Key Takeaways

  • Attackers increasingly select victims for operational leverage, not simply size or brand recognition.
  • Manufacturing attacks rose 56% in 2025, while smaller businesses also faced sustained targeting.
  • Recovery planning, tested backups, access controls, and incident reporting can reduce attacker leverage.

A ransomware victim profile is no longer a simple sketch of a large, cash-rich enterprise. It is a collection of characteristics that criminals can turn into leverage: costly downtime, sensitive records, regulatory exposure, fragile recovery processes, or limited security capacity.

That distinction matters. A regional hospital, midsized manufacturer, construction contractor, and small professional-services practice may have little in common commercially. From an attacker's perspective, however, each may present a credible reason to pay quickly.

The scale of reported activity illustrates the breadth of the target set. Researchers publicly tracked 7,307 victims associated with 138 ransomware groups in 2025. Healthcare led the sector count with 538 victims, followed by manufacturing with 473 and construction with 418. These totals represent visible cases, not a complete census.

Public disclosures capture only part of the market. Comparitech recorded 7,419 claimed attacks during 2025, but affected organisations publicly confirmed just 1,173. Criminal groups can exaggerate their results, while victims may limit disclosure for legal, investigative, or commercial reasons. Even so, the gap shows why leak-site counts and confirmed incidents should not be treated as interchangeable datasets.

While revenue still influences ransom calculations, it does not define victim selection. Businesses earning $4 million to $8 million were the most frequently targeted revenue segment in 2025, and 17% of victims had revenue below $20 million. Smaller businesses can offer a useful combination for criminals: valuable data, dependence on a limited number of systems, and fewer recovery resources than a global enterprise.

Why spend months pursuing one heavily defended corporation when several smaller victims may offer faster returns? SC Media has examined how ransomware economics can favor attack volume over prestige targets. That model helps explain why ordinary suppliers, local service providers, and specialist contractors remain exposed alongside household-name companies.

Manufacturing presents an especially stark example. Attacks against the sector rose 56%, from 937 in 2024 to 1,466 in 2025. Average ransom demands climbed from $523,000 to approximately $1.2 million. Production environments amplify pressure because disruption can halt machinery, delay customer orders, create safety concerns, and affect connected suppliers. Restoring office email is one problem. Restarting a tightly sequenced production line is another.

Geography adds another layer. The United States accounted for roughly half of publicly reported victims in Q3 2025, according to Check Point Research. Manufacturing and business services were the most affected sectors during that period. A large commercial base, extensive digital infrastructure, and many interconnected suppliers give ransomware operators a wide field of potential targets.

Industry labels alone can still mislead. A hospital's leverage point may be patient-care continuity and protected health information. A manufacturer may be unable to operate production systems. A professional-services business could face exposure of contracts, legal files, financial records, or client correspondence. The common thread is impact, not sector.

Groups such as LockBit, Qilin, and RansomHub also illustrate the wider criminal ecosystem in which affiliates can obtain tooling and infrastructure rather than building every capability themselves. This model can support broad targeting because different operators may pursue different geographies, sectors, and revenue bands at the same time.

For business leaders, profiling should work in reverse. Instead of asking whether the organisation looks important enough to attack, teams can identify what would create immediate pressure after encryption or data theft. Critical operational systems, privileged accounts, remote access, exposed credentials, backup administration, sensitive data stores, and key suppliers deserve particular attention.

That said, controls on paper are not the same as recoverability. Tested and isolated backups, rehearsed incident response, segmented access, multifactor authentication, timely remediation, and clear reporting procedures can reduce the leverage available to an attacker. Tabletop exercises should also involve operations, legal, communications, finance, and executive leadership, since ransomware quickly becomes more than an IT event.

The emerging victim profile is therefore broad but not random. Attackers tend to look for organisations where disruption or disclosure will hurt quickly and where recovery may be uncertain. Businesses that understand those pressure points can make themselves less attractive, while improving their ability to respond when prevention falls short.