ReliaQuest

82 stats7 reports

All Statistics

The Gentlemen posted 300 victims in Q2, edging out Qilin with 289 victims.

RansomwareThreat ActorsThe Gentlemen

The US absorbed 1,094 ransomware victim data leak posts in Q2, roughly 49% of observed activity and nine times the volume of the next country.

USRansomwareData Leak Site

The Gentlemen surged 588% quarter-over-quarter to 179 posts in Q1.

RansomwareThreat ActorsThe GentlemenActor Activity

Organizations leveraging AI and automation can contain threats within 4 minutes versus up to 16 hours with manual efforts.

Incident ResponseAI SecurityThreat Containment

The quickest data exfiltration attack in 2025 took just 6 minutes versus over 4 hours in 2024.

Data Exfiltration

80% of ransomware groups use AI, automation, or both in their attacks.

RansomwareAI in CybercrimeAutomation

44% of true-positive security alerts from cloud security tools in Q3 2025 were driven by identity-related weaknesses.

Cloud SecurityIdentity ManagementSecurity alerts

52% of all confirmed identity-based alerts were due to identity-related privilege escalation.

Cloud SecurityIdentity Management

99% of cloud identities were found to be over-privileged, creating significant security risks.

Cloud SecurityIdentity Management

Retail trade accounted for only 4% of total ransomware victims in Q2 2025.

RansomwareRetail

LockBit named just 24 organizations on its data-leak site in Q2 2025. This figure represents only 11% of its Q2 2024 victim count.

RansomwareLockBit

Akira showed a 348% rise in the number of organizations named in Q2 2025 compared to the same period last year.

RansomwareAkira

Exfiltration-only ransomware attacks are 34% faster than those involving encryption.

ReliaQuestAnnual Cyber-Threat Report·1y ago

Two-thirds of critical hands-on-keyboard incidents involved legitimate software like remote access tools last year.

ReliaQuestAnnual Cyber-Threat Report·1y ago

Compromised service accounts were present in 85% of breaches last year.

ReliaQuestAnnual Cyber-Threat Report·1y ago

The mean time to contain (MTTC) attacks using manual incident containment strategies is 8 hours and 12 minutes.

There was a >50% increase in infostealer logs posted on the dark web in 2024 compared to 2023.

50% of hands-on-keyboard incidents in 2024 used valid or exposed credentials for initial access.

20–25% of Scattered Spider domains targeted finance and insurance companies.

Approximately 30% of domains registered by Scattered Spider imitated Single Sign-On (SSO) and Identity Providers.

Around 20% of domains registered by Scattered Spider imitated Help Desk and IT Support.

The Gentlemen posted 101 victims in April, 77 in May, and 122 in June.

RansomwareActor ActivityThe Gentlemen

Deadlock emerged in June 2026 with 75 named victims in a single month.

RansomwareThreat ActorsDeadlock

Deadlock was absent from public data-leak sites for 11 months before emerging publicly.

RansomwareThreat ActorsDeadlockData Leak Site

Qilin fell from 111 data leak posts in April to 79 in June, a 29% decrease.

RansomwareThreat ActorsQilin

The top 11 tracked ransomware groups accounted for 1,368 victim claims across 99 countries in Q2.

RansomwareThreat IntelligenceThreat Actors

Ransomware attacks spread across 90 ransomware groups and 99 countries.

Ransomware

Ransomware groups posted 2,252 victims in Q2, down 15% from Q1 and up about 51% year over year.

Ransomware

DragonForce dropped from 65 data leak posts to 27 posts, a 58% decrease.

RansomwareThreat ActorsDragonForce

Coinbase Cartel collapsed from 45 data leak posts to 4 posts, a 91% decrease.

RansomwareThreat ActorsCoinbase Cartel

PSTS led sector targeting for the fifth consecutive quarter.

RansomwareThreat ActorsPSTS

Professional, Scientific, and Technical Services (PSTS) recorded 437 ransomware victim posts across the top 11 groups and accounted for 32% of tracked activity.

RansomwarePSTSSector Risk

BoaLoader malware is a factor in nearly 20% of incidents observed in the calendar year.

MalwareBoaLoader

Threat actors utilizing AI and automation tools can achieve lateral movement within an organization in as little as 4 minutes, 85% faster than the previous year.

Lateral MovementAI in CybercrimeAutomation

On average, lateral movement within an organization takes 34 minutes, 29% quicker than the 48 minutes recorded in 2024.

Lateral MovementThreat Actor Tactics

33% of raw CSPM alerts were identity-related, contributing to the operational burden on security teams.

Cloud SecurityIdentity ManagementCSPM

As of October 2025, there are over 14,700 Jenkins servers exposed to the internet that remain vulnerable to CVE-2024-23897.

VulnerabilitiesCloud Security

71% of critical vulnerability alerts in Q3 2025 originated from just four legacy CVEs.

VulnerabilitiesCloud SecurityCVEs

Akira has already listed 15% more victims in the first half of 2025 than it did throughout the entirety of 2024.

RansomwareAkira

Construction was the third most targeted sector by ransomware in Q2 2025.

RansomwareConstruction

Qilin emerged as the top ransomware threat in Q2 2025.

RansomwareQilin

The US remained the most targeted country by ransomware, accounting for 67% of the total organizations named on ransomware data-leak sites in Q2.

RansomwareUSData leak site

Germany rose to second most targeted country by ransomware in Q2 2025, climbing two spots from fourth in Q1 2025.

RansomwareGermany

Spain and other Spanish-speaking countries each accounted for less than 4% of Qilin's total victim volume in Q2.

RansomwareQilinSpain

Qilin showed an 80% increase in activity in Q2 compared to Q1 2025.

RansomwareQilin

DragonForce emergence: December 2023.

RansomwareDragonForce

DragonForce activity was up 119% between Q1 and Q2 2025.

RansomwareDragonForce

Lynx experienced a 41% drop in activity between Q1 and Q2 2025.

RansomwareLynx

80% of the organizations named by Qilin in Q2 were based in the US.

RansomwareQilin

SafePay's activity increased by 42% in Q2 2025 compared to Q1 2025.

RansomwareSafePay