Extortion is being repriced. The money is moving somewhere else.
The year's flagship research finally landed, and it confirms most of what we argued in March while adding one finding we did not see coming: ransomware appears in more breaches than ever and earns less than ever.
- Published
- June 24, 2025
- Period covered
- April 1, 2025 – June 30, 2025
- Documentary cut-off
- June 24, 2025
Executive perspective
Six conclusions that matter for the year ahead
Ransomware is in more breaches than ever and earns less than ever
It was present in 44% of breaches, up from 32%, a 37% increase in a single year. Over the same period the share of victims refusing to pay rose to 64%, from roughly 50% in 2022; the median payment fell to $115,000 from $150,000; and blockchain analysis puts total payments down 35%. More attacks, fewer payers, smaller cheques.
That repricing explains March's fragmentation, and predicts what comes next
Forty new groups formed in 2024 and the fourth quarter set a volume record. Read alongside collapsing unit economics, that is not a boom. It is more operators compensating for a shrinking return per victim, which mechanically requires more victims and more pressure on each. The escalation of extortion tactics forecast by the Canadian Centre for Cyber Security is the arithmetic consequence.
The criminal economy grew sharply, and the growth is in fraud
Losses reported to the FBI's IC3 reached a record $16.6 billion in 2024, up 33%, with investment fraud at $6.6 billion and business email compromise at $2.8 billion. Extortion, as a reported loss category, accounted for $143 million. The money did not leave cybercrime. It left extortion.
Third-party involvement in breaches doubled, from 15% to 30%
In March we argued that large organisations had hardened their own estates and relocated their residual risk onto their suppliers' balance sheets. This is that argument, measured independently, one quarter later. A risk that doubles in twelve months cannot be governed by an instrument that samples annually.
The remote access edge is now confirmed by three separate datasets
Edge devices and VPNs as a target of vulnerability exploitation rose to 22%, almost eight-fold from 3%. X-Force puts exploitation of public-facing applications at 30% of initial access, tied with valid accounts, with external remote services adding 11%. Our March reading called this the dominant door; three independent telemetries now say so.
The binding constraint moved from detection to visibility
Mandiant could not determine the initial infection vector in 34% of its 2024 investigations, and 57% of organisations first learned of their own compromise from an external source. When the adversary notifies you in a median of five days and your partners take 26, the problem is not that alerts are missing. It is that the evidence needed to reconstruct what happened was never collected.
The quarter in numbers
44%
Share of breaches involving ransomware, up from 32%
Measured across more than 12,000 breaches, and counted with or without encryption. The category grows while the technique inside it changes.
64%
Victims refusing to pay the ransom
Roughly 50% in 2022. The clearest evidence available that defensive investment produces a result measurable in money.
$115,000
Median ransom paid, down from $150,000
Total payments are down 35% on blockchain analysis. A falling price against rising volume is the definition of a repriced market.
30%
Breaches involving a third party, doubled from 15%
The supply chain stopped being a governance topic and became a measured breach statistic, in twelve months.
22%
Edge devices and VPNs as a target of vulnerability exploitation
Almost eight-fold from 3%, the sharpest single-year movement in the dataset, and an independent confirmation of our March reading.
$16.6 bn
Cybercrime losses reported to the FBI in 2024, up 33%
A record, across 859,532 complaints. Investment fraud and business email compromise drive it, not extortion.
34%
Intrusions whose initial vector could not be determined
A third of investigations cannot say how the attacker got in. That is a logging problem, not a detection problem.
57%
Organisations told of their own breach by an outsider
The adversary notifies in a median of five days, external partners in 26. Most organisations still learn of their worst day from someone else.
The board agenda
Five questions your board should be able to answer this quarter
They follow directly from the findings above. The full edition carries, for each one, the evidence behind it and the prioritised action that answers it.
If we were breached today, could we establish how they got in?
34% of investigations cannot.
Would we learn of our own compromise from inside or outside?
57% learn from outside.
How many of our suppliers could reach our data, and when did we last look at their exposure rather than their answers?
Third-party involvement doubled to 30%.
What is our maximum patch interval on internet-facing appliances, and who accepted it?
60% of top vulnerabilities have a public exploit within two weeks.
Who owns payment fraud in this organisation: finance, security, or nobody?
$2.8B in reported BEC losses.
Want to see what changed this quarter, the trend radar, the FortaRisks point of view and what we are watching next?
The executive perspective above is the opening of the report. The complete edition carries the analysis and the recommendations that follow from it.
What the full edition adds
- What changed this quarter, and what only looks new
- Trend radar: direction, maturity and business impact
- The FortaRisks point of view, four convictions
- Looking ahead, next 3 to 6 months, with confidence levels
- The threat landscape, developments in detail
- Sector exposure, with OT and manufacturing broken out
- Prioritised recommendations, by theme and by risk addressed
- The prioritised action answering each question above, plus the source base and method
16 pages · 13 sources · immediate download, no wait
How this edition was built
This edition draws on the executive and annual reports published by leading consulting, research and cybersecurity firms up to the cut-off date, read against FortaRisks Research analysis and our own cyber threat intelligence. Four major sources published since the March cut-off inform it, held against the nine behind the opening edition. It also scores the five forecasts we made in March: two materialised, one partially, two are too early to judge.
Every figure on this page appears in the full edition with its source, its data period and its methodological limits. A source is admitted only when its publication date precedes the documentary cut-off, so a historical edition never draws on research that did not yet exist. Where two independent datasets disagree, we report both rather than selecting one. The reading, the cross-source synthesis and the conclusions are FortaRisks Research's own, informed by the threat intelligence we operate.
See where your organisation sits on these numbers
The report says what is happening across the market. A 30-minute demo says what is happening on your attack surface.