Research on telecom ransomware in 2025 found that a small number of operations conducted most attacks, with Qilin the most active, followed by Akira and Play.
This Sits Awkwardly With The Fragmentation Finding
At 25-1226 the corpus recorded 124 active groups including 73 new entrants, and at 25-1004 the top ten’s share of leak-site postings falling from 71% to 56% across three quarters.
Within telecom specifically, three operations dominate. Both can be true: an ecosystem-wide long tail of small entrants alongside sector concentration, where the operations with the capability to attack large regulated carriers are a much smaller set than the operations that exist.
That is a more useful reading than either statistic alone, and it complicates the corpus’s own fragmentation argument rather than confirming it.
The Three Names Are The Ones The Year Keeps Producing
Qilin was the most prolific operation overall at 25-1108, with reported growth around 420%. Akira was linked to the Marquis compromise at 25-0814. Akira, Play and RansomHub absorbed the share vacated after the LockBit disruption, at 25-0402.
The same operations appear across sectors, which is consistent with the affiliate model: a platform grows by recruiting affiliates, and affiliates bring whatever access they have.
Which Makes Sector Concentration An Affiliate Artefact
If three platforms dominate telecom, the likeliest explanation is not that they specialise in it but that they are the largest platforms and telecom access flows to the largest platforms like everything else.
Graded medium: the ranking is from a single research source, and the interpretation is this desk’s inference from the affiliate structure at 25-1108.
Built on published vendor research, listed below, read against the ecosystem files in this database. The affiliate interpretation is our inference. Corrections: corrections@forensicpost.com.
- Telecom sector sees steady rise in ransomware attacksCybersecurity Dive
- Telecommunication sector faces new threatsThe Cyber Express