HomeSecurityQ2 2025: Increased ransomware attacks in retail

Q2 2025: Increased ransomware attacks in retail

The retail sector is being targeted by ransomware attacks , with incidents increasing by 58% in the second quarter of 2025 (compared to the previous one). According to the latest report from BlackFog , the UK appears to be playing a leading role in the attacks, with leading retailers such as Marks & Spencer (M&S), The Co-op and Harrods at the centre of the digital war.

Q2 2025: Increased ransomware attacks in retail

British companies in the spotlight – Attack by the Scattered Spider group

The attacks on the above companies are linked to the Scattered Spider group and included the development of ransomware. The attacks led to severe operational disruptions and significant financial losses. On July 10, British authorities arrested four suspects for participating in this action, intensifying the effort to limit cyber threats in the country.

In addition to British businesses, global brands such as Dior, Adidas, Louis Vuitton, Cartier and Victoria's Secret have also suffered cyberattacks, confirming that the retail sector has become a top target for cybercriminals.

See also: Authorities dismantle Diskstation ransomware gang

Why is the retail sector being targeted?

According to BlackFog, retailers are of particular interest to hackers due to the nature of their operations: they have complex supply chains, sensitive customer data , and payment data. Even a temporary disruption to a retailer’s operations can result in huge losses, which increases the likelihood of a ransom payment — making companies more vulnerable to blackmail.

As the researchers point out, “the urgent need for recovery is driving many companies to pay the ransom, reinforcing the business strategy of ransomware groups.”

Ransomware attacks launch globally

The overall picture is even more worrying. In the second quarter of 2025, 276 confirmed ransomware attacks, a number that increased by 63% compared to the same quarter of 2024.The months of April and May in particular recorded record numbers with 89 and 91 attacks respectively.

95% of attacks included data theft, while in many cases, encryption of systems was not necessary to achieve the attackers' goals.

See also: Albemarle County hit by Ransomware attack

The most affected industries

Although the retail sector is under pressure, the most targeted sector was healthcare with 52 attacks (18.8%), followed by government them (16.3%) and services (12%)to pay ransom.

The Qilin group emerged as the most active of the quarter, accounting for 10% of confirmed cases, followed by INC Ransom, Interlock, Akira, and Medusa

The invisible problem: Unreported attacks

One of the most shocking findings of the report is the lack of transparency: it is estimated that only 1 in 5 ransomware attacks are publicly reported. Specifically, 1446 incidents were not reported (a 19% increase compared to 2024). Qilin was again the most active group in unreported incidents (15%).

Internal confirmation: M&S chairman is “nailing” the market

Indicative of the lack of transparency is the testimony of Archie Norman, chairman of Marks & Spencer, before the UK Parliament. He revealed that he is aware of at least two serious attacks on major companies that were not publicly reported in the last four months.

Q2 2025: Increased ransomware attacks in retail

The critical need for transparency and defense

The rapid increase in ransomware attacks in the retail sector (and beyond) highlights not only the technological vulnerability of businesses, but also the inadequate response in terms of management and disclosure. In a world where cybersecurity is becoming an integral part of corporate survival, strengthening protection mechanisms, but also transparency towards the public and regulators, are the only way forward.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: GLOBAL GROUP: New Ransomware-as-a-Service business

🔐 The next big challenge for companies is not if they will be attacked, but when — and how to manage it.

Ransomware protection

  • Stay up to date on the latest ransomware trends and tactics used by attackers
  • Implement multi-factor authentication (MFA) for all user accounts
  • Enable firewall on all devices connected to your network
  • Keep sensitive data encrypted
  • Update all your devices and systems with the latest security patches
  • Conduct regular security audits and penetration testing
  • Use strong, unique passwords and change them regularly.
  • Limit user access to only necessary systems and information
  • Consider using  email security solutions for additional protection against phishing attacks
  • Have a recovery plan to quickly restore systems in the event of an attack
  • Enable the display of file extensions
  • Invest in advanced protection solutions
  • Use sandboxing for email attachments
  • Keep backup copies of your data

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS