Reporting and research indicate ransomware/data-extortion activity remained elevated through 2025 into early 2026, with threat actors increasingly emphasizing data theft, public pressure, and supply-chain leverage rather than encryption alone. Cyble’s threat landscape findings cited by TechRepublic put 2025 at 6,604 recorded ransomware attacks (up 52% YoY), with 731 attacks in December and 2,000+ claims in the last three months of 2025; the same reporting also notes supply-chain attacks nearly doubled, increasing the potential blast radius when service providers are hit.
A major example is Conduent, where the January 2025 ransomware attack is now assessed to have impacted ~25 million Americans (up from an initial 10 million), with reporting describing ~8TB of data stolen including Social Security numbers and medical data, alongside days of operational disruption. Separately, Accenture-linked research reported that the World Leaks extortion operation added a custom Rust-based tool, RustyRocket, described as a stealthy data-exfiltration and proxy capability using obfuscated, multi-layer encrypted tunnels and a runtime “guardrail” requiring a pre-encrypted configuration—features intended to make detection and monitoring difficult. Broader ecosystem reporting also highlights how data leak sites (DLSs) and “naming-and-shaming” tactics have become central to double-extortion pressure, while a weekly incident roundup underscores continued real-world disruption from ransomware (e.g., impacts to public services) and ongoing regulatory consequences for inadequate security controls following breaches.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
Accenture Cybersecurity reported that World Leaks had added a previously unseen malware tool called RustyRocket to its operations. The tool provides stealthy data exfiltration, proxying, persistence, and encrypted tunneling designed to blend malicious traffic into legitimate network activity.
As part of its response, Conduent said it implemented data protection and dark web monitoring measures. The company reported that it had not observed the stolen data appearing on dark web forums so far.
Conduent reserved $25 million for notification and related response activities, had already spent $9 million, and expected to complete payments by early 2026. The company also said cyber insurance could cover costs above that amount within policy limits.
Oregon's attorney reportedly stated that 10.5 million residents were affected by the Conduent breach. Combined with other state disclosures, this helped push the estimated total impact to roughly 25 million individuals.
Updated Texas breach reporting increased the estimated number of affected individuals tied to the Conduent incident from 4 million to 15.4 million. This was one of the major revisions that expanded the known scale of the breach.
In the final three months of 2025, ransomware groups claimed more than 2,000 attacks, including 731 in December alone. Elevated activity continued into early 2026, underscoring sustained momentum in the threat landscape.
Cyble identified the Russia-linked Qilin group as the most active ransomware operation in 2025, claiming 1,138 successful breaches. The group remained highly active into December 2025 and January 2026.
Cyble's annual threat report found ransomware activity surged throughout 2025, reaching 6,604 recorded attacks for the year, a 52% increase over 2024. Monthly attack volumes rose to nearly 700, with the United States accounting for 55% of attacks.
In a September 30, 2025 SEC filing, Conduent said it had detected the January ransomware incident and described the impact as limited to a subset of users. Later state-level breach figures indicated the exposure was much larger than that characterization suggested.
The ransomware group SafePay was identified in reporting as claiming responsibility for the Conduent attack. The breach was described as involving sensitive data including Social Security numbers and medical information.
Conduent detected a ransomware attack on January 13, 2025. The incident caused several days of operational disruption and involved the alleged theft of about 8 TB of sensitive data.
World Leaks began operating in early 2025 as a ransomware/extortion group focused primarily on stealing data and threatening publication rather than relying on file encryption. The group reportedly used social engineering, stolen credentials, and exploitation of exposed infrastructure for initial access.
Ransomware groups began using dark-web data leak sites in late 2019 to pressure victims by publishing stolen data samples, victim details, and deadlines. This marked a shift toward double extortion, combining encryption with threats to expose stolen information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourceinfosecurity-magazine.com
Open sourcewelivesecurity.com
Open sourcetechrepublic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.