In that six-month period, India recorded 21 ransomware incidents, underscoring a growing threat to the nation’s digital infrastructure
India has emerged as the third most targeted country in the Asia-Pacific region for ransomware attacks during the first half of 2025, trailing only Taiwan and Singapore, according to Cyble’s Global Threat Landscape Report: H1 2025.
In that six-month period, India recorded 21 ransomware incidents, underscoring a growing threat to the nation’s digital infrastructure. The sectors most affected include information technology, banking, financial services and insurance (BFSI), and manufacturing, highlighting the calculated nature of these assaults on core economic pillars.
Cyble’s intelligence suggests that ransomware groups such as Qilin, RansomHub and Medusa have increasingly treated Indian businesses as high-value targets, deploying precision attacks that exploit sector-specific vulnerabilities and even regional political instability.
Across the APAC region, ransomware attacks surged globally by 54 per cent year-on-year, with just three major operators — CL0P, Akira and Qilin — responsible for 34 per cent of all incidents. Notably, Qilin spearheaded activity in APAC, with 32 affiliate-driven attacks leveraging a Ransomware-as-a-Service model.
The report underscores a disturbing trend: ransomware campaigns are becoming more centralised and sophisticated, with a small number of actors wielding disproportionate influence and reach.
Why this matters
Strategic targeting: The prevalence of attacks on industries like BFSI and manufacturing signals that ransomware is not a scattershot threat — it is tailored, informed and opportunistic.
Widening gap in resilience: As attacks intensify, businesses — especially mid-sized and regional firms — must urgently boost cyber defences, adopt zero-trust models, and improve threat monitoring.
Global threat consolidation: The dominance of just a handful of ransomware groups amplifies the risk — they hold outsized power in the cyber-crime ecosystem.

