TechForge

May 27, 2025

  • Ransomware attacks dropped 31%, but Akira and Scattered Spider still active.
  • Retail and industrial firms hit hardest, mostly in US.

Ransomware attacks went down in April, with 416 cases reported. That’s a 31% drop from March, marking the second month in a row with falling numbers of incidents. While the slowdown offers some relief, it doesn’t mean attackers are backing off, preferring instead to go after high-value targets using more focused tactics.

Retailers in the UK were among the hardest hit in April. Well-known names like the Co-op, M&S, and Harrods were affected by ransomware incidents that caught public attention. Even though the total number of attacks in the Consumer Discretionary sector dropped, the impact of those that did occur was hard to ignore.

Retail remains an attractive target for attackers. The disruption of operations, especially payment systems, can cause chaos. There’s also customer data at stake, which can be valuable on black markets. These factors often impel companies to pay up quickly, and is most likely why attackers keep circling back.

The group behind some of the UK’s retail attacks, Scattered Spider, has been vocal about its role. It’s been publicising the breaches, adding pressure on victims and boosting its profile. That kind of attention can encourage copycats or help other attackers plan similar strikes.

Akira takes the lead

April saw Akira become the most active ransomware group, taking the top spot with 65 attacks. That’s a small jump from the previous month but enough to push it ahead of other groups in terms of numbers of incidents.

Qilin followed closely with 49 incidents, while Play came in third with 42.

One group that stood out for a different reason was Babuk2. It had dominated the cybersecurity scene in March with 84 attacks but dropped its number of attacks in April, logging only 16. Some in the cybersecurity community have questioned whether Babuk2 is really connected to the original Babuk group.

Industrial firms remain prime targets

The industrial sector continues to draw attention from attackers. In April, it accounted for nearly one-third of all ransomware cases, with 133 attacks, the highest of any sector.

Consumer Discretionary, despite the high-profile retail hits, came second with 73 attacks. That’s down from 124 in March. Its broad supply chains and access to personal data make it a consistent target.

North America hit the hardest

More than half of the global ransomware attacks in April – 211 cases – took place in North America. That number points to ongoing pressure in the region, where political tension and economic issues could be giving attackers more reasons to strike. With new tariffs announced last month, some experts believe financial motives and cyber espionage are likely to rise.

Europe saw 110 attacks, or about 27% of the total, followed by Asia with 51 (12%) and South America with 21 (5%).

New threats: Weaponised PDFs

Attackers are also finding new ways to break into systems. One growing trend is the use of weaponised PDFs. Such files may look harmless but can carry malware designed to sneak past security tools or trick users into clicking links or downloading infected content.

Some attackers use fake documents tailored to a specific company or person. These often rely on social engineering tricks and can use zero-day flaws – security gaps that haven’t yet been patched. Once opened, the file might quietly install software that gives hackers access to sensitive systems or data.

The rise of AI is adding a new layer to these attacks. It’s helping attackers create more convincing phishing overture messages, fake documents or emails, making it harder for people to tell what’s real. At the same time, the line between work and personal devices is getting more blurred, especially with remote work now common.

Matt Hull, Head of Threat Intelligence at NCC Group, said the drop in reported ransomware victims should not be mistaken for a declining threat.

“The recent attacks on the UK retail sector have laid bare just how disruptive and far-reaching these incidents can be. The reality is that this is only a glimpse of the broader threat landscape. Globally, many ransomware cases still fly under the radar, are under-reported or deliberately kept quiet.”

It’s worth noting that the statistics quoted above represent only those where the victim or perpetrator have made an attack’s existence public. Many other attacks take place and are successful (from the attacker’s point of view), but are not declared by the victim for fear of loss of brand value, or alarming customers.

“Geopolitical and economic uncertainty is also adding fuel to the fire,” Mike said, “providing more lucrative targets and opportunities for attackers to strike.”

“In this climate, a strong and embedded security culture is no longer optional; it is a critical enabler of organisational resilience. It’s more important than ever for organisations to maintain a strong security culture, respond quickly to emerging threats, and adapt to shifting tactics – all the while staying ahead of adversaries that never stop evolving.”

Author

  • As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

    View all posts

About the Author

Muhammad Zulhusni

As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

Related

August 11, 2026

August 10, 2026

August 5, 2026

July 30, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

12345 view(s)
11326 view(s)
7643 view(s)
6152 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.
Name(Required)