惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
A
About on SuperTechFans
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
N
Netflix TechBlog - Medium
Microsoft Security Blog
Microsoft Security Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
博客园 - Franky
D
Docker
Martin Fowler
Martin Fowler
Engineering at Meta
Engineering at Meta
The Cloudflare Blog
人人都是产品经理
人人都是产品经理
Last Week in AI
Last Week in AI
U
Unit 42
F
Fortinet All Blogs
H
Help Net Security
Blog — PlanetScale
Blog — PlanetScale
Microsoft Azure Blog
Microsoft Azure Blog
罗磊的独立博客
P
Proofpoint News Feed
月光博客
月光博客
G
Google Developers Blog

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
France: National Cybersecurity Agency Reports Ransomware ...
2026-03-11 · via www.infosecurity-magazine.com

The French Cybersecurity Agency (ANSSI) has confirmed the decline of known ransomware attacks in 2025, in part due to successful law enforcement operations.

The latest edition of the agency’s annual threat report, published on March 11, dives into the range of cyber threats that French public and private organizations have faced in 2025.

According to ANSSI data, there were 128 ransomware attacks reported in France in 2025, slightly fewer than the 141 such attacks recorded in 2024.

Monthly and cumulative distribution of ransomware attacks in France in 2024 and 2025. Source: Agence nationale de la sécurité des systèmes d'information (ANSSI), translated using OpenAI's GPT Image 1.5
Monthly and cumulative distribution of ransomware attacks in France in 2024 and 2025. Source: Agence nationale de la sécurité des systèmes d'information (ANSSI), translated using OpenAI's GPT Image 1.5

Nevertheless, the agency highlighted that ransomware compromises remained a significant threat and represent a substantial share of the over cybercriminal activity.

The report also noted that, while ANSSI’s partnering security vendors frequently warn about an uptick in encryption-less cyber extortion attacks such incidents have been limited, according to the agency’s data.

Small and medium businesses (SMBs) remained the organizations most targeted by ransomware, but public and private healthcare entities and education organizations have experienced the biggest year-over-year increase.

The most prevalent ransomware strains observed by ANSSI in 2025 were Qilin (21%), Akira (9%), and LockBit 3.0/LockBit Black (5%).

Additionally, more than a dozen strains (notably Nova, Warlock and Sinobi) were observed for the first time in 2025 in at least one incident.

ANSSI assessed that the drop in ransomware attacks is at least partly due to the successful preventive intervention of cyber defenders, including those from the French agency, and large-scale law enforcement operations.

One of the most impactful efforts was Operation Endgame, which ANSSI said disrupted a large part of the ransomware landscape and undermined trust within the cybercriminal ecosystem.

Cyber Incidents Treated by ANSSI Remain Stable

Overall, ANSSI received 3586 cyber alerts that involved the support of the agency in 2025, an 18% drop compared to 2024. However, this decline can be partly explained by a spike of signals sent to ANSSSI during the 2024 Paris Olympic and Paralympic Games.

Out of those 3586 cyber alerts, the agency reported 1366 cyber incidents where the involvement of a malicious actor was confirmed.

This is similar to the number ANSSI reported the previous year (1361 of cyber incidents in 2024), which itself was an increase from the 1112 incidents reported in 2023 and 831 in 2022.

The report also noted a significant increase in the number of incidents related to data exfiltration. However, the agency warned that claims of data exfiltration must always be considered with extra care as they often are subject to exaggeration or even lies from the cybercriminals.

For instance, out of the 460 events identified by ANSSI as possible data leaks in 2025, 42% were confirmed as being associated with actual compromises and the remainder were either false claims or "recycling" of data from previous compromises.

ANSSI also highlighted a significant drop in distributed denial-of-service (DDoS) attacks targeting French organizations in 2025.

Overlaps Between Nation-State Groups and Cybercriminals Complicate Attribution

Finally, the report emphasized the emergence of a technological and organizational fog, deliberately used as leverage by both nation-state attackers and cybercriminals, where groups from both categories increasingly share capabilities, adopt each other’s practices.

“This trend inherently complicates the attribution process, as it is associated with a division of tasks among multiple actors, each specializing in certain phases of a compromise,” the ANSSI report reads.

Vincent Strubel, ANSSI’s director general, said in the report that the series of cyber-attacks against Polish electrical infrastructure at the end of 2025 “raises the specter of the feared scenario for which France is preparing.”

“It is a central scenario in which we would face, by 2030, a massive increase in so‑called ‘hybrid’ attacks, with cyber-attacks representing a major component and having concrete or even destructive effects on our critical infrastructures,” he added. Before concluding that “yes, France has the means to counter, deter, or at least significantly complicate the work of attackers.”