Ransomware in 2025: Global Statistics, Southeast Asia's Growing Exposure, and Hard Lessons from Real Attacks

Primary Guard · July 6, 2026 · 7 min read

Ransomware attacks rose 32% in 2025, costing $57 billion globally. See the latest statistics, how Malaysia and Indonesia are being targeted, and what major attacks like KLIA and Indonesia's PDNS teach us about surviving ransomware.

Ransomware in 2025: Global Statistics, Southeast Asia's Growing Exposure, and Hard Lessons from Real Attacks

Ransomware is no longer a distant threat covered in foreign headlines. It is shutting down hospital wards in Ohio, crippling airport operations in Kuala Lumpur, and encrypting the national data centres of entire governments. In 2025, a ransomware attack occurs somewhere in the world every 19 seconds.

This article brings together the most authoritative global data, the specific statistics that define the Southeast Asian threat landscape, and forensic lessons from some of the highest-profile attacks of recent years — including incidents directly on Malaysian and Indonesian soil.

The Global Ransomware Crisis: By the Numbers

Person staring at ransomware screen

According to Comparitech, there were 7,419 ransomware attacks worldwide in 2025 — a 32% increase over 2024. More than 7,500 unique organisations appeared on dark web leak sites — a 58% jump (GuidePoint Security).

Ransomware now accounts for 44% of all data breaches globally, up from 32% (Verizon DBIR 2025). Over 73% of organisations reported being hit at least once in the past 12 months (Fortinet).

  • Global ransomware damages: $57 billion annually$156 million per day (Cybersecurity Ventures)
  • Average total breach cost: $5.08 million per incident (IBM 2025)
  • Median ransom payment: $59,600 in 2025, up from $12,700 in 2024 (Chainalysis)
  • Largest single payment on record: $75 million to Dark Angels group (Mandiant M-Trends)

84% of victims who paid ransoms failed to fully recover their data (Halcyon). And 80% of organisations that pay are attacked again within 12 months (Fortinet).

Mean recovery cost (excluding ransom): $1.53 million (Sophos 2025). Median recovery time: over 100 days. Only 22% of attacked organisations recovered within a week.

96% of ransomware attacks target backup repositories (Veeam 2024), and 76% succeed — meaning backups alone do not guarantee recovery.

Southeast Asia: A Region Under Escalating Attack

Southeast Asia urban skyline at night

According to Kaspersky's 2024 research, total ransomware detections in Southeast Asia exceeded 113,000 incidents.

By country in 2024:

  • Indonesia: 57,554 detections — highest in the region
  • Vietnam: 29,282 detections
  • Philippines: 21,629 detections
  • Malaysia: 12,643 detections — a 153% year-on-year increase
  • Thailand and Singapore also recorded significant increases

Malaysia topped Southeast Asia for web-based cyberattacks in H1 2024 — recording 19.62 million web-based attacks, more than six times Indonesia's 3.2 million. The Malaysia Cybersecurity Threat Report 2025 confirmed ransomware incidents targeting Malaysian organisations more than doubled from 2023 to 2025.

CyberSecurity Malaysia (MyCERT) reported a 78% quarter-on-quarter increase in ransomware incidents in Q4 2024. The Q1 2025 report identified Active Directory servers as primary targets in Malaysia — compromising these allows attackers to propagate ransomware across every connected device simultaneously.

Case 1: Kuala Lumpur International Airport (KLIA) — March 2025

International airport terminal

Attacker: Qilin (Russia-linked) | Ransom demand: USD $10 million

On 23 March 2025, Qilin struck Malaysia Airports Holdings Berhad (MAHB), operator of KLIA. The group claimed to have exfiltrated 2 terabytes of sensitive data. Flight information screens, check-in counters, and baggage handling systems went offline. MAHB refused to pay. Sources: RiskSight · Security Quotient · CM Alliance

Key lessons:

  1. Network segmentation is non-negotiable for critical infrastructure. OT and IT networks must be separated.
  2. High-profile does not mean high-security. Security investment must match the threat profile.
  3. Refusing to pay requires preparation — recovery without the decryption key demands planning before an incident occurs.
  4. Qilin targets via phishing. Email security, simulation training, and enforced MFA are essential.

Case 2: Indonesia's National Data Centre (PDNS 2) — June 2024

Government data centre server room

Attacker: Brain Cipher (LockBit 3.0 variant) | Ransom demand: USD $8 million

On 20 June 2024, Brain Cipher disrupted 282 public services across 210 government institutions, including immigration processing and airport services. Attackers disabled Windows Defender across PDNS 2 servers over three days before triggering encryption. The Indonesian government refused to pay. On 3 July, the group released the decryption key for free — but weeks of disruption had already been suffered. Sources: BSSN/Kominfo · FULCRUM · Medium

Key lessons:

  1. Patch management is foundational. CVE-2023-28252 — disclosed over a year earlier — was the entry point.
  2. Monitor for security control tampering. Windows Defender was disabled for three days without triggering alerts.
  3. Offline, air-gapped backups are the last line of defence. Backup strategy must be tested, not assumed.
  4. Centralisation carries catastrophic risk. A single breach cascaded across 282 government services.

Case 3: Change Healthcare (USA) — February 2024

Healthcare professional at hospital computer

Attacker: BlackCat/ALPHV | Impact: 100 million individuals affected; estimated cost $2.457 billion

BlackCat/ALPHV struck Change Healthcare — a division of UnitedHealth Group processing approximately one-third of all US medical claims. Electronic payments and medical claims processing halted nationwide. Patients were turned away and forced to pay out of pocket. UnitedHealth reportedly paid a $22 million ransom — then faced a second extortion attempt from a splinter group. Sources: CM Alliance · Spin.AI · BlackFog

Key lessons:

  1. MFA on every remote access point, without exception. Attackers gained access via a Citrix portal with NO multi-factor authentication.
  2. Audit third-party dependencies. Vendor security posture is your risk.
  3. Never pay without professional crisis negotiators. Payment led directly to double extortion.

Case 4: MGM Resorts (USA) — September 2023

Hotel lobby with digital displays

Attacker: Scattered Spider | Total cost: Over $100 million

Scattered Spider called MGM's IT helpdesk, impersonated an employee found on LinkedIn, and convinced staff to reset MFA credentials. Once inside, they deployed ransomware that locked slot machines, ATMs, hotel room key systems, and reservation platforms globally. MGM refused to pay. Caesars Entertainment, hit in the same campaign, reportedly paid a substantial ransom. Sources: Inszone Insurance · CM Alliance

Key lessons:

  1. Social engineering defeats technology. Mandatory helpdesk verification procedures are essential.
  2. Upgrade to phishing-resistant MFA. FIDO2 hardware keys resist fatigue attacks.
  3. Implement least-privilege access and monitor lateral movement.

Case 5: Marks & Spencer (UK) — April 2025

Retail store digital point-of-sale system

Attacker: Scattered Spider (DragonForce ransomware) | Impact: ~£300 million in lost operating profit

Scattered Spider struck Marks & Spencer, disrupting online orders, contactless payments, and internal systems for weeks. M&S disclosed the impact as approximately £300 million in lost operating profit — one of the most financially damaging cyberattacks in UK corporate history. Sources: CM Alliance · RiskSight

What Every Malaysian and Indonesian Organisation Must Do Now

Security operations centre monitoring dashboard
  1. Implement MFA everywhere — on every remote access point, VPN, cloud console, and privileged account. Use phishing-resistant MFA (FIDO2) for administrative access.
  2. Maintain offline, air-gapped, tested backups — 3-2-1 rule: three copies, two media types, one offline and off-site. Test restoration quarterly.
  3. Patch aggressively — the PDNS 2 attack exploited a Windows CVE patched over a year earlier.
  4. Deploy EDR with 24/7 monitoring — catch the pre-encryption phase before ransomware activates.
  5. Segment your network — OT and IT networks must be isolated from each other.
  6. Train your people — phishing simulation and clear helpdesk verification procedures are non-negotiable.
  7. Build and test an incident response plan — Malaysia's PDPA and Indonesia's PDPB carry notification obligations.
  8. Know who to call — a pre-arranged incident response provider relationship compresses time from detection to containment.

Under Attack Right Now?

Primary Guard's incident response team operates 24/7 across Malaysia and Indonesia, providing immediate triage, forensic containment, decryption negotiation support, and supervised recovery.

Use our Ransomware Recovery Triage Tool to identify your threat type in under two minutes and get a step-by-step recovery roadmap tailored to your situation.

Contact us: +603 8601 0561 | info@primaryguard.com | Emergency consultation

Primary Guard is Malaysia's leading managed cybersecurity provider, serving enterprises across Malaysia and Indonesia. Visit primaryguard.com.