惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
云风的 BLOG
云风的 BLOG
小众软件
小众软件
V
V2EX
博客园 - Franky
博客园 - 司徒正美
Apple Machine Learning Research
Apple Machine Learning Research
量子位
博客园 - 【当耐特】
雷峰网
雷峰网
WordPress大学
WordPress大学
Jina AI
Jina AI
Google DeepMind News
Google DeepMind News
N
Netflix TechBlog - Medium
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
阮一峰的网络日志
阮一峰的网络日志
IT之家
IT之家
Blog — PlanetScale
Blog — PlanetScale
Hugging Face - Blog
Hugging Face - Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
V
Visual Studio Blog
Microsoft Security Blog
Microsoft Security Blog

The Register - Security: Research

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits Extortion crews have their eyes on high-value AI data, Google warns Researcher shows how Claude Code can be tricked simply by asking it to summarize a website Copilot tricked into telling reseachers how to hack itself Akira ransomware scum blocked victim How the famed USENIX Security conf is managing a flood of papers in the AI era www.theregister.com Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine ChatGPT blindly trusts browser content, turning the page into a payload Russia-linked threat group put ChatGPT to work from lure to payload Kids can bypass some age checks with a drawn-on mustache What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia ORNL builds more sensitive GPS interference detector Researchers find sabotage malware that may predate Stuxnet Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus Anthropic, Google, Microsoft paid AI bug bounties – quietly Security reserchers tricked Apple Intelligence into cursing Don't open that WhatsApp message, Microsoft warns Security boffins harvest bumper crop of API keys from web Lightning-fast exploits mean patch fast, says Cisco Talos AI agents are 'gullible' and easy to turn into your minions Smooth criminals talking their way into cloud environments, Google says Snoops plant info-stealing malware on iPhones, Google warns Cybercrime up 245% since the start of the Iran war Rogue AI agents can work together to hack systems Fake applicants are sending security-killing malware AI agent hacked McKinsey chatbot for read-write access Kaspersky: No signs Coruna iPhone exploit kit made by US
Ransomware payments cratered in 2025 – attacks did not
Carly Page Carly Page · 2026-02-28 · via The Register - Security: Research

Research

Ransomware payments cratered in 2025, but attacks surged to record highs

Smaller crews piled in as old names splintered and rebranded

Ransomware payments cratered in 2025, but it seems like the cybercrooks launching the attacks didn't get the memo.

That's the headline from Chainalysis' 2026 Crypto Crime Report, which shows total on-chain ransomware payments falling for a second straight year, even as victim counts and leak site pressure continue to climb.

Ransomware gangs pulled in about $820 million in 2025, roughly 8 percent less than the year before, as the share of victims paying dropped to an all-time low of 28 percent. That drop might sound like progress if the wider picture weren't so bleak: the median ransom demand jumped from $12,738 in 2024 to $59,556 in 2025, and the number of publicly claimed attacks climbed along with it.

"Despite the relative stability in total payments, ransomware attacks surged across multiple vectors in 2025, with eCrime.ch data showing a 50 percent YoY increase in claimed ransomware victims, marking the most active year on record," Chainalysis said.

2025 delivered plenty of high-profile examples of this "most active" year. Jaguar Land Rover suffered what's been described as the costliest cyber incident in UK history, and Marks & Spencer endured prolonged operational disruption after a Scattered Spider-linked breach that wiped hundreds of millions off its market value. 

While 2025 had its share of mega-breaches, the real story is volume. Smaller, opportunistic groups are behind a growing share of extortion attempts, even as the old guard – LockBit, BlackCat, and friends – have been raided, sanctioned, arrested, or simply popped back up under new logos. What's left is a crowded field of spin-offs and opportunists taking their chances, and plenty of these incidents never show up as a clean, traceable crypto payout on a blockchain explorer.

Security firm Emsisoft's 2025 ransomware data reinforces that picture. More than 8,000 organizations were publicly named on leak sites last year – a sharp jump from previous years.

Developed economies are still squarely in the crosshairs. The United States leads the pack yet again, followed by Canada, Germany, the UK, and the rest of Western Europe. Manufacturing, financial, and professional services took plenty of hits, and in Canada and Germany, attackers showed a particular appetite for supply chains, logistics networks, and critical infrastructure. In the US, every major sector – including government and critical infrastructure – saw year-over-year increases in the number of claimed victims.

Chainalysis's report also offered a glimpse behind the scenes, where ransomware now looks less like a single criminal enterprise and more like a supply chain.

Initial access brokers (IABs) – the middlemen selling ready-made footholds into corporate networks – received at least $14 million in on-chain payments in 2025. That's small compared to ransomware's $820 million haul, but Chainalysis found that spikes in IAB payments often precede increases in ransomware payments and US victim leak posts by roughly 30 days. Access gets bought, and a few weeks later, someone's name appears on a leak site.

The Chainalysis report suggests that ransomware isn't shrinking so much as shifting, with fewer victims paying but more organizations getting hit, higher demands, and a thriving access-for-sale marketplace quietly teeing up the next wave of leak-site disclosures. ®