Ransomware Declines but Cyberattacks Surge Against Government Institutions

SECURITYRansomware Declines but Cyberattacks Surge Against Government Institutions
- Advertisement -Translation agency in Poland – professional language servicesTranslation agency in Poland – professional language services

The third quarter of 2025 brought a major shift in the global cyber-threat landscape. According to Cisco Talos, more than 60% of incidents began with the exploitation of vulnerabilities in publicly accessible applications, and—for the first time—the public sector became the number one target for cybercriminals.


Ransomware Declines but Remains a Major Threat

Cisco Talos reports that in Q3 2025, ransomware-related incidents accounted for around 20% of all cases, down from 50% in Q2. While the decrease is significant, experts emphasize that this is not a long-term trend. Ransomware remains one of the most persistent and dangerous threats facing organizations worldwide.


Public Administration Becomes the Main Target

For the first time since Cisco Talos began collecting data in 2021, government and municipal organizations became the most frequently attacked sector.
Local municipalities — responsible for critical public services — were especially vulnerable. The victims included schools, hospitals, and other public institutions that often operate with limited budgets and outdated IT infrastructure.

In Q3 2025, both profit-driven cybercriminal groups and Russia-linked APT (Advanced Persistent Threat) actors conducted coordinated campaigns primarily targeting the public sector.


Exploiting Vulnerabilities in Public-Facing Applications

Over 60% of all incidents in Q3 began with the exploitation of vulnerabilities in publicly accessible applications — a dramatic increase compared to less than 10% in the previous quarter.

The spike was driven by a wave of attacks targeting on-premises Microsoft SharePoint servers, using a compromise chain known as ToolShell.

“Attackers showed how quickly they can move through poorly segmented environments. In one case, ransomware was deployed just weeks after the initial ToolShell intrusion. This highlights the critical importance of proper network segmentation,”
says Lexi DiScola, Threat Intelligence Analyst at Cisco Talos.

ToolShell activity in Q3 underscored how fast attackers weaponize newly discovered zero-day vulnerabilities. The first exploitation attempts occurred one day before Microsoft’s public advisory, and most incidents analyzed by Talos happened within just ten days.

“Cybercriminals now automatically scan the internet for vulnerable hosts while defenders race to test and deploy patches. About 15% of incidents this quarter involved infrastructure missing critical updates. Fast patching and strong segmentation are among the most important defensive measures today,”
adds DiScola.


New Attack Techniques and Ransomware Variants

Cisco Talos identified three new ransomware variants during the quarter:

  • Warlock
  • Babuk
  • Kraken

These appeared alongside well-known families such as Qilin and LockBit.

Qilin, active since early 2025, has rapidly expanded its operations and is likely to remain a major threat through the end of the year. In one case, attackers deployed ransomware just two days after the initial breach.
LockBit also remained active, continuing its role as one of the most notorious ransomware groups globally.

Talos attributed one of the analyzed incidents to Storm-2603, a group believed to operate from China. Notably, Storm-2603 used the legitimate security tool Velociraptor—typically used for system analysis and forensics—to gather data, monitor activity and maintain persistence on compromised systems. It was the first documented case where this tool was used in a ransomware campaign.

Check out our other content
Related Articles
The Latest Articles