Desk live·
ForensicPost
Breaches/Analysis/File 25-1201

44% of 2025 Breaches Involved Ransomware and 30% a Third-Party Failure

Roughly 44% of 2025 breaches involved ransomware and around 30% were linked to supply-chain or third-party failure. The second number is the one that changed how this desk files.

Constructed geometry · not a chart of case data
TargetGlobal breach landscape
ActorMultiple
D. Kennedy & S. Rosler13 min readConfidence: medium3 sources reviewed

Sector analysis of 2025 puts around 44% of breaches as involving ransomware and roughly 30% as linked to supply-chain or third-party failure, against an estimated global cybercrime cost in the region of $10.5 trillion.

Treat the cost figure with considerable caution — it is a modelled aggregate with contested methodology, and it circulates far more widely than its derivation supports. The composition figures are the useful part.

Thirty Per Cent Is A Structural Finding

Almost a third of breaches originating with a third party means the boundary an organisation defends is no longer the boundary that determines its exposure.

The 2025 files in this database are dominated by exactly that: Collins Aerospace at 25-0919, Salesloft at 25-0818, the Oracle EBS campaign at 25-0930, SonicWall at 25-0917. In each, the compromised party and the affected parties were different organisations.

The Two Categories Overlap More Than The Split Suggests

Presenting ransomware and supply chain as separate percentages implies they are separate phenomena. Frequently they are the same incident counted twice — the Cl0p campaign was a supply-chain exploitation executed by a ransomware group that deployed no ransomware.

That taxonomy problem is worth naming, because it means neither figure can be read as a share of a clean partition, and comparing them year to year compares definitions as much as events.

What 2025 Established For The Years After It

Three things this desk has since filed repeatedly for 2026 have their origin in 2025 incidents: identity-led access replacing exploitation, extortion without encryption, and concentration at suppliers converting one intrusion into hundreds of victims.

None of those was new in 2025. What 2025 provided was the scale that made them undeniable — and it is why backfilling this year matters for anyone reading the 2026 files.

How we reported this

This is an analysis file built on published year-in-review research, listed below, read against files in this database. Aggregate cost figures are modelled and contested; we cite the composition percentages and treat the trillion-dollar figure as indicative at best. Corrections: corrections@forensicpost.com.

Sources
  1. Inside the biggest cyber attacks of 2025Security Boulevard
  2. The biggest cyber attacks of 2025 and what they mean for 2026Integrity360
  3. Biggest cyber attacks of the year 2025: a wake-up call for cybersecurityCybersecurity Insiders
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary