ZeroFox Intelligence Flash Report - Ransomware Incidents Reach Record High in Q1 2025
|by Alpha Team

ZeroFox Intelligence Flash Report - Ransomware Incidents Reach Record High in Q1 2025
Product Serial: F-2025-04-24a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on the record-breaking number of ransomware and digital extortion incidents observed during the first three months of 2025.
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- ZeroFox observed at least 1,961 separate ransomware and digital extortion (R&DE) incidents during the first three months of 2025, a significantly higher total than that observed during any previous three-month period.
- North America-based entities were the most targeted by a significant proportion, accounting for approximately 65 percent of incidents-slightly higher than the average of 58 percent observed throughout 2024.
- Organizations in the manufacturing industry were targeted by more R&DE incidents during Q1 2025 than those in other industries, a trend that has continued since at least 2021.
- The most active R&DE collectives during the first three months of 2025 were almost certainly Cl0p, RansomHub, Akira, Lynx, and Qilin. This is a notably different picture to that from the final quarter of 2024, with only two out of five of the same collectives appearing in both lists.
Tags: tlp:clear, dark web, MAL Ransomware, threat actor