Report by ExtraHop

2025 Global Threat Landscape Report

88 FINDINGSPublished Oct 13, 2025
View Original Report →

Key Findings

33.3% of government sector threats were attributed to DarkSide in 2024.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

39.92% of manufacturing and construction organizations reported limited visibility into their entire environment.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

25.6% of government sector threats were attributed to RansomHub in 2024.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

29.27% of ransomware incidents involved initial access as the detected phase.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware detection

10% of organizations in the government sector experienced ransomware incidents annually.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
GovernmentRansomware

13.4% of IT and security decision-makers indicated third-party/supply chain compromise as a common entry point for attackers.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

70% of organizations reported that they paid the ransom in 2023

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
PaymentsRansomware

The percentage of organizations that never paid a ransom increased from 9% last year to 30% this year

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware

Unnamed Fortune 50 company reported a ransom payment of $75 million

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
PaymentsRansomware payout

42.22% of finance organizations reported limited visibility into their entire environment.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Visibility

33.3% of government sector threats were attributed to LockBit in 2024.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

4.83% of organizations reported average downtime of one week after a cyber incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Downtime

23.26% of organizations reported average downtime of 11-24 hours after a cyber incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Downtime

5.53% of ransomware incidents involved a ransom demand as the detected phase.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

37.50% of agriculture organizations reported limited visibility into their entire environment.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Agriculture

23.08% of government organizations reported limited visibility into their entire environment.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Government

55% of organizations reported experiencing 11 or more hours of downtime on average after a cyber incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Downtime

In August 2024, the Rhysida ransomware group attacked the Port of Seattle, causing systems to be offline for more than three weeks.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Downtime

2.33% of organizations reported average downtime of more than a week after a cyber incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Downtime

On average, organizations take just over 2 weeks to respond to and contain a security alert from initial detection to resolution.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware response

At least 165 Snowflake customers were affected by the 2024 Snowflake data breach, including major technology organizations like Pure Storage and AT&T

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Snowflake

59.2% of security and IT decision-makers in the technology sector perceive the public cloud as a significant cybersecurity risk in 2024

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Cloud

59% of organizations in France expressed the highest level of concern regarding risks, while 36.8% in the UAE exhibited the lowest level of concern.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
FranceUAE

23.1% of government sector threats were attributed to Volt Typhoon in 2024.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

The finance sector had an average ransom payment of $3.8 million

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
PaymentsRansomware

The government sector had an average ransom payment just below $7.5 million

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Government

The Ticketmaster/Live Nation breach exposed the personal and financial information of 560 million customers.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

The ransomware attack against Change Healthcare involved the exfiltration of sensitive data belonging to an estimated 192.7 million individuals, making it the largest healthcare data breach on record.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

The average downtime per cybersecurity incident was 37 hours

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

The average length of time to respond to and contain a security alert was 2 weeks

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

70% of organizations experienced ransomware incidents in the last year

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

Organizations estimated that ransomware actors had access to their systems for an average of 2 weeks

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
ransomware access

61.6% of security and IT decision-makers in the U.S. perceive the public cloud as the highest cybersecurity risk in 2024

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Cloud

53.8% of global security and IT decision-makers identified the public cloud as a significant cybersecurity risk to their organization in 2024

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Cloud

43.7% of organizations surveyed identified third-party services and integrations as a concern, tying with public cloud as the number one risk within the telecom industry.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
third-party

Scattered Spider was detected in 22.0% of cybersecurity incidents over the last 12 months.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware

RansomHub was detected in 26.8% of cybersecurity incidents over the last 12 months.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Incidents

28.2% of government sector threats were attributed to Midnight Blizzard/APT29/Nobellium/Cozy Bear in 2024.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

LockBit registered a 37% detection rate in Germany, indicating a significantly elevated threat compared to other regions in 2024.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

13.0% of IT and security decision-makers cited software misconfiguration as a common entry point for attackers.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

33.7% of IT and security decision-makers identified phishing and social engineering as the most common infiltration methods in their attacks.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

Almost 25% of respondents reported detections related to the Scattered Spider group over the last year.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

12.2% of IT and security decision-makers noted that compromised credentials are increasingly becoming a primary gateway for attackers.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

Organizations in the UAE paid ransoms that were 26% higher than the global average, with an average payment of $5.4 million

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware payoutUAE

The average ransom payment in Australia was $2.5 million, the lowest among the countries surveyed

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Australia

The healthcare sector had the highest average ransom payment at $7.5 million

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
HealthcareRansomware payout

The average ransom payment in 2023 was more than $3.6 million, an increase from last year's average of $2.5 million

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware payout

Organizations in the UAE faced an average of 7 ransomware incidents, the highest number globally

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
UAE

Australia experienced an average of 4 ransomware incidents per year, the fewest globally

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Australia

Organizations in the education sector reported an average dwell time of about 5 weeks prior to a ransomware incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware

30.6% of organizations recognized they were being targeted by ransomware during or after data exfiltration had already begun.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware detection

Organizations in the government sector reported an average dwell time of about 7 weeks prior to a ransomware incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Dwell timeRansomware

13.11% of ransomware incidents involved encryption as the detected phase.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware detection

17.59% of ransomware incidents involved reconnaissance as the detected phase.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware detection

29.69% of retail organizations reported limited visibility into their entire environment.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Retail

52.63% of travel and leisure organizations reported limited visibility into their entire environment.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Visibility

51.02% of education organizations reported limited visibility into their entire environment.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Education

ExtraHop detects ransomware every 1.5 days across its customer base.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware detection

44.96% of technology organizations reported limited visibility into their entire environment.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Tech

37.50% of transportation organizations reported limited visibility into their entire environment.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Transportation

30.66% of healthcare organizations reported limited visibility into their entire environment.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Healthcare

43.90% of telecom organizations reported limited visibility into their entire environment.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Visibility

Critical industries globally, such as government and transportation, face an average response time of upwards of 3 weeks to security alerts.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware responseCritical Industries

In the United States, organizations experience an average response time of 2.8 weeks to security alerts.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
USARansomware response

2.61% of organizations were unsure or could not answer regarding their average downtime after a cyber incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Downtime

20.82% of organizations reported average downtime of less than 5 hours after a cyber incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Downtime

Organizations experienced an average downtime of 37 hours after a cyber incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Downtime

Respondents in the transportation industry reported the highest average amount of downtime at 74 hours.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Transportation

23.99% of organizations reported average downtime of 2 days after a cyber incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Downtime

Nearly one third of organizations reported downtime extended for two days or more after a cyber incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Downtime

6.94% of organizations reported average downtime of 4-6 days after a cyber incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Downtime

14.66% of organizations reported average downtime of 3 days after a cyber incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Downtime

The CDK Global attack resulted in over a billion dollars in estimated losses for the automotive industry.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

The average ransomware payout was $3.6 million

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
DowntimeRansomware payout

41.9% of organizations surveyed perceived generative AI applications as a risk, ranking third compared to legacy systems at 23.5% and endpoint devices at 30.6%.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
AI

Midnight was detected in 23.3% of cybersecurity incidents over the last 12 months.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Incidents

25.6% of government sector threats were attributed to Akira in 2024.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

20.5% of government sector threats were attributed to Fin7 in 2024.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

33.3% of government sector threats were attributed to Black Basta in 2024.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

19.4% of IT and security decision-makers reported software vulnerabilities as the second-most common entry point for attackers.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

20% of organizations in the healthcare sector experienced ransomware incidents annually.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
HealthcareRansomware

7.2% of IT and security decision-makers reported insider threats as a means of infiltration.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025

The percentage of organizations experiencing 20 or more ransomware incidents annually increased from 0% to 3% year-over-year.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
RansomwareIncidents

Organizations experienced an average of 5 to 6 ransomware incidents over the last 12 months, marking a 25% decrease from nearly 8 incidents in 2024.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware

CDK Global reported a ransom payment of $50 million

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
PaymentsRansomware

Organizations cited an average dwell time of nearly 2 weeks for threat actors prior to a ransomware incident.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware detection

22.00% of ransomware incidents involved lateral movement and privilege escalation as the detected phase.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware detection

12.00% of ransomware incidents involved data exfiltration as the detected phase.

ExtraHop2025 Global Threat Landscape Report·Oct 13, 2025
Ransomware detection