Every defensive number improved. Attack volume roughly doubled. Both are true.
For the first time in five years the average breach cost fell and encryption reached a six-year low. Over the same window, blocked attempts rose 145.9%, exfiltration 92.7% and public extortion 70.1%. These are not contradictory findings.
- Published
- September 23, 2025
- Period covered
- July 1, 2025 – September 30, 2025
- Documentary cut-off
- September 23, 2025
Executive perspective
Six conclusions that matter for the year ahead
Breach costs fell for the first time in five years
The global average dropped to USD 4.44 million, and IBM attributes it to faster containment. Defence is now producing a measurable, repeatable financial result. This is the second consecutive quarter in which the clearest evidence in the field is evidence that preparation works.
Ransomware encryption is collapsing as a technique
Half of attacks now result in encrypted data, down from 70% a year earlier and the lowest in six years. The median demand fell 34% to $1.32 million and the median payment fell 50% to $1 million. Sixty-three percent of organisations refused to pay, corroborating the 64% the DBIR reported last quarter from a separate dataset.
Volume and data theft replaced it, exactly as the arithmetic required
Zscaler blocked more than 10.8 million ransomware attempts between April 2024 and April 2025, a 145.9% increase and the largest spike in three years. Exfiltration across ten major families rose 92.7% to 238.5 terabytes. Public extortion cases rose 70.1%. In June we forecast escalation in pressure rather than in price. This is that, measured.
Canada is now the second most-targeted country in the world
The United States absorbs 50.8% of ransomware attacks; Canada follows, ahead of the United Kingdom, Germany and India. For a Canadian mid-market organisation this is the single most important line in this edition, and it means the honest benchmark is American rather than international.
The AI exposure is an access-control problem, not an adversary problem
Ninety-seven percent of organisations reporting an AI-related breach lacked proper access controls on the system involved, and 63% have no AI governance policy at all. We have argued since March that AI's measurable security cost sits on the adoption side. This is that argument with a number on it.
Cloud intrusion is accelerating faster than anything else we track
CrowdStrike observed a 40% rise over twelve months, and a 136% rise in the first half of 2025 alone compared with all of 2024. We had marked this trend stable in two previous editions. The share of incidents was stable; the count was not, and we have corrected the method.
The quarter in numbers
$4.44 M
Global average cost of a data breach
The first decline in five years, attributed to faster containment. The clearest indicator that defensive investment returns money.
50%
Attacks that result in encrypted data, down from 70%
The lowest in six years. The technique that defines the category is being abandoned, not defeated.
+145.9%
Ransomware attempts blocked, April 2024 to April 2025
More than 10.8 million, the largest spike in three years. Volume is the compensation for falling yield.
+92.7%
Data exfiltration volume across ten major ransomware families
238.5 terabytes stolen. Theft has replaced encryption as the primary source of leverage.
+70.1%
Public extortion cases published on leak sites
Reputational and regulatory pressure now does the work encryption used to do, on the attacker's timetable.
2nd
Canada's rank among the world's most-targeted countries
Behind the United States at 50.8%, ahead of the United Kingdom, Germany and India. Not a peripheral market.
97%
AI-related breaches where the AI system lacked proper access controls
With 63% of organisations holding no AI governance policy. The AI security problem, measured, is an access problem.
+136%
Cloud intrusions in the first half of 2025 against all of 2024
The fastest-moving line in this edition, and one we previously mismeasured by reporting share instead of count.
The board agenda
Five questions your board should be able to answer this quarter
They follow directly from the findings above. The full edition carries, for each one, the evidence behind it and the prioritised action that answers it.
Which AI systems hold or reach our sensitive data, and who reviewed their access last?
97% of AI breaches lacked access controls.
If nothing were encrypted and everything were published, who would speak, and when?
Public extortion cases up 70.1%.
How many cloud intrusions would we detect on the control plane rather than the endpoint?
Cloud intrusion up 136% in six months.
Are we resourced against a global average or against the second most-targeted country on earth?
Canada ranks second.
Where do we still accept a voice as proof of identity?
One fraudulent call in 599.
Want to see what changed this quarter, the trend radar, the FortaRisks point of view and what we are watching next?
The executive perspective above is the opening of the report. The complete edition carries the analysis and the recommendations that follow from it.
What the full edition adds
- What changed this quarter, and what only looks new
- Trend radar: direction, maturity and business impact
- The FortaRisks point of view, four convictions
- Looking ahead, next 3 to 6 months, with confidence levels
- The threat landscape, developments in detail
- Sector exposure, with OT and manufacturing broken out
- Prioritised recommendations, by theme and by risk addressed
- The prioritised action answering each question above, plus the source base and method
15 pages · 16 sources · immediate download, no wait
How this edition was built
This edition draws on the executive and annual reports published by leading consulting, research and cybersecurity firms up to the cut-off date, read against FortaRisks Research analysis and our own cyber threat intelligence. It scores the five forecasts made in June: three materialised or close to it, one directionally supported, one unresolved for want of data. It also corrects a measurement error in our own two previous editions.
Every figure on this page appears in the full edition with its source, its data period and its methodological limits. A source is admitted only when its publication date precedes the documentary cut-off, so a historical edition never draws on research that did not yet exist. Where two independent datasets disagree, we report both rather than selecting one. The reading, the cross-source synthesis and the conclusions are FortaRisks Research's own, informed by the threat intelligence we operate.
See where your organisation sits on these numbers
The report says what is happening across the market. A 30-minute demo says what is happening on your attack surface.