
SAN FRANCISCO – 16th July, 2025 – BlackFog, the leader in ransomware prevention and anti data exfiltration (ADX), today revealed findings from analysis of ransomware activity from April to June 2025 across publicly disclosed and non-disclosed attacks.
The data shows that over this period there was a 63% increase in publicly disclosed attack volumes with a total of 276 incidents compared to Q2 2024 (169 incidents). Notably, this is the highest number for this timeframe since BlackFog began tracking in 2020.
Key findings for April to June
Sharp increase in publicly disclosed attacks year on year
All three months set a new high compared with the same time period in previous years. Year on year the increases by month are:
- A 113% increase in June with a total of 96 attacks
- A 51% increase in April with a total of 89 attacks
- A 40% increase in May with a total of 91 attacks
Healthcare sector the most targeted
In terms of disclosed attacks, healthcare was the most targeted sector with 52 attacks. This was followed by the government sector, which recorded 45 attacks and the services industry with 33 attacks.
Retail in the ransomware crosshairs
The retail sector recorded its highest ever Q2 attack volumes, with UK retailers in particular bearing the brunt of high-profile ransomware attacks. The number of publicly disclosed ransomware incidents in this sector jumped by 58% compared to Q1 2025.
The Construction, Hospitality and Arts and Entertainment sectors also reported the highest ever Q2 attack volumes. Across the board, the use of data exfiltration remained consistently high, with 95% of publicly disclosed attacks involving the theft of sensitive information.
Qilin dominates the global ransomware threat with a strategic shift
Amongst 53 active ransomware groups, the Qilin ransomware gang took the lead as the most active, responsible for 10% (28) of disclosed attacks and 15% of those revealed on dark web leak sites. Earlier this year, CISA issued a formal warning after Qilin struck high profile targets in the UK and US with the group labelled a major risk to critical infrastructure.
The hidden landscape: unreported incidents continue to increase
The figures also reveal that the scale of hidden activity remains significant with 80.9% of all ransomware attacks going unreported. Across Q2 there were 1,446 undisclosed ransomware attacks marking a 19% increase compared to the same quarter in 2024.
As with the first quarter of this year, the services industry was the hardest hit, accounting for 23% (337) of all undisclosed attacks in Q2.
Commenting on the findings, Dr. Darren Williams, Founder and CEO of BlackFog said: “The findings lay bare the extent of the challenge that organizations face. The past few months have been especially punishing for global retailers, with prominent high street stores falling victim and absorbing the financial and operational fallout of these attacks.
He continues “The findings also highlight that, time and again, attackers are ultimately after one thing: data. This is yet another reminder that organizations must take decisive action to reduce the risk of exfiltration with controls and processes that form a protective ‘ring of steel’ around their most sensitive data to stop attackers in their tracks.”
Methodology
This report was generated in part from data collected by BlackFog Enterprise over the specific report period April – June 2025. It highlights significant events that prevented or reduced the risk of ransomware or a data breach and provides insights into global trends for benchmarking purposes. This report contains anonymized information about data movement across hundreds of organizations and should be used to assess risk associated with cybercrime.
Industry classifications are based upon the ICB classification for Supersector used by the New York Stock Exchange (NYSE).
All recorded events are based upon data exfiltration from the device endpoint across all major platforms.
BlackFog’s State of Ransomware report for April – June 2025 can be accessed here:
About BlackFog
BlackFog is the category-defining vendor in anti data exfiltration (ADX). Founded in 2015, the company invented ADX on the thesis that the endpoint is the only control point capable of stopping data from leaving an organization, an architectural bet that has now been validated across three exfiltration vectors: ransomware, shadow AI, and autonomous AI agents. BlackFog’s endpoint-native platform protects more than 500 enterprises, government agencies, and critical infrastructure operators worldwide.
The company is the publisher of the annual State of Ransomware report and the BlackFog/Sapio Shadow AI Research, the most-cited primary research in the category. BlackFog’s recognition includes the teiss Awards 2026, the AI Excellence Award 2026, the Cybersecurity Excellence Awards 2026, and the Cybersecurity Breakthrough Award. Headquartered in San Francisco with international operations in London and Belfast. Learn more at blackfog.com.
Media Contact:
Share This Story, Choose Your Platform!
Related Posts
The Canvas Ransomware Attack: How ShinyHunters Exposed a Global Education Security Crisis
ShinyHunters’ Canvas ransomware attack exposed millions of student records, highlighting growing risks of data exfiltration in education.
Free 14-Day AI Discovery & Data Exposure Assessment
BlackFog's state of ransomware May 2026 measures publicly disclosed and non-disclosed attacks globally.
The State of Ransomware: May 2026
BlackFog's state of ransomware May 2026 measures publicly disclosed and non-disclosed attacks globally.
BlackFog Honored with 2026 MSP Today Product of the Year Award
BlackFog’s ADX Vision won the 2026 MSP Today Product of the Year Award for helping MSPs detect Shadow AI risks and protect data.
Snowflake Data Breach Explained: Timeline, Impact, and Key Lessons
The 2024 Snowflake data breach exposed 165+ organizations through stolen credentials and absent MFA. Here’s the timeline, impact, and key lessons for cloud security.
RAG Poisoning: How Hidden Prompts Steal Corporate Data
RAG poisoning lets attackers hijack AI assistants like Copilot to exfiltrate corporate data. Here is how the attack works and how to defend against it.






