Desk live·
ForensicPost
Ransomware/Analysis/File 25-1004

Ten Groups Accounted for 71% of Leak-Site Postings in Q1 2025

The ten most active groups accounted for 71% of leak-site postings in Q1 2025, 63% in Q2 and 56% in Q3. Active leak sites reached a record 81.

Constructed geometry · not a chart of case data
TargetRansomware ecosystem
ActorMultiple
D. Kennedy11 min readConfidence: medium2 sources reviewed

Analysis of leak-site activity through 2025 records the ten most active groups accounting for 71% of postings in the first quarter, 63% in the second and 56% in the third, while the number of active data-leak sites reached a record 81 in Q3.

Three Consecutive Quarters Is A Trend, Not Noise

Most of the percentages this desk handles are single points from a single study. A monotonic decline across three quarters, measured consistently by one methodology, is a considerably stronger observation.

It is also internally coherent with the group count at 25-1226 and the site count here: more operators, each smaller, is exactly what a falling top-ten share describes.

The Corpus Files This Under Concentration, Inverted

The dominant structural argument in this database is that concentration on the defensive side creates systemic risk — one vendor, thousands of downstream victims, as at 25-0814 and 25-0801.

The attacking side is moving the other way. It is deconcentrating, and the effect is also negative for defenders: a concentrated adversary is one you can study, name, sanction and disrupt, and 26-0624 records what that looks like when it works.

Concentration is dangerous on the side that holds the data and useful on the side that attacks it. Both are moving in the unhelpful direction simultaneously.

What A Defender Should Take From It

Practically: attribution matters less than it did. If the top ten account for a bare majority and are being displaced quarterly, knowing which group is in your network tells you less about what happens next than it would have two years ago.

Controls should therefore be organised around technique rather than actor — the argument at 25-0719, where one exploit chain served both espionage and extortion. Graded medium: single-methodology quarterly data, and this desk cannot verify the underlying collection.

This is an analysis file

Built on published quarterly research, listed below. The quarterly series is one vendor’s methodology and the trend should be read within that. Corrections: corrections@forensicpost.com.

Sources
  1. Threat spotlight: ransomware and cyber extortion in Q3 2025ReliaQuest
  2. The state of ransomware — Q3 2025Check Point Research
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary