Ransomware Actors Targeting Global Public Sectors and Critical Infrastructure
The public sector is currently experiencing a significant cybersecurity challenge due to an increase in ransomware attacks targeting government entities worldwide.
The public sector is currently experiencing a significant cybersecurity challenge due to an increase in ransomware attacks targeting government entities worldwide.
Research from Trustwave's SpiderLabs indicates that nearly 200 public sector organizations have been affected by ransomware in 2025. Babuk and Qilin are identified as the leading groups responsible for these attacks on critical infrastructure and government services.
Data from Comparitech shows that ransomware attacks against government entities between 2018 and 2024 resulted in $1.09 billion in operational downtime costs. These attacks also lead to disruptions in essential services such as emergency response systems and public health portals, causing a loss of citizen trust and economic consequences.
Trustwave's data collection confirmed 196 public sector ransomware victims in the first seven months of 2025. Babuk2 is leading with 43 claimed victims, followed by Qilin with 21 attacks.
The United States reported 69 confirmed public sector ransomware incidents, the highest among affected countries. Additionally, Canada, the United Kingdom, and France reported 6-7 cases each, while India, Pakistan, and Indonesia reported 5 confirmed attacks each.
Research from Trustwave's SpiderLabs indicates that nearly 200 public sector organizations have been affected by ransomware in 2025.
Ransomware actors have developed new operational methods, moving beyond traditional file encryption to data extortion strategies. This involves stealing sensitive information and leveraging threats of public disclosure to compel payment, particularly effective against government entities.
The first half of 2025 saw a 47% increase in global ransomware incidents compared to the same period in 2024, with a 60% increase affecting government organizations.
Government entities faced the highest average ransom demands across all sectors, reaching $6.7 million during Q1 2025, with over 17 million records breached during this period.
Reasons for Targeting Government Entities
Public institutions are attractive targets for attackers due to the sensitive citizen data they hold, their essential services that cannot tolerate downtime, and often inadequate cybersecurity defenses.
Ransomware groups operating under the ransomware-as-a-service model find government targets to be high-impact and low-security, with a strong likelihood of ransom payments due to operational pressures.
Efforts to combat ransomware in the public sector require coordinated national action, combining robust technical controls with policy-level deterrence and international cooperation.
Based on reporting by GBHackers.
