Skip to content
WITTCO
All news posts

Ransomware Claimed a Record Number of Victims in 2025: What Small Businesses Should Know

· WITTCO

Ransomware gangs posted more victims in 2025 than in any year on record. GuidePoint Security counted 7,515 organizations claimed on ransomware leak sites, a 58% increase over 2024. Blockchain analysis firm Chainalysis, using its own data, put the rise in claimed victims at 50% and called 2025 the most active year on record.

The counts differ because each firm tracks leak sites its own way, but they point in the same direction.

The 2025 numbers

  • GuidePoint recorded 2,287 victims in the fourth quarter, its largest quarter ever, and 814 in December alone, up 42% from a year earlier.
  • It tracked 124 distinct ransomware groups, a 46% jump. GuidePoint says law enforcement takedowns have split the criminal market into many smaller groups rather than a few large ones.
  • Fewer victims are paying. Chainalysis estimates ransomware payments totaled $820 million in 2025, down 8% from $892 million in 2024, and that about 28% of victims paid, possibly an all-time low.
  • Those who pay are paying more. The median payment rose to nearly $60,000, up 368% from $12,738 in 2024, according to Chainalysis.

Why small businesses feel it most

Verizon's 2025 Data Breach Investigations Report, covering incidents from November 2023 through October 2024, found ransomware in 44% of all breaches, up from 32% the year before. In organizations with fewer than 1,000 employees, ransomware was involved in 88% of breaches, compared with 39% at larger organizations.

Verizon also found that the median ransom paid fell to $115,000 from $150,000, and that 64% of victims did not pay, up from 50% two years earlier. Payment figures differ between studies because they use different data and time periods.

The report adds that small businesses are less likely than large ones to have up-to-date, readily available backups, which works in attackers' favor.

What to do

CISA's #StopRansomware Guide lists the basics that stop many attacks or limit the damage:

  1. Keep offline, encrypted backups of critical data and test restoring them regularly. CISA warns that automated cloud sync alone may not be enough, because encrypted local files can sync to the cloud and overwrite good copies.
  2. Use phishing-resistant multifactor authentication for all services, especially email, VPNs and accounts that reach critical systems.
  3. Patch operating systems and software regularly, starting with internet-facing systems.
  4. Use endpoint detection and response (EDR) tools on computers and servers.
  5. Train employees to recognize phishing, and keep that training current.
  6. Write and practice a basic incident response plan, and keep a printed copy.

WITTCO covers these basics for small businesses with SentinelOne endpoint protection, Datto backups, patch management and phishing simulation, supported by a 100% U.S.-based team.

Sources

More from the newsroom

Let’s take a look at your setup.

Book a free assessment. We’ll tell you what’s working, what’s risky and what we’d fix first, even if you never hire us.

Prefer email? info@getwittco.com