Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology7 min read

Reported ransomware incidents are just the tip of the iceberg | TechRadar

Ransomware attacks taking place under the radar are growing Discover insights about reported ransomware incidents are just the tip of the iceberg | techradar.

TechnologyInnovationBest PracticesGuideTutorial
Reported ransomware incidents are just the tip of the iceberg | TechRadar
Listen to Article
0:00
0:00
0:00

Reported ransomware incidents are just the tip of the iceberg | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Reported ransomware incidents are just the tip of the iceberg

Ransomware attacks taking place under the radar are growing

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

The intense scrutiny that organizations face after highly publicized ransomware attacks has become one of the defining features in this era of cyberattacks, as regulators, customers and shareholders all look for answers.

The consequences are often highly visible and public attention can last for months; from schools forced to close down, manufacturers halting production lines and healthcare providers racing against the clock to restore services for patients.

Yet these widely reported attacks represent only a small fraction of the overall threat.

Most ransomware attacks are opportunistic. Here’s how you can stop attackers

‘Big Game Hunters’: UK ransomware volume drops significantly 'but the reality is more alarming' – big orgs are being hit harder and with greater success

Backups won’t save you from this version of ransomware

The reality is far more extensive as the daily onslaught of ransomware attacks extends across every sector and size of organization.

This is because attackers are motivated principally by one thing: the value and presence of the company’s data.

The extent of ransomware attacks taking place under the radar is growing. From our own research tracking ransomware activity, we discovered 7,079 undisclosed attacks in 2025, accounting for 86% of all attacks that year. This represented a sharp rise of 37% rise compared with the previous year.

While everyone knows ransomware is a threat, these blind spots present a problem. It means Boards and security leaders are making risk decisions without knowing the real threat level, whilst regulators are developing policies and regulations based on seeing a fraction of the problem. Tracking trends, sharing information and understanding the full extent of the threat is vital for shaping the strategies and solutions that protect against this fast-changing and highly evolved ransomware criminal ecosystem.

Regulatory frameworks are clear on an organization's responsibilities when it comes to reporting incidents that impact essential services and breaches that involve personal data. Under the GDPR, organizations are required to disclose personal data breaches within 72 hours, and the ICO also recommends that law enforcement is advised.

Nevertheless, a breach that reaches the public eye means damaging publicity, questions from shareholders and customers venting their frustration. Set this brand damage against the option of paying the ransom quietly and organizations may attempt to resolve incidents without public disclosure.

The changing tactics of ransomware groups may also contribute to an organization's response. Data encryption forced companies' hands – systems stopped working, people noticed and hiding it was impossible. However, data exfiltration - which now happens in the vast majority of attacks - works differently as payments could be made without anyone outside the building even knowing.

The rise of the cyber hacker - does clout matter more than cash?

When confidence becomes a risk: The gap between cyber resilience readiness and reality

The gap between what's happening in the real world and what gets reported matters for several reasons. When a regulatory framework is built on incomplete data, entire industries may underestimate their exposure because they're only seeing a proportion of what's happening.

The consequences extend beyond policy. Threat intelligence sharing, which relies on organizations reporting what they've seen, breaks down when most incidents stay secret. Cybersecurity vendors develop defenses against the attacks they know about, while critical information on tactics, techniques and procedures remain in the shadows.

When such a large proportion of these attacks goes unreported, the security industry struggles to track how quickly adversaries are advancing and we're fighting an enemy we can only partially observe. This is particularly significant at a time when AI has entered the picture with attackers able to speed up reconnaissance, find vulnerabilities and scale their operations faster than any manual work could achieve.

Fixing this requires changes to both law and culture and the goal should be giving policymakers and security teams the information they need.

Change is coming, with proposals for new legal requirements to strengthen incident reporting obligations. In the UK, the government has consulted on reforms that would require businesses to report ransomware incidents within 72 hours. While it remains unclear whether this will apply to all ransomware incidents, organizations should begin preparing now to ensure they can identify and report incidents promptly and effectively.

This focus better reflects modern ransomware, where data theft often causes more damage than downtime, and these new requirements will bring more incidents into the open.

Information sharing within industries needs to improve as well. The logic is straightforward; when attacks stay hidden, everyone becomes more vulnerable, especially when ransomware groups keep evolving their methods and attackers get faster at what they do. The longer we operate on incomplete information, the further behind we fall.

Whilst the threat across all industries and organizations remains high, businesses must continue to focus on protections to boost resilience, rather than waiting until regulations force them to take action.

With criminals’ intent on data theft as leverage for extortion, the best defensive strategy is to make your organization a hard target and minimize the risk of being the next victim of an attack that puts you under the microscope of regulators, media and the wider public.

We've Reviewed, Rated, and Ranked The Best Firewall Software.

This article was produced as part of Tech Radar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of Tech Radar Pro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

You must confirm your public display name before commenting

1 Dutton Ranch fans are already hoping one unhinged character 'doesn't survive' first season of Taylor Sheridan's Yellowstone spinoff series — but for the 'dumbest reason'

2'You can really tell how long a game has been in development' — 007 First Light features a cameo of an internet star who went viral years ago

3 Could AI-powered dash cams save businesses millions in legal fees?

4 The Pope just warned AI could create ‘new forms of dehumanization’ — and his message feels aimed straight at Big Tech

5 Ghost CMS flaw hijacked to target hundreds of websites with Click Fix attacks — here's how to stay safe

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.