Semperis has published the results of a global ransomware study of nearly 1,500 organizations across a variety of industries, aiming to understand their experience with ransomware over the last 12 months. The study shows that hackers are relentless and ransomware remains a global epidemic. In 40% of attacks, threat actors threatened to physically harm executives at organizations that declined to pay a ransom demand. US-based companies experienced physical threats 46% of the time, while 44% of German firms reported similar forms of intimidation.
The 2025 Ransomware Risk Report: Essential Guidance for Building Operational Resilience Against Cyberattacks also found that 47% of attacked companies in the US, UK, France, Germany, Spain, Italy, Singapore, Canada, Australia, and New Zealand reported that hackers threatened to file regulatory complaints against them if they did not report the incident. In the US, the rate rose to 58%, a 23% increase, while in Singapore the extortion threat surged to 66% — a rise of 40%, and the highest of any country.
When comparing results with last year’s ransomware study, Semperis found slight year-on-year decreases in the number of companies paying ransoms. Still, 69% of companies that were victimised by ransomware paid a ransom. Unfortunately, 38% of companies paid multiple ransoms, and 11% paid three times or more. In the US, 47% of companies paid ransoms multiple times, while in Singapore this figure was 50%.
Ransomware attacks continue to be highly coordinated, strategically timed, and deeply embedded throughout systems before they are executed. This gives multiple attackers access to multiple operational systems, allowing them to execute repeated strikes. Organizations must remain on continual alert, always prepared for not just one, but several potential breaches.
The findings indicate that ransomware attacks are frequent, with 50% of respondents citing cybersecurity threats as the top risk to business resilience. The leading cybersecurity challenge facing organizations is the sophistication of attacks (37%), followed by attacks against organizations’ identity infrastructure (32%), most commonly Active Directory. Nearly 20% of companies that paid a ransom either received corrupt decryption keys that were unusable or had stolen data published despite assurances to the contrary.






