Ransomware payouts hit new high in Q2 2025, driven by social engineering and data theft, says Veeam

Ransomware payouts hit new high in Q2 2025, driven by social engineering and data theft, says Veeam

A new report from Coveware by Veeam reveals a dramatic escalation in targeted attacks, with hackers increasingly using social engineering and data exfiltration to extort record-high ransom payments.

According to Bill Siegel, CEO of Coveware by Veeam, the landscape has fundamentally changed. “The second quarter of 2025 marks a turning point in ransomware, as targeted social engineering and data exfiltration have become the dominant playbook,” he said.”

Key findings from the Q2 2025 report:

  • Social engineering: Three major ransomware groups dominated the quarter – Scattered Spider, Silent Ransom, and Shiny Hunters – each using highly targeted social engineering to breach organisations across various sectors. 
  • Ransom payments soar: Both the average and median ransom payments have rocketed to $1.13 million (up 104% from Q1 2025) and $400,000 (up 100%), respectively. 
  • Data theft: Data exfiltration was a factor in 74% of all cases, with many campaigns now prioritising data theft over traditional system encryption. 
  • Professional services: Professional services (19.7%), healthcare (13.7%), and consumer services (13.7%) bore the brunt of attacks. Mid-sized companies (11–1,000 employees) made up 64% of victims, proving to be a sweet spot for attackers who can balance payout potential against less mature defences.
  • Attack techniques evolve: Credential compromise, phishing, and the exploitation of remote services continue to be the main methods for initial access. 
  • New entrants: Q2’s top ransomware variants were Akira (19%), Qilin (13%), and Lone Wolf (9%). Silent Ransom and Shiny Hunters entered the top five for the first time.

Browse our latest issue

Intelligent CISO

View Magazine Archive