Hacker News Viewer

7,655 Ransomware Claims in One Year: Group, Sector, and Country Breakdown

by adulion on 3/31/2026, 10:02:34 AM

https://ciphercue.com/blog/7655-ransomware-claims-march-2025-to-march-2026

Comments

by: wongarsu

&gt; 141 countries appeared in the dataset. US organisations are the most frequent targets at 40%, but the remaining 60% spans six continents. European subsidiaries, APAC operations, and Latin American offices are all represented<p>Love how this subtly implies that only the US has independent companies, every other region just has subsidiaries and branch offices of US companies

3/31/2026, 11:41:35 AM


by: jstanley

&gt; Of 129 active groups, the top five posted 3,027 of the 7,655 claims (40%). After them, the field fragments quickly.<p>Does it?<p>The 4th group accounted for 5.0%, 5th was 4.5%, 6th was 3.4% and 10th was 2.5%, I think it doesn&#x27;t fragment particularly any more quickly after the top 5 than within the top 5.<p>Is this LLM analysis?

3/31/2026, 10:58:25 AM


by: gebalamariusz

The 40% acceleration in the second half is the number that jumps out. That is not just &quot;more groups&quot;, something changed operationally in the ecosystem around September 2025.<p>SafePay dominating Germany with 72 claims is worth watching. Most ransomware analysis focuses on US-heavy groups, but a group concentrating on a single non-US market suggests either language capability, specific supply chain access, or targeting of regulatory environments where disclosure pressure increases payment rates. Germany&#x27;s strict GDPR enforcement could make the threat of a leak more effective than in markets where fines are lower.<p>The 35% of claims with no sector attribution is a significant gap. If those ~2700 unattributed claims skew toward smaller organizations without public sector classification, the actual concentration in SMB targets could be much higher than the data shows.<p>The point about ecosystem resilience is the most important takeaway for defenders. 129 active groups means the threat model is not &quot;prevent group X&quot; but &quot;assume breach and limit blast radius.&quot; That shifts investment from detection toward segmentation, backup isolation, and recovery speed.

3/31/2026, 11:14:24 AM