110 initial access listings collected in Q4 2024 were related to US-based companies.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

"BlackLock" activity rose 1,425% from Q3 to Q4 2024.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

The mean time to contain (MTTC) attacks using manual incident containment strategies is 8 hours and 12 minutes.

ReliaQuestRacing the Clock: Outpacing Accelerating Attacks·Jan 1, 2025