CIO Influence
CIO Influence News Machine Learning Security

Semperis 2025 Ransomware Study Reveals Relentless Cyberattacks on Global Organizations

Semperis 2025 Ransomware Study Reveals Relentless Cyberattacks on Global Organizations

Semperis - Cybersecurity Excellence Awards

Study shows many companies paid multiple ransoms in the past 12 months. Victims also report that hackers have threatened to physically harm executives and file regulatory complaints against their companies.

Semperis, a provider of AI-powered identity security and cyber resilience, published results of a global ransomware study of nearly 1,500 organizations in a variety of industries that aims to understand their experience with ransomware over the last 12 months. The study shows hackers are relentless and ransomware is still a global epidemic. In fact, in 40% of attacks, threat actors threatened to physically harm executives at organizations that declined to pay a ransom demand. US-based companies experienced physical threats 46% of the time, while 44% of German firms experienced similar forms of intimidation.

Theย 2025 Ransomware Risk Report: Essential Guidance for Building Operational Resilience Against Cyberattacksย found that 47% of attacked companies in the US, UK,ย France,ย Germany,ย Spain,ย Italy,ย Singapore,ย Canada,ย Australiaย andย New Zealandย reported that hackers threatened to file regulatory complaints against them if they didn’t report the incident. In the US, the rate jumped to 58%, a 23% increase, while inย Singaporeย the extortion threat surged to 66%, a jump of 40% and the highest of any country.

Also Read:ย CIO Influence Interview with Dipto Chakravarty, Chief Product and Technology Officer at Black Duck

In comparing results from last year’s ransomware study, Semperis found slight decreases year over year in companies paying ransoms. Still, 69% of companies that were victimized by ransomware paid a ransom. Unfortunately, 38% of companies paid multiple ransoms and 11% of companies paid three times or more. In the US, 47% of companies paid ransoms multiple times, while inย Singaporeย 50% of companies paid multiple times.

Former US National Cyber Director and Semperis Strategic Advisorย Chris Inglisย suggests that now is not the time for companies to get a false sense of security. He says, “Now is not the time for complacency. True regret isn’t knowing what you should have done; it’s not having done what you knew was needed and had the means to do.”

The Ransomware Scourge

Ransomware attacks continue to be highly coordinated, strategically timed and deeply embedded throughout systems before they are executed. This gives multiple attackers access to multiple operational systems โ€” so they can execute multiple strikes. Organizations must be on continual alert, always ready for the success of not one, but multiple breaches.

The findings indicate that ransomware attacks are frequent, with 50% of respondents citing cybersecurity threats as the top threat to business resilience. The top cybersecurity challenge facing organizations is the sophistication of attacks (37%), while next (32%) is attacks against organizations’ identity infrastructure, most commonly Active Directory. Nearly 20% of companies that paid a ransom either received corrupt decryption keys that were unusable or the hackers still published stolen data after stating they would not.

“Paying ransoms should never be the default option. While some circumstances might leave the company in a non-choice situation, we should acknowledge that it’s a downpayment on the next attack. Every dollar handed to ransomware gangs fuels their criminal economy, incentivizing them to strike again. The only real way to break the ransomware scourge is to invest in resilience, creating an option to not pay ransom,” saidย Mickey Bresman, CEO of Semperis.

Also Read:ย Scott Holden Joins Vanta as Chief Marketing Officer

What can organizations do to build on successes and increase their resilience against ransomware?

First, organizations should evaluate the security of partners and supply chain vendors as they could be the weakest link. When partners and vendors have access to sensitive systems and data, risk increases. Organizations should also be prepared for changing tactics in ransomware development and deployment and plan regular tabletop exercises to improve ransomware response.

Jen Easterly, the former Director of the Cybersecurity and Infrastructure Agency (CISA) believes there are signs of defenders increasingly winning battles in the ransomware fight with criminal enterprises. “I believe that we can make ransomware a shocking anomaly. And that is the world I want to live in: A world where software vulnerabilities are so rare that they make the nightly news, not the morning meeting. A world where cyberattacks are as infrequent as plane collisions. I do believe we can get there.”

[To share your insights with us as part of editorial or sponsored content, please write toย psen@itechseries.com]

Related posts

Airbiquity Joins AWS Partner Network

PR Newswire

Kivera Enters US Market with $3.5Million Seed Funding

Business Wire

Dremio Launches the Industryโ€™s First SQL Lakehouse Service to Accelerate BI and Analytics