< Back to all clusters
[TECHNOLOGY] · 2 sources

Kaspersky report finds ransomware attacks falling yet becoming more industrialized

Kaspersky’s 2026 State of Ransomware report notes a modest dip in the overall share of organisations hit by ransomware in 2025 compared with 2024, but highlights a shift toward highly industrialised operations. Attackers now automate intrusions, focus on stealing and exfiltrating data rather than merely encrypting systems, and employ “EDR killers” to disable endpoint‑detection tools.

The report shows regional variation: Latin America recorded the highest victim proportion at 8.13 %, followed by the Asia‑Pacific (7.89 %), Africa (7.62 %), the Middle East (7.27 %), the CIS (5.91 %) and Europe (3.82 %). Threat actors increasingly use post‑quantum cryptography, Telegram channels and dark‑web forums to trade compromised data sets and credentials. Law‑enforcement actions in early 2026 seized the RAMP forum and shut down LeakBase, yet new platforms are expected to arise.

Kaspersky identified Qilin as the leading ransomware‑as‑a‑service operator in 2025, with Clop and Akira ranking second and third. The growth of Initial Access Brokers and the “Access‑as‑Service” model further lowers the barrier for launching ransomware attacks.