May 12th is Anti-Ransomware Day, established in 2020 by INTERPOL to commemorate the anniversary of the WannaCry ransomware attack that occurred on May 12, 2017. The purpose of Anti-Ransomware Day is to promote best practices for prevention and response.
To highlight Anti-Ransomware Day, Resilience Forward is highlighting resources published to support the event as well as asking various industry experts for their take on the current state of ransomware and resilience.
Kaspersky presents its annual report on the evolving global and regional ransomware cyberthreat landscape
Kaspersky was one of the original Anti-Ransomware Day supporters and has used the 2025 event to publish its annual State of Ransomware Report.
Current and emerging ransomware trends highlighted in the report include:
- AI tools were increasingly used in ransomware development, as demonstrated by FunkSec, a ransomware group that emerged in late 2024 and quickly gained notoriety by surpassing established groups like Cl0p and RansomHub with multiple victims claimed in December alone. Operating under a Ransomware-as-a-Service (RaaS) model, FunkSec employs double extortion tactics – combining data encryption with exfiltration – targeting sectors such as government, technology, finance, and education in Europe and Asia. The group’s heavy reliance on AI-assisted tools sets it apart, with its ransomware featuring AI-generated code, complete with flawless comments, likely produced by Large Language Models (LLMs) to enhance development and evade detection. Unlike typical ransomware groups demanding millions, FunkSec adopts a high-volume, low-cost approach with unusually low ransom demands, further highlighting its innovative use of AI to streamline operations.
- The RaaS (ransomware-as-a-service) model remains the predominant framework for ransomware attacks, fuelling their proliferation by lowering the technical barrier for cybercriminals. In 2024, RaaS platforms like RansomHub thrived by offering malware, technical support and affiliate programs that split the ransom. This model enables less-skilled actors to execute sophisticated attacks, contributing to the emergence of multiple new ransomware groups in 2024 alone.
- In 2025, ransomware is expected to evolve by exploiting unconventional vulnerabilities, as demonstrated by the Akira gang’s use of a webcam to bypass endpoint detection and response systems and infiltrate internal networks. Attackers are likely to increasingly target overlooked entry points like IoT devices, smart appliances or misconfigured hardware in the workplace, capitalizing on the expanding attack surface created by interconnected systems. As organizations strengthen traditional defences, cybercriminals will refine their tactics, focusing on stealthy reconnaissance and lateral movement within networks to deploy ransomware with greater precision, making it harder for defenders to detect and respond in time.
- The proliferation of LLMs tailored for cybercrime will further amplify ransomware’s reach and impact. LLMs marketed on the dark web lower the technical barrier to creating malicious code, phishing campaigns and social engineering attacks, allowing even less skilled actors to craft highly convincing lures or automate ransomware deployment. As more innovative concepts such as RPA (Robotic Process Automation) and LowCode, which provide an intuitive, visual, AI-assisted drag-and-drop interface for rapid software development, are quickly adopted by software developers, we can expect ransomware developers to use these tools to automate their attacks as well as new code development, making the threat of ransomware even more prevalent.
Ransomware and resilience: comments from industry experts
The following comments have been provided to Resilience Forward for Anti-Ransomware Day.
Darren Thomson, Field CTO EMEAI, Commvault
“Ransomware attacks continue to escalate year after year, and cybercriminals are no longer just chasing payouts – they’re hunting for headlines. Recent attacks targeting high-profile organizations and critical supply chains show a clear shift in strategy: aiming for maximum disruption and publicity by targeting the ‘big fish’.
“Recent research found that cyberattacks are costing UK businesses £64 billion a year, accumulated across ransom payments, lost business, and other related costs. Yet, despite the rising threat, too many organizations remain underprepared. True cyber resilience means more than just defence, it also requires the ability to recover fast. This is where tools such as cleanroom environments come in. By restoring critical cloud services in a secure, isolated space and using automation to speed up recovery, companies can minimise downtime. While recovery takes 24 days on average, some organizations don’t achieve business-as-usual for over 200, often due to poor preparation and a lack of understanding of their ‘minimum viable company’ – the essential systems needed to stay operational.
“But resilience isn’t just a concern for businesses. Individuals must also take responsibility for their cybersecurity. Consumers should start by evaluating their own situation: Could you manage without Internet access? Do you have a backup plan if payment terminals go down?
“Taking practical steps like using secure password managers, avoiding password reuse, and steering clear of public Wi-Fi without a VPN are essential. On Anti-Ransomware Day, it’s time for both businesses and consumers to assess their cyber resilience.”
Glenn Akester, Technology Director for Cyber Security & Networks, Node4
“Ransomware remains a serious and evolving threat for UK mid-market businesses. With ransomware-as-a-service widely available, launching an attack no longer requires deep technical skill, just intent. At the same time, threat actors are starting to use AI to accelerate and adapt their tactics, from crafting more convincing phishing emails to mutating ransomware code in real time to bypass detection. This constant variation is making traditional, signature-based defences less effective, particularly for organizations without dedicated cyber teams.
“In this environment, resilience isn’t just about technology, it’s about preparedness. Defending against ransomware means getting the basics right – timely patching, strong endpoint protection, access control, and real-time monitoring to spot unusual activity. It’s not about adding more tools, but making sure existing ones are well managed, integrated, and focused on reducing risk rather than ticking compliance boxes.
“Backups play a critical role, but they’re a last line of defence. If ransomware gets through, the speed and reliability of your recovery is what prevents a security incident from escalating into a full-blown operational crisis. Increasingly, attackers are targeting backup environments directly, knowing they’re often the last lifeline for compromised organizations. That’s why they must be secure by design – immutable, segregated from live systems, and regularly tested. A backup that fails under pressure isn’t really a backup at all. Mitigation and recovery processes should be robust, rehearsed, and clearly owned across the organization.
“Worryingly, recent research has revealed that cybersecurity ranks only 7th among strategic priorities for both business leaders and IT professionals, with protection from ransomware and malware ranking below 10th among cybersecurity priorities. This Anti-Ransomware Day is a good moment to review your current posture. Are your defences keeping pace with the threat? Could you recover under real-world pressure? In today’s threat landscape, resilience can’t be assumed, it needs to be designed, tested, and maintained. Now is the time to close the gaps.”
Shobhit Gautam, Staff Solutions Architect, EMEA, HackerOne
“Ransomware continues to be the most common ‘end game’ that cybercriminals are working towards. Already, ransomware attacks reached a record high in March 2025, with criminals focusing their attacks on key sectors such as healthcare, retail, and manufacturing. These attacks may be increasing due to the growing reliance on digital systems within these industries, along with the higher use of third-party components and inadequately protected legacy systems, compounded by reduced funding for security measures.
“With the decentralization of the ransomware ecosystem, we are now witnessing a rise in ransomware attacks. Initial Access Brokers (IABs) and ransomware-as-a-service (RaaS) continue to be significant concerns for organizations. The accessibility of ransomware tools and the capabilities of AI mean that criminals no longer need an in-depth knowledge of programming or hacking to launch these attacks.
“The deepening role of artificial intelligence in the technology industry is leading to an AI arms race between security teams and cybercriminals. With more than 50% of security researchers saying so, it is vital that businesses take the necessary steps to reduce the ransomware threat.
“One of the most successful ways to counter the risk of ransomware is to adopt crowdsourced security. Bug bounty programs incentivise security researchers to highlight any weaknesses and potential vulnerabilities in businesses’ defences and can provide support to mitigate these threats. Working with security researchers is a critical step in identifying and fixing vulnerabilities before malicious actors can exploit them.”
Jakub Lewandowski, Associate General Counsel EMEA, Commvault
“Paying a ransom is a dangerous move – there’s often no guarantee that the criminals behind the attack will deliver the outcome they’ve promised, so in doing so, an organization is playing right into their hands. The more victims who pay, the more criminals will continue to attack – why wouldn’t they? And with research revealing that 78% of organizations who paid a ransom demand were hit by a second ransomware attack, there’s strong evidence to suggest that it makes them more of a target in future.
“Bans on paying ransoms could, if properly enforced, put a halt to this lucrative criminal business, which is only becoming more commonplace with the rapid rise in AI technology. If all public sector and critical infrastructure organizations are legally prevented from paying, then it makes them a less attractive target.
“In the meantime though, these organizations would need to be better prepared to prevent and recover from attacks, as they won’t have the failsafe option of paying up. The UK Government must therefore incentivize increasing investment in attack prevention, detection, and recovery to enable these critical organizations to continue to operate even when in a cyber crisis – or else risk a national disaster.”






