A global ransomware surge has hit thousands of companies in 2025. Cybercriminals increasingly target smaller firms and manufacturers struggling with downtime costs and limited cybersecurity defenses.
Alarming Growth in Ransomware Activity
Between January and September 2025, over 6,000 ransomware cases were exposed on dark web leak sites, marking a 47% year-over-year increase, according to cybersecurity firm NordStellar. The majority of these victims are U.S.-based businesses, with the manufacturing sector taking the hardest blow.
Cybersecurity expert Vakaris Noreika noted that U.S. organizations remain primary targets due to their profitability and strict regulatory requirements, making them more likely to pay ransoms quickly to resume operations.
Manufacturing Sector Takes the Hardest Hit
In Q3 2025 alone, manufacturing reported 245 ransomware incidents. These companies face major financial pressure from downtime, often forcing them to meet ransom demands to avoid prolonged disruption.
Meanwhile, ransomware groups increasingly favor small and midsize businesses (SMBs). Lacking advanced IT infrastructure, these firms often operate on limited cybersecurity budgets, making them easier and less risky to compromise.
Dominant Ransomware Gangs
Well-known ransomware operators such as Qilin, Akira, and Play continue to dominate the global cybercrime landscape. These groups maintain constant activity across multiple leak sites, demonstrating both persistence and adaptability in exploiting new vulnerabilities.
Mitigation and Protection Strategies
Experts urge organizations to strengthen their defenses with essential cybersecurity practices:
- Conduct employee training on phishing and social engineering.
- Enforce multi-factor authentication and password management systems.
- Regularly monitor for dark web data leaks and external vulnerabilities.
- Maintain secure data backups and detailed incident recovery plans.
Noreika emphasized that hybrid and remote work environments further expand attack surfaces. Unmanaged devices and third-party vendors can easily become weak points if not properly secured.
Conclusion
The global ransomware surge in 2025 exposes widespread weaknesses in both enterprise and SMB defenses. With attack volumes rising and threat groups evolving, proactive security, routine patching, and continuous monitoring remain the strongest shields against ransomware disruption.


0 responses to “Global Ransomware Surge: Thousands of Companies Hit in 2025”