Key Takeaways
- Ransomware represented 40% of financially motivated cyber events ENISA analyzed for 2025.
- Victim disclosures and the number of active ransomware groups increased sharply during 2025.
- Website disruption alone does not prove ransomware, and available evidence does not show that Facebook was affected.
Ransomware remains the European Union’s most impactful short-term cyber threat, according to findings published by the European Union Agency for Cybersecurity. ENISA said ransomware accounted for 40% of the financially motivated cyber events it analyzed for 2025, reinforcing concerns about the operational and financial exposure facing businesses, government agencies and online service operators.
The assessment matters because ransomware has evolved well beyond basic file encryption. Many operators now rely on double extortion, stealing information before encrypting systems and then threatening to publish the data if payment is withheld. For an affected business, that can turn one security incident into several overlapping problems: disrupted operations, possible data exposure, regulatory scrutiny and an expensive recovery process.
Even so, care is needed when classifying an outage or compromised website. The limited incident wording associated with the available material appears to describe ransomware involving a website or online service, but it does not provide enough evidence to identify the affected site. In particular, the evidence does not establish that Facebook was compromised.
A public website going offline is not, by itself, evidence of ransomware. Distributed denial-of-service attacks can make internet services unavailable by overwhelming infrastructure with traffic, but they generally do not encrypt internal systems. Ransomware typically requires attackers to gain access, move through the environment and deploy encryption or data-theft tooling. That distinction affects everything from public communications to forensic priorities.
The wider numbers show why businesses may encounter premature ransomware claims during unexplained outages. Check Point Research reported that ransomware groups published 1,592 victims on data-leak sites in Q3 2025, or roughly 520 to 540 new victims per month. The quarterly figure was 25% higher than in Q3 2024.
Meanwhile, Searchlight Cyber counted 7,458 victims listed on dark-web extortion sites during 2025, a 30% year-over-year increase. Researchers also identified 124 ransomware groups. Groups such as LockBit, Qilin and Akira illustrate a fragmented criminal market in which brands, affiliates and infrastructure can change quickly.
Those listings are useful indicators, though they are not the same as confirmed breach notifications. Criminal groups may exaggerate claims, repost older victims or identify organizations before independent verification is available. While speed is valuable during incident response, reacting hastily without evidence can create a secondary crisis. Who was affected, what systems were accessed and whether data left the environment should remain separate questions until forensic work answers them.
Public-sector exposure is especially pronounced. ENISA’s 2025 reporting found that public administration represented approximately 38% of recorded incidents from July 2024 through June 2025. Digital infrastructure and online services also attracted ransomware and espionage activity, raising the potential for one compromised supplier to affect multiple customers.
That supplier dimension is familiar. The source material references Emsisoft and REvil’s supply-chain attack on Kaseya’s VSA software, an example of how access to a widely deployed management product can expand an incident far beyond the initial point of compromise. It also explains why vendor access, remote administration tools and service-provider accounts warrant close monitoring.
For business leaders, preparation should extend beyond backups. Organizations can reduce exposure by separating backup credentials from production accounts, testing restoration procedures, limiting privileged access and recording how third parties connect to critical systems. Incident plans should also cover evidence preservation, legal review, regulatory reporting and communications with customers and suppliers.
The first public statement deserves care, too. An outage can be acknowledged without assigning a cause that has not been established. Once ransomware is confirmed, response teams can assess encryption, data theft and persistence as distinct workstreams. That measured approach gives executives, customers and investigators a clearer account of what actually happened.
⬇️