New data reveals a shift from quick-hit ransomware attacks to stealthy, persistent threats that are harder to detect and costlier to contain.
The report examines the expanding attack surface and the tactics threat actors are using to exploit organisations and execute lucrative attacks.
According to the findings, threat actors are shifting away from broad, indiscriminate campaigns towards more targeted approaches that yield greater impact. As IT environments become more complex and attack surfaces grow, adversaries are capitalising on blind spots, spending more time inside networks to inflict greater damage and secure higher payouts.
Ransomware payouts soar as attackers evolve
While the frequency of ransomware attacks has dropped from eight incidents per organisation to five or six in the last year, the average ransomware payment surged from US$2.5 million to US$3.6 million.
This offset between frequency and cost reflects how attackers have evolved to move undetected within an organisation’s environment. Threat actors had access to networks for nearly two weeks on average before launching an attack. Nearly a third of organisations only became aware of a ransomware incident after data exfiltration had already begun.
Delays in response increase downtime
Organisations take more than two weeks on average to respond to and contain a security alert. This delay enables attackers to maximise damage, with the research showing an average downtime of more than 37 hours following an incident.
Critical infrastructure and government most targeted
RansomHub (26.8%), LockBit (26.5%), Darkside (25.7%), APT41 (24%) and Black Basta (23.4%) were the most detected threat actors in organisational environments last year. In the government sector, LockBit (33.3%), Darkside (33.3%), Black Basta (33.3%) and RansomHub (25.6%) were among the most active groups.
Old tactics persist in modern attacks
As attack surfaces expand, organisations cited the public cloud (53.8%), third-party services and integrations (43.7%) and Generative AI applications (41.87%) as their most significant cybersecurity risks. The most common entry methods remained phishing and social engineering (33.65%), followed by software vulnerabilities (19.43%), third-party or supply chain compromise (13.4%) and compromised credentials (12.2%).
Visibility remains a top challenge
Key barriers to a timely response included limited visibility across the environment (41%), overwhelming alert volume (34%), disparate and poorly integrated tools (34%) and manual SOC workflows (34%). Visibility issues were most prevalent in critical sectors such as telecoms, finance and education.
“This research validates what we’ve been seeing firsthand: motivated attackers are exploiting new entry points to bypass traditional defences and remain hidden inside a network until the time is right to strike,” said Raja Mukerji, Co-founder and Chief Scientist, ExtraHop. “The reality is, threats will always find a way in, and organisations must be able to detect threats as they move laterally between systems to escalate privileges and exfiltrate data. Enterprises that lack the ability to not only see, but also contextualise, every bit of network traffic will continue being targeted and plagued by costly downtime and ransom payments.”


