Monday, 29 September 2025
28.7 C
Singapore
28.5 C
Thailand
21.6 C
Indonesia
28.2 C
Philippines

Coveware by Veeam reports sharp rise in Q2 2025 ransomware attacks

Coveware by Veeam reports a sharp rise in Q2 2025 ransomware attacks, with social engineering and data theft driving record payouts.

Coveware by Veeam has reported a significant rise in ransomware activity during the second quarter of 2025, driven largely by targeted social engineering and data theft. The company’s latest quarterly report highlights record ransom payouts and the growing importance of data resilience in defending against increasingly sophisticated attacks.

Social engineering and data exfiltration dominate attacks

According to the report, three ransomware groups — Scattered Spider, Silent Ransom, and Shiny Hunters — were responsible for many of the quarter’s most damaging incidents. These groups have shifted from broad, opportunistic campaigns to highly targeted attacks, using advanced impersonation techniques to deceive help desks, employees, and third-party providers.

Bill Siegel, CEO of Coveware by Veeam, said: “The second quarter of 2025 marks a turning point in ransomware, as targeted social engineering and data exfiltration have become the dominant playbook. Attackers aren’t just after your backups – they’re after your people, your processes, and your data’s reputation. Organisations must prioritise employee awareness, harden identity controls, and treat data exfiltration as an urgent risk, not an afterthought.”

The analysis shows that data exfiltration was present in 74% of cases, with many attackers now focusing on stealing sensitive information rather than encrypting systems. Multi-extortion tactics and delayed threats have also become more common, prolonging the risk period for victims.

Record ransom payouts and targeted industries

Ransom demands have climbed sharply, with average payments rising to US$1.13 million — a 104% increase from the previous quarter — and median payments doubling to US$400,000. This surge was fuelled by larger organisations paying after data theft-only incidents, even though the overall proportion of companies paying ransoms remained at 26%.

The most targeted industries were professional services (19.7%), healthcare (13.7%), and consumer services (13.7%). Mid-sized businesses employing between 11 and 1,000 staff accounted for 64% of victims, making them an attractive target due to their potential payout value and often less mature security measures.

Evolving threats and shifting ransomware landscape

Credential theft, phishing, and remote service exploitation remain the most common entry points. Attackers are increasingly bypassing technical controls through human manipulation, while vulnerabilities in widely used platforms such as Ivanti, Fortinet, and VMware continue to be exploited. The report also notes an increase in so-called “lone wolf” attacks, where experienced extortionists operate independently using unbranded tools.

Akira was the most prevalent ransomware variant in Q2, accounting for 19% of cases, followed by Qilin (13%) and Lone Wolf (9%). Silent Ransom and Shiny Hunters entered the top five rankings for the first time, signalling the emergence of new influential players in the ransomware ecosystem.

Coveware by Veeam’s findings draw from its direct involvement in ransomware cases, using real-time incident response, proprietary forensic tools, and detailed tracking of threat actor behaviour. This approach provides a comprehensive and timely view of the threat landscape, helping organisations strengthen their defences and prepare for recovery.

Hot this week

Google launches Mixboard, an AI tool for creating moodboards

Google has launched Mixboard, an AI moodboard builder in public beta, helping users create design boards with text prompts or templates.

TeamViewer launches global MSP Partner Programme to drive growth and service innovation

TeamViewer launches a global MSP Partner Programme to help service providers scale, innovate, and deliver secure, reliable digital services.

Top gaming mice in 2025: Best lightweight, wireless, and esports options reviewed

Discover the best gaming mice of 2025, from ultralight wireless models to esports-ready designs built for speed and precision.

Dell launches first wireless earbuds with AI noise suppression

Dell has launched its first wireless earbuds, the Pro Plus EB525, which feature AI noise suppression, adaptive ANC, and enterprise integration.

ByteDance backs Soonshot’s AI-powered short-form K-dramas to grow global fan base

Soonshot partners with ByteDance’s BytePlus to deliver AI-powered short-form K-dramas and expand its global audience from Singapore.

Fire at South Korea’s national data centre disrupts hundreds of government services

A fire at South Korea’s national data centre disrupted nearly 650 government services, raising concerns over safety and centralisation.

Future humanoid robots may feature unconventional designs, an expert says

Expert Rodney Brooks predicts that humanoid robots of the future will feature wheels, sensors, and unconventional designs unlike those of humans.

Apple tests internal ‘Veritas’ chatbot as part of Siri upgrade development

Apple is testing an internal chatbot called Veritas to develop new Siri AI features, but has no plans to release it to consumers.

Building the next-generation enterprise data centre

Enterprises in Southeast Asia must modernise data centres with AI-ready compute, NVMe-TCP storage, advanced cooling, and green standards.

Related Articles

Popular Categories