Ransomware continues to be the predominant cause of high-value cyber insurance claims in 2025, with attackers increasingly targeting small and mid-sized businesses as large enterprises bolster their defenses. According to Allianz’s Cyber Security Resilience 2025 report, 88% of breaches at smaller firms involved ransomware, compared to 39% at larger organizations, highlighting a shift in attacker focus toward easier targets. Ransomware accounted for approximately 60% of insurance claims exceeding €1 million in the first half of 2025, underscoring its financial impact. Attackers are evolving their tactics, moving beyond simple encryption to prioritize data exfiltration, which is often less resource-intensive and more likely to result in ransom payments. The value of stolen data is rising, and the average global breach cost is approaching $5 million, with privacy regulations and litigation risks compounding the financial exposure for affected organizations. Social engineering, phishing, and business email compromise remain prevalent, with generative AI making these attacks more convincing and credential abuse now the most common attack vector. Groups such as Scattered Spider exemplify the trend of using social engineering and credential theft to rapidly escalate attacks from account takeover to ransomware deployment. Retailers have become the most targeted sector in early 2025, following manufacturing and professional services in total losses, due to their large volumes of personal data and complex supply chains. Supply chain disruptions are also emerging as a significant source of cyber insurance claims, as interconnected business operations increase systemic risk. The evolving threat landscape is prompting organizations to reassess their cyber resilience strategies, with a focus on proactive defense measures and third-party risk management. The increasing sophistication of attacks, especially those leveraging AI and targeting operational technology, is driving a need for improved governance and contractual protections with suppliers. As attackers adapt, organizations must prioritize both IT and OT security, ensure executive support for resilience initiatives, and address hidden dependencies that could become blind spots in their defenses. The convergence of ransomware, data exfiltration, and supply chain vulnerabilities is shaping the cyber insurance market and influencing security priorities for businesses of all sizes in 2025.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.