logo
Coveware by Veeam Reveals Q2 2025 Ransomware Surge: Social Engineering and Data Exfiltration Drive Record Payouts

Coveware by Veeam Reveals Q2 2025 Ransomware Surge: Social Engineering and Data Exfiltration Drive Record Payouts

Business Wire4 days ago
SEATTLE--(BUSINESS WIRE)-- Coveware by Veeam ®, the leading authority in ransomware response and cyber extortion trends, today unveiled its Q2 2025 ransomware report, spotlighting a dramatic escalation in targeted social engineering attacks and a surge in ransom payments driven by sophisticated data exfiltration tactics.
'The second quarter of 2025 marks a turning point in ransomware, as targeted social engineering and data exfiltration have become the dominant playbook,' said Bill Siegel, CEO of Coveware by Veeam.
'The second quarter of 2025 marks a turning point in ransomware, as targeted social engineering and data exfiltration have become the dominant playbook,' said Bill Siegel, CEO of Coveware by Veeam. 'Attackers aren't just after your backups – they're after your people, your processes, and your data's reputation. Organizations must prioritize employee awareness, harden identity controls, and treat data exfiltration as an urgent risk, not an afterthought.'
Key Q2 2025 findings from Coveware by Veeam include:
Social Engineering Drives the Biggest Threats: Three major ransomware groups – Scattered Spider, Silent Ransom, and Shiny Hunters – dominated the quarter, each leveraging highly targeted social engineering to breach organizations across sectors. These groups abandoned mass opportunistic attacks for precision strikes, using novel impersonation tactics against help desks, employees, and third-party service providers.
Ransom Payments Soar to New Highs: Both the average and median ransom payments rocketed to $1.13 million (+104% from Q1 2025) and $400,000 (+100% from Q1 2025), respectively. This spike is attributed to larger organizations paying out after data exfiltration-only incidents, even as the overall rate of organizations paying ransoms held steady at 26%.
Data Theft Overtakes Encryption as Primary Extortion Method: Exfiltration was a factor in 74% of all cases, with many campaigns now prioritizing data theft over traditional system encryption. Multi-extortion tactics and delayed threats are on the rise, keeping organizations in the crosshairs long after an initial breach.
Professional Services, Healthcare, and Consumer Services Hit Hardest: Professional services (19.7%), healthcare (13.7%), and consumer services (13.7%) bore the brunt of attacks. Mid-sized companies (11 – 1,000 employees) comprised 64% of victims, a sweet spot for attackers balancing payout potential against less mature defenses.
Attack Techniques Evolve, Human Factor Remains Key Vulnerability: Credential compromise, phishing, and exploitation of remote services continue to dominate initial access, with attackers increasingly bypassing technical controls via social engineering. Groups regularly exploit vulnerabilities in widely-used platforms (Ivanti, Fortinet, VMware), and 'lone wolf' attacks by seasoned extortionists using generic, unbranded toolkits are on the rise.
New Entrants Reshape Ransomware Rankings: Q2's top ransomware variants were Akira (19%), Qilin (13%), and Lone Wolf (9%), while Silent Ransom and Shiny Hunters entered the top five for the first time.
Coveware by Veeam has helped thousands of cyber extortion victims and developed industry leading software and services that enable rapid forensic triage, extortion negotiation and remediation, cryptocurrency settlements and decryption services with a singular goal and outcome - data recovery from ransomware attacks. Through these incidents, Coveware by Veeam has gathered data and insights on threat actor patterns that provide an unrivaled view of the current threat landscape. These valuable findings are shared with customers to help educate and reduce risks, improve security posture, and ensure rapid recovery. Select Coveware by Veeam capabilities are incorporated into Veeam offerings including Veeam Data Platform and the Veeam Cyber Secure Program, delivering the insights and capabilities to a broader set of customers.
Coveware by Veeam's quarterly report is based on firsthand data, expert insights and analysis from the ransomware and cyber extortion cases that they manage each quarter. By utilizing real-time incident response, proprietary forensic tools (including Recon Scanner), and comprehensive documentation of threat actor behavior, attack vectors, and negotiation outcomes, Coveware by Veeam delivers unparalleled visibility into the threat landscape. By aggregating and analyzing case-specific data – rather than relying on third-party sources – Coveware by Veeam is able to identify emerging trends, track tactics, techniques, and procedures (TTPs), and provide actionable, experience-based intelligence on the rapidly evolving ransomware landscape.
To learn more on this latest report from Coveware by Veeam, read the blog post. For more information on Veeam, visit https://www.veeam.com.
About Veeam Software
Veeam®, the #1 global market leader in data resilience, believes every business should be able to bounce forward after a disruption with the confidence and control of all their data whenever and wherever they need it.​ Veeam calls this radical resilience, and we're obsessed with creating innovative ways to help our customers achieve it.
Veeam solutions are purpose-built for powering data resilience by providing data backup, data recovery, data portability, data security, and data intelligence. ​With Veeam, IT and security leaders rest easy knowing that their apps and data are protected and always available across their cloud, virtual, physical, SaaS, and Kubernetes environments.
Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, including 67% of the Global 2000, that trust Veeam to keep their businesses running. ​Radical resilience starts with Veeam. Learn more at www.veeam.com or follow Veeam on LinkedIn @veeam-software and X @veeam.
Frequently Asked Questions:
What are the biggest ransomware threats facing organizations in 2025?
According to the latest report from Coveware and Veeam, the main threats are targeted social engineering attacks and data exfiltration, led by groups like Scattered Spider, Silent Ransom, and Shiny Hunters.
Which industries and company sizes are most impacted by ransomware attacks?
The latest report from Coveware and Veeam found professional services, healthcare, and consumer services firms are most targeted. Mid-sized companies (11–1,000 employees) make up 64% of victims due to less mature defenses.
How have ransomware techniques evolved in 2025?
The latest report from Coveware and Veeam found that attackers now focus on credential compromise, phishing, and exploiting remote services. Social engineering is a key weakness, and there's a rise in 'lone wolf' attacks using generic toolkits and vulnerabilities in platforms like Ivanti, Fortinet, and VMware.
How can organizations strengthen their defenses against ransomware?
Coveware by Veeam advises boosting employee security awareness, hardening identity controls, and urgently addressing data exfiltration risks. Using Veeam's resilience and recovery solutions helps reduce risk and maintain business continuity.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

FUN Investors Have Opportunity to Join Six Flags Entertainment Corporation Fraud Investigation With the Schall Law Firm
FUN Investors Have Opportunity to Join Six Flags Entertainment Corporation Fraud Investigation With the Schall Law Firm

Business Wire

time2 hours ago

  • Business Wire

FUN Investors Have Opportunity to Join Six Flags Entertainment Corporation Fraud Investigation With the Schall Law Firm

LOS ANGELES--(BUSINESS WIRE)-- The Schall Law Firm, a national shareholder rights litigation firm, announces that it is investigating claims on behalf of investors of Six Flags Entertainment Corporation ('Six Flags' or 'the Company') (NYSE: FUN) for violations of the securities laws. The investigation focuses on whether the Company issued false and/or misleading statements and/or failed to disclose information pertinent to investors. Six Flags announced its Q2 2025 financial results on August 6, 2025. The Company swung from a profit to a $100 million dollar loss for the quarter, and cut its full year guidance. The Company blamed bad weather for the downturn but also indicated lower sales of season passes contributed to poor results. Finally, the Company's CEO will step down at the end of the year. If you are a shareholder who suffered a loss, click here to participate. We also encourage you to contact Brian Schall of the Schall Law Firm, 2049 Century Park East, Suite 2460, Los Angeles, CA 90067, at 310-301-3335, to discuss your rights free of charge. You can also reach us through the firm's website at or by email at bschall@ The Schall Law Firm represents investors around the world and specializes in securities class action lawsuits and shareholder rights litigation. This press release may be considered Attorney Advertising in some jurisdictions under the applicable law and rules of ethics.

CUPE: Liberals reward Air Canada's refusal to bargain fairly by crushing flight attendants' Charter rights
CUPE: Liberals reward Air Canada's refusal to bargain fairly by crushing flight attendants' Charter rights

Business Wire

time5 hours ago

  • Business Wire

CUPE: Liberals reward Air Canada's refusal to bargain fairly by crushing flight attendants' Charter rights

TORONTO--(BUSINESS WIRE)--Air Canada asked the government to crush underpaid flight attendants' Charter rights, and Jobs Minister Patty Hajdu only waited a few hours to deliver. The Liberal government has invoked Section 107 of the Canada Labour Code to end a strike by Air Canada flight attendants fighting to end unpaid work and poverty wages. "The Liberals have talked out of both sides of their mouths. They said the best place for this is at the bargaining table. They refused to correct this historic injustice through legislation," said Wesley Lesosky, President of the Air Canada Component of CUPE. "Now, when we're at the bargaining table with an obstinate employer, the Liberals are violating our Charter rights to take job action and give Air Canada exactly what they want — hours and hours of unpaid labour from underpaid flight attendants, while the company pulls in sky-high profits and extraordinary executive compensation." CUPE came to the table with data-driven and reasonable proposals for a fair cost-of-living wage increase and an end to forced unpaid labour. Air Canada responded by sandbagging the negotiations. The Liberal government is rewarding Air Canada's refusal to negotiate fairly by giving them exactly what they wanted. This sets a terrible precedent. Contrary to the Minister's remarks, this will not ensure labour peace at Air Canada. This will only ensure that the unresolved issues will continue to worsen by kicking them down the road. Nor will it ensure labour peace in this industry — because unpaid work is an unfair practice that pervades nearly the entire airline sector, and will continue to arise in negotiations between flight attendants and other carriers.

'This government is anti-union and anti-worker': CUPE NS Denounces Use of Bill 107
'This government is anti-union and anti-worker': CUPE NS Denounces Use of Bill 107

Business Wire

time5 hours ago

  • Business Wire

'This government is anti-union and anti-worker': CUPE NS Denounces Use of Bill 107

HALIFAX, Nova Scotia--(BUSINESS WIRE)--CUPE Nova Scotia strongly condemns the federal government's decision to interfere in workers' right to collective bargaining and job action by invoking Section 107 of the Canada Labour Code. 'Clearly, this government is anti-union and anti-worker,' said Alan Linkletter, CUPE Nova Scotia President. 'Forcing workers back on the job instead of supporting free and fair collective negotiations directly contradictions workers' rights that are guaranteed under the Canadian Charter of Rights and Freedoms.' Air Canada has asked the government to crush striking workers' Charter rights, and Federal Labour minister Patty Hajdu is ready to deliver. Hajdu announced that the federal government will be invoking Section 107 at a press conference this afternoon, citing the financial welfare of Canadians and the economy at large as a deciding factor for this decision. 'She says this move is for the financial security of Canadians—are these workers not Canadians? Does their welfare not matter? How can you be financially secure when you don't even get paid for all of the hours you work?' Contrary to the Minister's remarks, this will not ensure labour peace in Canada. This will only push this fight onto the next group of workers in negotiations, while Air Canda's flight attendants continue to work for a billion-dollar company for free. Flight attendants are only paid when the plane is moving, and work as many as 35 unpaid hours a month performing vital duties that ensure the safe and smooth operation of each flight. Now, instead of paying flight attendants for all the hours they work, Air Canada has clearly sought help from the federal government to continue exploiting their employees. 'Minister Hajdu's comments indicate a clear lack of respect for workers' rights,' said Sherry Hillier, President of CUPE Newfoundland and Labrador and National General Vice President for Atlantic Canada. 'By using Section 107 to force workers back on the job yet again, they're setting a pattern. And that pattern is that Liberals don't care about Canadians.' Recent polling data indicates that 9 out of 10 Canadians support Air Canada flight attendants' fight for fair pay. 88% per cent of Canadians believe flight attendants should be paid for all work-related duties including boarding, delays, and safety checks. 76% support raising their pay to reflect the important safety role they play. 59% believe the federal government should respect flight attendants' right to take job action–even if it causes travel disruptions. CUPE represents over 10,000 Air Canada flight attendants across the country, and workers have been demonstrating at Halifax Stanfield International Airport since 6AM. 'Messages of support have been pouring in for these workers from across the country,' continued Linkletter. 'Canadians stand with us. Our elected representatives should, too.'

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store