Ransomware Frontline Report
Current Edition Sources — Updates and Additions in the Current Edition
This page lists the source identifiers cited in the report, their public URLs, and the existing limitations.
S01
- Source
- #StopRansomware Guide (2025)
- Publisher
- CISA
- URL
- https://www.cisa.gov/sites/default/files/2025-03/StopRansomware-Guide%20508.pdf
- Limitation
- A U.S. government practical guide. Not a worldwide statistic.
S02
- Source
- 2025 Annual Report
- Publisher
- FBI IC3
- URL
- https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- Limitation
- Self-reported complaints; not a complete tally of amounts paid or of total damage.
S03
- Source
- 2025 DBIR
- Publisher
- Verizon
- URL
- https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf
- Limitation
- A submitted sample of incidents, not a global occurrence rate. Do not conflate the overall figure with the figures broken out by organization size.
S04
- Source
- 2026 DBIR
- Publisher
- Verizon
- URL
- https://www.verizon.com/business/resources/reports/dbir/
- Limitation
- The detailed definitions and population should be re-confirmed in the report’s own body text. The around-15 figure is a count of techniques, not an AI-involvement rate across all breaches. Used in the report body only as a reference current-state indicator.
S05
- Source
- 情報セキュリティ10大脅威 2025
- Publisher
- IPA
- URL
- https://www.ipa.go.jp/security/10threats/10threats2025.html
- Limitation
- A ranking based on a vote of Japanese experts, not a ranking by number of incidents.
S06
- Source
- ランサムウェア対策特設ページ
- Publisher
- IPA
- URL
- https://www.ipa.go.jp/security/anshin/measures/ransom_tokusetsu.html
- Limitation
- Not used as grounds for settling any individual case.
S07
- Source
- 中小企業における脅威への対策強化
- Publisher
- Tokyo Metropolitan Government
- URL
- https://cybersecurity-taisaku.metro.tokyo.lg.jp/basics/kisokaramanabu8-2/
- Limitation
- An anonymized educational-material case. The victim organization is not speculated upon.
S08
- Source
- Play ransomware advisory
- Publisher
- CISA
- URL
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-352a
- Limitation
- The behavior of a specific group; not generalized to all groups.
S09
- Source
- Medusa ransomware advisory
- Publisher
- CISA
- URL
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
- Limitation
- The scope known to the joint advisory.
S10
- Source
- 2024-02-21 SEC filing
- Publisher
- UnitedHealth Group
- URL
- https://www.sec.gov/Archives/edgar/data/731766/000073176624000045/unh-20240221.htm
- Limitation
- An initial disclosure; not a document that shows the full cause or final scope of damage.
S11
- Source
- 2024 Form 10-K
- Publisher
- UHG
- URL
- https://www.sec.gov/Archives/edgar/data/731766/000073176625000063/unh-20241231.htm
- Limitation
- Attacker attribution and payment decisions for the incident are not speculated upon.
S12
- Source
- 2023 Annual Report
- Publisher
- FBI IC3
- URL
- https://www.ic3.gov/annualreport/reports/2023_ic3report.pdf
- Limitation
- Year-over-year comparisons are affected by changes in reporting behavior and classification.
S13
- Source
- 2022 Annual Report
- Publisher
- FBI IC3
- URL
- https://www.ic3.gov/AnnualReport/Reports/2022_ic3report.pdf
- Limitation
- Same as above (S12).
S14
- Source
- AIDS Trojan / PC Cyborg
- Publisher
- WatchGuard
- URL
- https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/aids-trojan
- Limitation
- A secondary source on a historical incident. This report does not speculate on technical details or the author’s motive.
S15
- Source
- U.S. Leads Multi-National Action Against GameOver Zeus Botnet and CryptoLocker Ransomware
- Publisher
- U.S. Department of Justice
- URL
- https://www.justice.gov/archives/opa/pr/us-leads-multi-national-action-against-gameover-zeus-botnet-and-cryptolocker-ransomware
- Limitation
- Investigative material as of the time of the takedown. Not generalized to the overall scale of ransomware’s prevalence.
S16
- Source
- Multiple Ransomware Infections Reported
- Publisher
- CISA
- URL
- https://www.cisa.gov/news-events/alerts/2017/05/12/multiple-ransomware-infections-reported
- Limitation
- An early alert. Not used as grounds for the final number of victims.
S17
- Source
- Ransomware, extortion and the cyber crime ecosystem
- Publisher
- UK NCSC
- URL
- https://www.ncsc.gov.uk/paper/ransomware-extortion-and-the-cyber-crime-ecosystem
- Limitation
- Analysis by a UK government body. Not a document that settles the full damage to any individual organization or the full range of an attacker’s actions.
S18
- Source
- Department of Justice Seizes $2.3 Million in Cryptocurrency Paid to the Ransomware Extortionists DarkSide
- Publisher
- U.S. Department of Justice
- URL
- https://www.justice.gov/archives/opa/pr/department-justice-seizes-23-million-cryptocurrency-paid-ransomware-extortionists-darkside
- Limitation
- An investigative and seizure announcement. Does not present the technical details of the shutdown decision or the full societal loss.
S19
- Source
- CISA-FBI Guidance for MSPs and Their Customers Affected by the Kaseya VSA Supply-Chain Ransomware Attack
- Publisher
- CISA
- URL
- https://www.cisa.gov/news-events/alerts/2021/07/04/cisa-fbi-guidance-msps-and-their-customers-affected-kaseya-vsa-supply-chain-ransomware-attack
- Limitation
- Emergency guidance. Not used as grounds for settling the final number of victims or the full intrusion route.
S20
- Source
- Interlock Ransomware
- Publisher
- CISA
- URL
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a
- Limitation
- The behavior of a specific group; not generalized to all groups.
CE1
- Source
- 情報セキュリティ10大脅威 2026
- Publisher
- IPA
- URL
- https://www.ipa.go.jp/security/10threats/10threats2026.html
- Limitation
- Successor to S05 (2025 edition). A ranking based on a vote of Japanese experts, not a ranking by number of incidents.