Google Warns Ransomware Actors Are Shifting Tactics as Profits Fall and Data Theft Rises
## Cybersecurity: Ransomware Threat Landscape in 2025
Cybersecurity: Ransomware Threat Landscape in 2025
The ransomware landscape has evolved significantly in 2025, with a notable decline in ransom payment rates and average demands. Organizations have improved their recovery capabilities, impacting the traditional ransomware model.
In the fourth quarter of 2025, ransomware payment rates reached historically low levels. Average ransom demands fell from $2 million in 2024 to $1.34 million in 2025. The increase in recovery from backups has diminished the leverage of ransomware operators.
Despite financial declines, threat actors are adapting their tactics to enhance operational resilience and complicate extortion defenses. Google Cloud's Threat Intelligence Group identified these changes through investigations across multiple regions.
The REDBIKE ransomware family emerged as the most prevalent, accounting for 30% of incidents, surpassing previous leaders LOCKBIT and ALPHV.
Major Ransomware-as-a-Service (RaaS) operations, including LockBit and ALPHV, faced significant disruption due to law enforcement actions and internal issues. However, new groups such as Qilin and Akira have stepped in, increasing victim posts on data leak sites by 50% compared to 2024.
The ransomware landscape has evolved significantly in 2025, with a notable decline in ransom payment rates and average demands.
Threat actors are increasingly targeting smaller organizations with less robust security, moving away from large enterprises with mature defenses.
The Rise of Data Theft as an Extortion Method
Data exfiltration has become a primary extortion tactic, with 77% of ransomware intrusions involving data theft, up from 57% in the previous year. Attackers often steal sensitive files before encryption and threaten public exposure on leak sites.
Common tools used for exfiltration include Rclone, WinRAR, FileZilla, and cloud platforms like MEGA and OneDrive. These tools were frequently observed in 2025 incidents.
Organizations are advised to implement robust data loss prevention (DLP) controls, monitor outbound traffic, and restrict unauthorized tools. Keeping detailed logs of cloud storage access and endpoint activity can help detect exfiltration attempts early.
Guidance from the Ransomware Protection and Containment Strategies white paper is recommended for strengthening defenses and improving recovery preparedness.
Based on reporting by Cyber Security News.
