
Ransomware grew again in 2025. Depending on whose tracker you trust, claimed victims rose 58% year-over-year to a record 7,515–8,159 organizations, the highest volume ever recorded on public leak sites. One of the industry’s most-cited annual breach-data reports shows ransomware now shows up in 44% of confirmed breaches, up from 32% the year before, the fastest single-year jump that report has tracked. A separate major threat-intelligence index counted 109 active ransomware groups operating in 2025, a 49% increase, as law-enforcement takedowns of established gangs simply scattered their affiliates into newer, hungrier crews, Qilin chief among them.
That’s the headline everyone already expected: more attackers, more attacks, more group churn. The number that should actually change how you spend your security budget is a different one.
The clock dropped to 29 minutes. That’s not a typo.
One of the largest endpoint-security vendors’ annual global threat reports measured “breakout time,” the gap between an attacker’s first foothold and the moment they start moving laterally inside your network, at an average of 29 minutes in 2025, down 65% from the year before. The fastest breakout on record: 27 seconds. In one intrusion investigated for that report, data was already leaving the building four minutes after initial access. A separate incident-response firm’s annual trends data tells the same story from a different angle; the handoff from initial-access broker to ransomware affiliate has compressed to roughly 22 seconds, and prior compromise, buying a foothold that already exists, is now the single most common way ransomware operators get in.
Sit with that math for a second. If your SOC needs 20 minutes to triage an alert and another 15 to escalate it, the adversary is already on a second host before the Slack message lands. A detection stack tuned to catch what happens after breakout is tuned to catch nothing. This is precisely the gap we’ve been naming since 2015: the average organization still takes roughly 200 days to detect a breach, usually because someone outside the company tells them about it first. The industry has spent a decade shaving days off that number while attackers shaved it down to minutes. The two curves are moving in opposite directions, and most SOCs are still measuring their performance against the wrong one.
“Resilience” is the right word. Most vendors are still selling “prevention.”
Ransomware resilience, the ability to detect, contain, and recover from an attack in progress rather than betting everything on stopping it at the door, is rightly being called out as one of the defining cybersecurity priorities heading into 2026, alongside continuous monitoring as the only realistic answer to attacks this automated and this fast. Similar trend analysis from across the AI-defense side of the market makes the same point: static, signature-based controls simply cannot keep pace with adversaries who are now using AI to scale reconnaissance and automate lateral movement.
We agree with the diagnosis. We’d push back on the prescription most of the market is selling in response, which is: buy a faster autonomous agent and let it fight the faster autonomous attacker on your behalf. Automation absolutely has a role; that same endpoint-vendor report found that 82% of detections in 2025 involved no malware at all, meaning the attacker is living off legitimate tools and valid credentials an endpoint agent was never designed to flag. Endpoint telemetry alone, however fast the agent, cannot see an identity-based intrusion that never touches a signature. It cannot see a ransomware crew that, per that same year’s threat research, is increasingly deploying directly onto virtualization hosts specifically to stay off the heavily monitored endpoint. That’s not a hypothetical gap. That’s this year’s dominant ransomware tradecraft, documented in the same body of research that produced the 29-minute number.
This is why we built LMNTRIX around continuous response, not incident response: correlated telemetry across endpoint, network, identity, cloud, and deception, instrumented behind whatever endpoint agent a customer already has running, regardless of vendor, with a human analyst validating every incident before it reaches a client. Not because automation is bad. Because a 29-minute breakout window doesn’t leave time for an alert to sit in a queue, and a cloud- or identity-based intrusion doesn’t leave a signature for an autonomous endpoint agent to catch in the first place. Coverage across the whole attack chain is what determines the outcome, not how many alerts a single sensor can generate in 29 minutes.
What “shrinking but still too slow” looks like in practice
The gangs setting the pace this year aren’t subtle about proving the point. Qilin alone posted 697 victims in the second half of 2025, a five-fold year-over-year increase, built on aggressive affiliate recruitment and purchased VPN credentials rather than novel exploits. A newer group, Sinobi, added 149 healthcare victims in a single quarter just months after forming, a tempo GRIT’s researchers say is only possible with experienced affiliates rebranding under a new name. None of that required a zero-day. It required speed defenders didn’t have, through doors (identity, SaaS, third-party access) that a lot of “next-gen” endpoint stacks still don’t watch closely enough.
There is one piece of genuinely good news buried in the 2025 numbers: victims are pushing back. Payment rates fell to a record low of 28–31%, down from 49% the year before, and 64% of organizations now refuse to pay outright. That’s resilience working, but resilience that starts after detection is resilience that starts too late for the 71% of organizations who report being hit at all. The number worth fixing sits earlier in the chain: how fast you see the breakout, not how firmly you can refuse the ransom note once it’s already on your screen.
If your current stack is still built to catch what a single endpoint agent can see, it’s fighting last year’s threat model. Be the hunter, not the prey.
