Analysis of leak-site activity through 2025 records the ten most active groups accounting for 71% of postings in the first quarter, 63% in the second and 56% in the third, while the number of active data-leak sites reached a record 81 in Q3.
Three Consecutive Quarters Is A Trend, Not Noise
Most of the percentages this desk handles are single points from a single study. A monotonic decline across three quarters, measured consistently by one methodology, is a considerably stronger observation.
It is also internally coherent with the group count at 25-1226 and the site count here: more operators, each smaller, is exactly what a falling top-ten share describes.
The Corpus Files This Under Concentration, Inverted
The dominant structural argument in this database is that concentration on the defensive side creates systemic risk — one vendor, thousands of downstream victims, as at 25-0814 and 25-0801.
The attacking side is moving the other way. It is deconcentrating, and the effect is also negative for defenders: a concentrated adversary is one you can study, name, sanction and disrupt, and 26-0624 records what that looks like when it works.
Concentration is dangerous on the side that holds the data and useful on the side that attacks it. Both are moving in the unhelpful direction simultaneously.
What A Defender Should Take From It
Practically: attribution matters less than it did. If the top ten account for a bare majority and are being displaced quarterly, knowing which group is in your network tells you less about what happens next than it would have two years ago.
Controls should therefore be organised around technique rather than actor — the argument at 25-0719, where one exploit chain served both espionage and extortion. Graded medium: single-methodology quarterly data, and this desk cannot verify the underlying collection.
Built on published quarterly research, listed below. The quarterly series is one vendor’s methodology and the trend should be read within that. Corrections: corrections@forensicpost.com.
- Threat spotlight: ransomware and cyber extortion in Q3 2025ReliaQuest
- The state of ransomware — Q3 2025Check Point Research