Semperis, a provider of AI-powered identity security and cyber resilience, today published the results of a global ransomware study of nearly 1,500 organisations in a variety of industries that aims to understand their experience with ransomware over the last 12 months. The study shows hackers are relentless and ransomware is still a global epidemic. In fact, in 40% of attacks, threat actors threatened to physically harm executives at organisations that declined to pay a ransom demand.
The 2025 Ransomware Risk Report: Essential Guidance for Building Operational Resilience Against Cyberattacks found that UK organisations are being targeted more than most other countries (84%), and around half of those attacks (49%) are successful. While data erasure and release of sensitive data are the most common threats, 47% of attacked companies in the US, UK, France, Germany, Spain, Italy, Singapore, Canada, Australia and New Zealand also reported that hackers threatened to file regulatory complaints against them if they didn’t report the incident.
In comparing results from last year’s ransomware study, Semperis found slight decreases year over year in companies paying ransoms. Still, 69% of companies that were victimised by ransomware paid a ransom (a drop of 10 percentage points). However, UK government and public sector organisations are alarmingly more likely to pay: An overwhelming 83% paid the ransom, ahead of the planned ransomware payment ban. Globally, 38% of companies paid multiple ransoms and 11% of companies paid three times or more.
Former US National Cyber Director and Semperis Strategic Advisor Chris Inglis suggests that now is not the time for companies to get a false sense of security. He says, “Now is not the time for complacency. True regret isn’t knowing what you should have done; it’s not having done what you knew was needed and had the means to do.”
The Ransomware Scourge
Ransomware attacks continue to be highly coordinated, strategically timed and deeply embedded throughout systems before they are executed. This gives multiple attackers access to multiple operational systems — so they can execute multiple strikes. Organisations must be on continual alert, always ready for the success of not one, but multiple breaches.
The findings indicate that ransomware attacks are frequent, with 50% of respondents citing cybersecurity threats as the top threat to business resilience. The top cybersecurity challenge facing organisations is the sophistication of attacks (37%), while for 32% it is attacks against organisations’ identity infrastructure, most commonly Active Directory. Nearly 20% of companies that paid a ransom either received corrupt decryption keys that were unusable or the hackers still published stolen data after stating they would not.
“Paying ransoms should never be the default option. While some circumstances might leave the company in a non-choice situation, we should acknowledge that it’s a downpayment on the next attack. Every dollar handed to ransomware gangs fuels their criminal economy, incentivising them to strike again. The only real way to break the ransomware scourge is to invest in resilience, creating an option to not pay ransom,” said Mickey Bresman, CEO of Semperis.
What can organisations do to build on successes and increase their resilience against ransomware?
First, organisations should evaluate the security of partners and supply chain vendors as they could be the weakest link. When partners and vendors have access to sensitive systems and data, risk increases. Organisations should also be prepared for changing tactics in ransomware development and deployment, and plan regular tabletop exercises to improve ransomware response.
Jen Easterly, the former Director of the Cybersecurity and Infrastructure Agency (CISA) believes there are signs of defenders increasingly winning battles in the ransomware fight with criminal enterprises. “I believe that we can make ransomware a shocking anomaly. And that is the world I want to live in: A world where software vulnerabilities are so rare that they make the nightly news, not the morning meeting. A world where cyberattacks are as infrequent as plane collisions. I do believe we can get there.”
The full ransomware study can be obtained here: 2025 Ransomware Risk Report: Essential Guidance for Building Operational Resilience Against Cyberattacks. Semperis is dedicated to helping global organisations defend against cyberattacks of their hybrid identity systems, including Active Directory and Entra ID.
About Semperis
Semperis protects critical enterprise identity services for security teams charged with defending hybrid and multi-cloud environments. Purpose-built for securing hybrid identity environments—including Active Directory, Entra ID, and Okta—Semperis’ AI-powered technology protects over 100 million identities from cyberattacks, data breaches, and operational errors.
As part of its mission to be a force for good, Semperis offers a variety of cyber community resources, including the award-winning Hybrid Identity Protection (HIP) Conference, HIP Podcast, and free identity security tools Purple Knight and Forest Druid. Semperis is a privately owned, international company headquartered in Hoboken, New Jersey, supporting the world’s biggest brands and government agencies, with customers in more than 40 countries.
Learn more: https://www.semperis.com