Vendor research reports that 47% of ransomware attacks were stopped before encryption during 2025, compared with 22% in 2023.
The Corpus Has Been Unable To See This
At 25-0807 this desk recorded that a database assembled from disclosures records failures in detail and successes almost never, and that every generalisation here about organisational response is drawn from a sample selected for having responded badly.
At 25-1218b the corpus listed four categories that publicly disclosed attack counts exclude by construction, one of which is attacks that were stopped.
This figure measures precisely that excluded category. It comes from incident response and managed detection engagements rather than from leak sites — which is the only place such data could come from.
A Doubling In Two Years Is Large Enough To Interrogate
This desk discounted an 80% single-year jump at 25-0423 on the grounds that attack patterns do not move that fast, and treated a fourfold telecom rise across three years at 25-0714 as more defensible because the baseline was longer.
Twenty-two to forty-seven per cent over two years sits between those. It is fast, and it describes defensive capability rather than adversary behaviour — and defensive capability can change quickly when a product category is widely adopted.
The Population Is The Problem
These figures come from the customers of a security vendor, and specifically from customers who engaged incident response or managed detection services. That population is better defended than average by definition.
The corpus applied the same objection to national rankings at 25-0711, where "customers impacted" meant customers of the publisher. Graded medium: the direction is credible and the level does not describe the general population of organisations.
Built on published vendor research, listed below, derived from the publisher’s incident response and managed detection engagements. The population is not representative of organisations generally. Corrections: corrections@forensicpost.com.
- Faster attacks and recovery-denial ransomware reshape threat landscapeCSO Online
- Detection at dusk: why dwell times collapsed in 2025Black Hat MEA Insights