Data-Leak Sites Surge to Record Levels Amid Scattered Spider RaaS and LockBit 5.0 Rise
## Cybersecurity Update: Q3 2025 Ransomware Developments
Cybersecurity Update: Q3 2025 Ransomware Developments
In the third quarter of 2025, ransomware threats reached significant levels, with active data-leak sites increasing to 81 platforms. This rise was influenced by notable developments within the cybersecurity landscape.
The hacking group Scattered Spider revealed plans for its first ransomware-as-a-service (RaaS) platform, "ShinySp1d3r RaaS." This development marks a shift in the ransomware landscape, with English-speaking groups challenging the dominance of traditionally Russian-led RaaS providers.
Scattered Spider, known for its phishing and social-engineering expertise, aims to combine these skills with their new RaaS platform, potentially altering the competitive dynamics in the ransomware market.
LockBit 5.0 and Critical Infrastructure
On September 3, 2025, LockBit announced the release of LockBit 5.0, allowing affiliates to target critical infrastructure, including power plants. This move indicates a shift in focus and strategy, potentially increasing risks to essential services.
In the third quarter of 2025, ransomware threats reached significant levels, with active data-leak sites increasing to 81 platforms.
The new version seeks to reestablish LockBit as a leading ransomware threat by expanding target options and addressing affiliates' trust issues.
A coalition formed between LockBit, DragonForce, and Qilin aims to share resources and tactics, promoting the use of double-extortion schemes and broadening attack scopes. This alliance highlights a strategic shift to more coordinated ransomware operations.
Data-leak sites increased from 72 in Q2 to 81 in Q3 2025, with emerging groups like Beast and Cephalus driving a rise in healthcare sector listings. Notably, Thailand experienced a 69% surge, influenced by the new group Devman2.
These developments indicate a rapidly evolving ransomware landscape, characterized by new entrants, strategic alliances, and expanding geographical targets. Organizations are advised to enhance security measures, focusing on social engineering defenses, network segmentation, and rapid incident response to mitigate these threats.
Based on reporting by GBHackers.
