A new report from Coveware by Veeam reveals a dramatic escalation in targeted attacks, with hackers increasingly using social engineering and data exfiltration to extort record-high ransom payments.
According to Bill Siegel, CEO of Coveware by Veeam, the landscape has fundamentally changed. “The second quarter of 2025 marks a turning point in ransomware, as targeted social engineering and data exfiltration have become the dominant playbook,” he said.”
Key findings from the Q2 2025 report:
- Social engineering: Three major ransomware groups dominated the quarter – Scattered Spider, Silent Ransom, and Shiny Hunters – each using highly targeted social engineering to breach organisations across various sectors.
- Ransom payments soar: Both the average and median ransom payments have rocketed to $1.13 million (up 104% from Q1 2025) and $400,000 (up 100%), respectively.
- Data theft: Data exfiltration was a factor in 74% of all cases, with many campaigns now prioritising data theft over traditional system encryption.
- Professional services: Professional services (19.7%), healthcare (13.7%), and consumer services (13.7%) bore the brunt of attacks. Mid-sized companies (11–1,000 employees) made up 64% of victims, proving to be a sweet spot for attackers who can balance payout potential against less mature defences.
- Attack techniques evolve: Credential compromise, phishing, and the exploitation of remote services continue to be the main methods for initial access.
- New entrants: Q2’s top ransomware variants were Akira (19%), Qilin (13%), and Lone Wolf (9%). Silent Ransom and Shiny Hunters entered the top five for the first time.


