96 percent of ransomware cases included data theft

New research reveals evolving threat tactics, the rising role of business email compromise, and the importance of proactive security measures.

  • Thursday, 27th February 2025 Posted 3 months ago in by Phil Alsop

Arctic Wolf has released its annual Arctic Wolf Threat Report, offering an in-depth analysis of the evolving cyber threat landscape. This year’s findings underscore how cybercriminals are adapting their methods to bypass stronger security defences—prioritising data theft, refining business email compromise (BEC) scams, and exploiting known vulnerabilities to infiltrate organisations worldwide.

Leveraging insights from Arctic Wolf’s incident response (IR) engagements, threat intelligence research, and telemetry from the Arctic Wolf Aurora Platform, the report provides a detailed examination of the tactics, techniques, and procedures (TTPs) attackers are using to out-manoeuvre traditional defences. It also offers actionable recommendations for organisations looking to enhance their cybersecurity resilience, taking advantage of the report’s description of the current threat landscape.

“The 2025 Arctic Wolf Threat Report highlights a critical shift in cybercriminal behaviour: data exfiltration has become the norm, not the exception,” said Kerri Shafer-Page, vice president of incident response, Arctic Wolf. “Threat actors are no longer just locking up data with ransomware; they’re stealing it first to maximise pressure on victims. The insights help organisations understand the risks they face today and shape the advanced detection and response strategies embedded within the Arctic Wolf Aurora Platform to keep our customers secure.”

Key findings from the 2025 Arctic Wolf Threat Report include:

• Steal first, extort second. As organisations improve their ability to recover from ransomware, cybercriminals have turned to data exfiltration to increase leverage—96% of ransomware cases analysed included data theft.

• The cybercrime trifecta. Three types of cybersecurity incidents account for 95% of all incident response (IR) cases: ransomware 44%, business email compromise (BEC) 27%, and intrusions 24%.

• Threat actors follow the money. BEC continues to grow as a preferred tactic, particularly in the finance and insurance sector, where it accounted for 53% of IR cases—making it the only industry where BEC outpaced ransomware.

• Patch or pay. In 76% of intrusion cases, attackers exploited just 10 specific vulnerabilities—none of which were zero-days, and most linked to remote access tools and externally facing services. This reinforces the need for proactive patch management.

• Ransomware’s price tag: $600K. Median ransom demands remain high at $600,000 USD, demonstrating that ransomware remains a lucrative business for cybercriminals despite increased law enforcement action.

• Never split the difference. The Arctic Wolf Incident Response Team helped reduce aggregate ransom demands by 64%, and 70% of clients using Arctic Wolf’s negotiation services avoided paying ransoms altogether.

The 2025 Arctic Wolf Threat Report brings together Arctic Wolf’s top security minds—from incident responders and researchers to data scientists and engineers—to provide a comprehensive analysis of today’s evolving cyber threat landscape. This essential resource helps security, IT, and business leaders anticipate threats, strengthen defences, and stay ahead of adversaries. Powered by insights from the Arctic Wolf Aurora Platform and backed by security operations expertise from one of the world’s largest commercial Security Operations Centres (SOCs), Arctic Wolf delivers the intelligence and defence organisations need to proactively detect, respond to, and remediate cyber threats.

Why most businesses aren’t yet winning with AI

Posted 1 day ago by Phil Alsop
71% of business leaders say their workforces are not ready to successfully leverage AI.
Five9 has released its 2025 Business Leaders Customer Experience Report offering analysis of CX trends shaping how global business leaders create...
Delinea has unveiled new research highlighting how ransomware attacks have continued to surge over the past year, despite fewer victims paying. Over...
96% of tech professionals view AI agents as a growing security risk, yet 98% of organisations plan to expand adoption.

Opportunities to optimise ServiceNow operations

Posted 1 day ago by Phil Alsop
xtype’s 2025 State of ServiceNow Operations Report identifies key optimisation areas as organisations expand their ServiceNow implementations.

AI is now the leading security concern

Posted 6 days ago by Phil Alsop
AI surpasses ransomware as the top concern, as organizations navigate the double-edged sword of innovation and risk.

Workforce crisis sparks debate over HR & IT merger

Posted 6 days ago by Phil Alsop
New study of global tech leaders finds IT leaders believe combining functions could boost productivity and engagement.
Cyware survey identifies significant gaps in internal collaboration, tool integration, and automation — with only 13% confident their systems...