Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityLogical SecuritySecurity & Business ResilienceSecurity Education & Training

State of ransomware: Evolving threats and strategies to stay safe

By Dale “Dr. Z” Zabriskie
Red neon lights

Emily Pippus via Unsplash

March 27, 2025

Ransomware in 2025 is no longer just a cybersecurity challenge — it has escalated into a global crisis affecting economies, governments, and essential services. From multinational corporations to hospitals and schools, no organization is immune to these increasingly sophisticated attacks. According to Cohesity’s Global Cyber Resilience Report, 69% of organizations paid a ransom in the past year, emphasizing the urgent need for stronger defenses against cybercriminals.

Recent and notable attacks

Over the past year, ransomware gangs have grown bolder and more advanced in their tactics. The ALPHV (BlackCat) ransomware group targeted several hospitals across Europe, crippling emergency services and demanding multimillion-dollar ransoms. Meanwhile, LockBit attacked a major United States energy provider, disrupting fuel distribution and causing regional shortages.

Attackers have also refined their extortion techniques. While double extortion (encrypting and leaking stolen data) has become standard, triple extortion has emerged, incorporating distributed denial-of-service (DDoS) attacks to further pressure victims into paying. In another unprecedented move, ALPHV (BlackCat) attempted to exploit SEC regulations to pressure MeridianLink, a publicly traded digital lending solutions provider, to comply with their ransom demands. To escalate pressure, ALPHV filed a complaint with the SEC against MeridianLink for this alleged non-compliance, marking a novel tactic in ransomware extortion strategies.

Additionally, supply chain attacks are on the rise, with ransomware infiltrating cloud platforms and software providers, allowing malware to spread across multiple organizations. From security weaknesses in black-box commercial software to cryptocurrency applications and infrastructure, supply chain attacks are an increasingly popular tool for bad actors.

New hacking techniques: How ransomware gangs are breaking through

Ransomware groups are continuously adapting their strategies. In 2025, many rely on AI-enhanced phishing, leveraging generative AI to craft compelling and convincing fake emails that deceive employees and bypass security systems.

Cybercriminals continue to deploy living-off-the-land (LotL) techniques, using legitimate system tools like PowerShell and remote desktop software to deploy ransomware without triggering security alerts. This tactic enables malware to blend seamlessly into regular network activity.

Another concerning development is the emergence of zero-day-as-a-service marketplaces, where attackers purchase unpatched vulnerabilities from underground sources. Using automated scanning tools, cybercriminals use that knowledge to quickly identify and exploit weaknesses before organizations can patch them.

Government and corporate responses

Governments worldwide are intensifying efforts to combat ransomware, though their strategies vary. In addition to the EU’s implementation of DORA, a proposed ban on ransom payments in the United Kingdom has sparked debate. Supporters argue that eliminating financial incentives will deter attackers, while critics warn that essential sectors — such as healthcare — could be put at risk if forced to refuse ransom demands.

In the U.S., authorities are expanding ransomware sanctions programs, targeting hackers and cryptocurrency platforms that facilitate ransom payments. The Joint Cyber Defense Collaborative (JCDC) is uniting government agencies, tech companies, and cybersecurity experts to improve intelligence sharing and strengthen coordinated defenses.

Corporations are also increasing cybersecurity investments, focusing on prevention and rapid recovery. Many organizations now implement immutable backups (which cannot be altered, even by administrators) and zero-trust security architectures, which require continuous user verification to limit unauthorized access.

Additionally, cyber insurance policies are evolving to demand stricter security measures. To qualify for coverage, businesses must demonstrate comprehensive incident response plans, conduct regular employee phishing training, and implement robust security controls such as multi-factor authentication (MFA) and endpoint detection and response (EDR) solutions.

Closing the gap: Proactive strategies for 2025

As ransomware evolves, organizations must transition from reactive responses to proactive resilience. Response and recovery should be the focus. Key strategies include:

  1. Vulnerability Management: Continuous monitoring and rapid patching of security flaws, particularly zero-day vulnerabilities.
  2. Air-Gapped Backups: Regularly updated offline backups that cannot be altered or deleted by ransomware and are tested frequently for reliability.
  3. Jump Bag Readiness: A collection of a pre-configured set of cybersecurity tools, documentation and credentials for rapid incident response and recovery.
  4. Zero-Trust Networks: Continuous verification of users and devices to prevent lateral movement by attackers.
  5. Advanced Threat Detection: Deployment of XDR (Extended Detection and Response) solutions to detect early intrusion attempts across endpoints, cloud services, and networks.
  6. Clean Room: A secure, isolated environment designed to investigate cyberattacks and recover clean data, reducing the risk of reinfection. 
  7. Incident Response Plans: Well-documented and rehearsed response strategies covering technical mitigation, legal implications, and public relations management.

The road ahead

Ransomware in 2025 is faster, wiser, and more destructive than ever before and is no longer just an IT problem — it is an operational and societal threat. While attackers continue to innovate, so do defenders. Staying protected requires preparation, intelligence sharing and unified efforts. Organizations can begin closing the cybersecurity gap by leveraging cutting-edge technology, policy changes and industry-wide collaboration.

The message for 2025 is clear: Prepare, practice, collaborate, and adapt — because unfortunately — it will only get worse.

KEYWORDS: organizational resilience ransom ransomware threat landscape

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Dr. z headshot

Dale “Dr. Z” Zabriskie is Field CISO at Cohesity. Image courtesy of Zabriskie

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Man on laptop

Healthcare Executives Face a New Era of Personal Risk

Police lights

Security Team Member Dies in Standoff with Dallas Police

Stadium

Physical Security in Global Arenas: How AI Improves Security at Scale

Four people in suits

Mexico Security Crisis: Never Waste a Crisis

Product Spotlight

ISC West 2026 Product Preview

SEC 2026 Benchmark Banner
SEC 2026 Benchmark Banner

Events

April 15, 2026

How AI is Closing the Decision Gap in Leading GSOCs

Learn how modern security teams are evolving from alert-driven workflows to outcome-driven operations and how AI is enabling faster, more confident decisions at every stage of the incident response lifecycle.

April 21, 2026

The Blind Spot in Enterprise Security: Managing Workforce Risk Post-Hire

Organizations continuously monitor their networks and systems for risk, yet the people with legitimate access are often the least monitored part of the model. Discover a Workforce Risk Intelligence Framework that adds a dedicated layer focused on workforce risk.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
SEC 2026 Top Cybersecurity Leaders

Related Articles

  • schools remote learning

    Schools, here’s how to stay cyber-safe in the age of remote learning

    See More
  • leader-to-leader

    Emerging technology, evolving threats — Part III: 5G and the new surfaces and strategies

    See More
  • Sale sign

    How to Stay Safe Online This Black Friday, According to a Cyber Expert

    See More

Related Products

See More Products
  • 9780367221942.jpg

    From Visual Surveillance to Internet of Things: Technology and Applications

  • Photonic Sensing: Principles and Applications for Safety and Security Monitoring

  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products

Events

View AllSubmit An Event
  • December 11, 2025

    Responding to Evolving Threats in Retail Environments

    ON DEMAND: Retail security professionals face an array of security challenges, from organized retail crime to cyber-physical threats and public safety concerns. Learn how one of the world’s largest retail destinations stays ahead of these emerging threats.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing