Google Threat Intelligence Group and Mandiant reported that financially motivated intrusion activity is increasingly shifting away from traditional ransomware encryption toward data-theft extortion, even as ransomware remains a major enterprise threat. Google said data theft accompanied 77% of ransomware intrusions it observed in 2025, up from 57% in 2024, and noted that some ransomware-as-a-service operations now offer data-theft-only extortion options. The reporting also highlighted that English-speaking underground actors are increasingly focused on stealing data for leverage rather than deploying encryptors, with groups such as Scattered Spider, ShinyHunters, and Clop cited as examples of actors associated with large-scale extortion activity.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
On March 16, 2026, Google Threat Intelligence Group and Mandiant published a report describing the 2025 ransomware landscape, including declining profitability, lower ransom demands and payment rates, and a shift toward data extortion. The report also assessed that ransomware would remain a major threat in 2026 despite these operational changes.
Based on Mandiant incident response data from 2025, REDBIKE was the most commonly observed ransomware family, accounting for about 30% of analyzed incidents. The finding identified REDBIKE as the leading family in a year marked by broader shifts in ransomware operations.
Researchers found that ransomware actors targeted virtualization infrastructure such as VMware ESXi in about 43% of analyzed 2025 intrusions. This reflected continued attacker focus on high-impact systems that can affect many workloads at once.
In 2025, exploitation of vulnerabilities in VPNs, firewalls, and similar edge technologies was a leading initial access method in ransomware incidents. Researchers specifically highlighted frequent abuse of flaws in Fortinet, SonicWall, Palo Alto Networks, and Citrix products.
Throughout 2025, financially motivated threat actors increasingly favored data-theft-only extortion over traditional ransomware encryption, especially among English-speaking underground actors such as Scattered Spider, ShinyHunters, and Clop. Researchers found confirmed or suspected data theft in 77% of ransomware intrusions, while successful ransomware deployment fell from 54% in 2024 to 36%.
Mandiant reported that leak activity affecting Germany rose 92% in 2025, roughly triple the European average, returning pressure levels to those seen in 2022 and 2023. The report said global extortion groups including Qilin and SafePay heavily targeted German organizations, especially Mittelstand and professional services firms, amid a more volatile European leak-site ecosystem.
Across 2025, researchers observed a sharp rise in extortion-related leak site activity, with posts increasing 48% year over year to 7,784 and unique leak sites rising nearly 35% to 128. The increase reflected growing reliance on public shaming and data extortion, though researchers cautioned that some leak site claims may be false or recycled.
As prominent ransomware groups lost momentum in 2025, Qilin and Akira expanded to fill the gap in the criminal market. Their growth contributed to continued ransomware activity despite broader disruption among leading operators.
During 2025, major ransomware-as-a-service groups including LockBit, ALPHV, Basta, and RansomHub were weakened, disrupted, or dismantled by law enforcement pressure and internal conflicts. The disruption reduced the dominance of some established groups and reshaped the ransomware ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
cloud.google.com
Open sourcecybersecuritynews.com
Open sourcecyberscoop.com
Open sourcecloud.google.com
Open sourcecomputerweekly.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.