ReliaQuest
Reports
All Statistics
The Gentlemen surged 588% quarter-over-quarter to 179 posts in Q1.
The Gentlemen posted 101 victims in April, 77 in May, and 122 in June.
Deadlock emerged in June 2026 with 75 named victims in a single month.
The quickest data exfiltration attack in 2025 took just 6 minutes versus over 4 hours in 2024.
80% of ransomware groups use AI, automation, or both in their attacks.
BoaLoader malware is a factor in nearly 20% of incidents observed in the calendar year.
44% of true-positive security alerts from cloud security tools in Q3 2025 were driven by identity-related weaknesses.
52% of all confirmed identity-based alerts were due to identity-related privilege escalation.
99% of cloud identities were found to be over-privileged, creating significant security risks.
Akira has already listed 15% more victims in the first half of 2025 than it did throughout the entirety of 2024.
Retail trade accounted for only 4% of total ransomware victims in Q2 2025.
The US remained the most targeted country by ransomware, accounting for 67% of the total organizations named on ransomware data-leak sites in Q2.
Two-thirds of critical hands-on-keyboard incidents involved legitimate software like remote access tools last year.
Compromised service accounts were present in 85% of breaches last year.
80% of ransomware attacks in the last year focused on data exfiltration only.
The mean time to contain (MTTC) attacks using manual incident containment strategies is 8 hours and 12 minutes.
"Akira" more than doubled its Q3 count and listed 71 organisations on data-leak sites in December alone.
LockBit's victim count decreased from 176 in May 2024 to only five in December.
Roughly 20% of the domains registered by Scattered Spider imitated Gateway and Network Infrastructure.
The average breakout time in 2024 was 48 minutes, which is 22% faster than in 2023.
66% of customer ransomware incidents in 2024 involved initial access likely purchased from an IAB.
Deadlock was absent from public data-leak sites for 11 months before emerging publicly.
Qilin fell from 111 data leak posts in April to 79 in June, a 29% decrease.
The top 11 tracked ransomware groups accounted for 1,368 victim claims across 99 countries in Q2.
Ransomware attacks spread across 90 ransomware groups and 99 countries.
Ransomware groups posted 2,252 victims in Q2, down 15% from Q1 and up about 51% year over year.
The Gentlemen posted 300 victims in Q2, edging out Qilin with 289 victims.
DragonForce dropped from 65 data leak posts to 27 posts, a 58% decrease.
Coinbase Cartel collapsed from 45 data leak posts to 4 posts, a 91% decrease.
PSTS led sector targeting for the fifth consecutive quarter.
The US absorbed 1,094 ransomware victim data leak posts in Q2, roughly 49% of observed activity and nine times the volume of the next country.
Professional, Scientific, and Technical Services (PSTS) recorded 437 ransomware victim posts across the top 11 groups and accounted for 32% of tracked activity.
Threat actors utilizing AI and automation tools can achieve lateral movement within an organization in as little as 4 minutes, 85% faster than the previous year.
On average, lateral movement within an organization takes 34 minutes, 29% quicker than the 48 minutes recorded in 2024.
Organizations leveraging AI and automation can contain threats within 4 minutes versus up to 16 hours with manual efforts.
33% of raw CSPM alerts were identity-related, contributing to the operational burden on security teams.
As of October 2025, there are over 14,700 Jenkins servers exposed to the internet that remain vulnerable to CVE-2024-23897.
71% of critical vulnerability alerts in Q3 2025 originated from just four legacy CVEs.
Germany rose to second most targeted country by ransomware in Q2 2025, climbing two spots from fourth in Q1 2025.
Spain and other Spanish-speaking countries each accounted for less than 4% of Qilin's total victim volume in Q2.
DragonForce emergence: December 2023.
DragonForce activity was up 119% between Q1 and Q2 2025.
Lynx experienced a 41% drop in activity between Q1 and Q2 2025.
80% of the organizations named by Qilin in Q2 were based in the US.
In Q1 2025, Clop named 389 victims on its data-leak site in February alone.
Qilin showed an 80% increase in activity in Q2 compared to Q1 2025.
SafePay's activity increased by 42% in Q2 2025 compared to Q1 2025.
LockBit named just 24 organizations on its data-leak site in Q2 2025. This figure represents only 11% of its Q2 2024 victim count.
Q2 2025 saw a 31% decrease in named ransomware victims compared to the previous quarter, marking a return to more typical levels.
Akira listed approximately 130 organizations to its data-leak site each quarter in 2025.