Middle East and APAC users hit most by ransomware globally: report

Middle East and APAC users hit most by ransomware: report

Share

Mumbai: Users in Middle East and APAC region faced more ransomware attacks globally, during the period from 2023-2024, revealed a new Kaspersky report, released ahead of International Anti-Ransomware Day on May 12.

Middle East and APAC region topped in the users share (0.72% and 0.60% respectively) attacked by ransomware, followed by Africa (0.41%), Latin America (0.33%), CIS (Commonwealth of Independent States) (0.32%) and Europe (0.28%) trailing behind, according to Kaspersky State of Ransomware Report–2025.

From 2023 to 2024 the users share affected by ransomware attacks globally increased to 0.44% by 0.02 p.p, as per the report based on Kaspersky Security Network data. Although it appears as a small percentage, however, the fact is attackers often don’t distribute this type of malware on a mass scale, but prioritise high-value targets, which reduces the overall number of incidents.

Middle East and APAC region users share

In the Middle East and APAC region, ransomware affected a higher share of users due to rapid digital transformation, expanding attack surfaces and varying levels of cybersecurity maturity. Enterprises in APAC were heavily targeted, driven by attacks on infrastructure and operational technology, especially in countries with growing economies and new data privacy laws.

While, Africa witnessed low ransomware due to the region’s lower levels of digitisation and economic constraints, which reduce the number of high-value targets. However, as countries like South Africa and Nigeria expand their digital economies, ransomware attacks are on the rise, particularly in the manufacturing, financial and government sectors.

Limited cybersecurity awareness and resources leave many organisations vulnerable, though the smaller attack surface means the region remains behind global hotspots.

Latin America region also experienced ransomware attacks, particularly in Brazil, Argentina, Chile and Mexico. Manufacturing, government, and agriculture, as well as critical sectors such as energy and retail were targeted, but economic constraints and smaller ransoms deter some attackers. Despite this, the region’s growing digital adoption is increasing its exposure to cyberattacks.

The CIS saw a smaller share of users encountering ransomware attacks. However, hacktivist groups such as Head Mare, Twelve and others active in the region often use ransomware such as LockBit 3.0 to inflict damage on target organisations. Manufacturing, government and retail sectors were the most targeted, due to varying cybersecurity maturity levels across the region affecting security.

Europe was consistently targeted with ransomware but benefits from robust cybersecurity frameworks and regulations deter some attackers. Sectors such as manufacturing, agriculture, and education were often targeted, but mature incident response and awareness limit the scale of attacks. The region’s diversified economies and strong defenses made it less of a focal point for ransomware groups than regions with rapid, less secure digital growth.

Interestingly, the report found that AI tools were increasingly used in ransomware development and attacks. RaaS (Ransomware-as-a-Service) model remained the predominant framework for ransomware attacks, fuelling their proliferation by lowering the technical barrier for cybercriminals.

“Ransomware is one of the most pressing cybersecurity threats facing organisations today, with attackers targeting businesses of all sizes and across every region,” said Dmitry Galov, Head of Research Centre for Russia and CIS at Kaspersky’s GReAT.

“Our report highlighted that there is a concerning shift toward exploiting overlooked entry points — including IoT devices, smart appliances, and misconfigured or outdated workplace hardware,” added Galov.

According to Galov, these weak spots often go unmonitored, making them prime targets for cybercriminals. Galov recommended that organisations need a layered defence: up-to-date systems, network segmentation, real-time monitoring, robust backups, and continuous user education to stay secure

“Building cyber awareness at every level is just as important as investing in the right technology,” concluded Galov.

In 2025, ransomware is expected to evolve by exploiting unconventional vulnerabilities. As organisations strengthen traditional defences, cybercriminals will refine their tactics, focusing on stealthy reconnaissance and lateral movement within networks to deploy ransomware with greater precision, making it harder for defenders to detect and respond in time.

The proliferation of LLMs tailored for cybercrime will further amplify ransomware’s reach and impact, the report stated.