Desk live·
ForensicPost
Ransomware/Analysis/File 25-0918

US Government Ransomware Incidents Rose 65% in the First Half of 2025

Ransomware incidents affecting government bodies rose 65% in the first half of 2025 against the same period a year earlier, and incidents against education rose 23% from January. Both sectors fund security from tax revenue.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUS public sector
ActorMultiple
D. Kennedy12 min readConfidence: medium3 sources reviewed

Published analysis records a 65% increase in ransomware incidents affecting government bodies in the first half of 2025 compared with the same period in 2024, and a 23% rise in incidents against schools, colleges and universities since January 2025. US federal cyber authorities have described ransomware as the most disruptive threat facing state and local government.

Public Bodies Cannot Use The Standard Response

A commercial organisation facing rising attack volume can raise prices, defer other investment, or accept a lower margin. The mechanism is unpleasant but it exists.

A county government cannot. Its revenue is set by a political process on an annual cycle, and increasing the security budget means an explicit, contested decision to spend less on something a resident can see — road repairs, library hours, a school programme.

This is the central finding of the funding files in this corpus, from water districts at 26-0729 to school boards at 26-0228: the parties who could fix the problem are not the parties who control the money.

They Are Targeted Because They Are Reachable, Not Because They Are Rich

Government bodies are poor ransom prospects. Payment is frequently prohibited or politically impossible, budgets are public, and the negotiation happens in the open.

What they offer instead is a high probability of success against a low investment of effort, together with disruption severe enough to generate pressure from residents. And the data — identity records, benefit claims, court files, crash reports as at 25-0612 — has resale value independent of whether anyone pays.

A Caution On Both Figures

Both percentages are drawn from counts of publicly known incidents, and public-sector incidents are more likely to become publicly known than commercial ones — open-meeting requirements, public-records law and elected officials all push disclosure.

A growth rate computed from a sector with rising disclosure pressure overstates the growth in attacks. That does not make the direction wrong, and it does mean the magnitude should be held loosely. Graded medium accordingly.

This is an analysis file

Built on published trend analysis, listed below, read against the public-sector incidents in this database. The underlying counts are of publicly known incidents and are not a census. Corrections: corrections@forensicpost.com.

Sources
  1. U.S. state and local government under ransomware: 2025–2026 trend analysisSOCRadar
  2. Improving state and local government cybersecurityITIF
  3. The state of ransomware 2025BlackFog
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary