Historical intelligence backfill. This assessment covers reporting originally published on 2025-10-22 and was added to the RWP archive on 2026-09-07.
Nozomi's summer 2025 ransomware map is sensor alerts, not leak-site headcount
22 October 2025 — May was the loudest month in their sensors, BlackSuit on top, US 56 percent of malware-associated alerts, UK 14.5 percent. Do not add it to Dragos's industrial leak-site series.
Bottom line up front
CONFIRMED Nozomi Labs, 22 October 2025 — six-month sensor view of ransomware-related alerts, not a leak-site census. May was the peak month. BlackSuit led (CISA: Royal successor; Royal/Conti lineage; combined ransoms cited over $370M in CISA's telling as Nozomi quotes it). Black Basta in the top three; Nozomi notes the February leak pushed the gang quieter but leftover modules still alerted. Top countries by alert share: United States 56.42 percent, UK 14.53 percent. Attribution caveats: reused IPs, imprecise family labels. This is OT/IoT sensor noise, not "1,211 industrial victims." Dragos Q3/Q4 posts remain the leak-site series. Process/ICS Stage 2: not claimed.
Historical backfill of 22 October 2025 reporting; added 7 September 2026.
What happened
A Labs chart pack for spring/summer 2025 detections.
Why it mattered
Mixing sensor-alert share with leak-site victim counts is how briefings lie. Keep the units straight.
Who / what was affected
Nozomi's deployed sensors, English-speaking-heavy. Not a global victim registry.
Technical context
Hunt BlackSuit/Royal leftovers. Do not retire Black Basta detections because of a chat leak.
Exploitation / threat status at the time
CONFIRMED Nozomi alert mix.
REPORTED CISA lineage notes as quoted.
What defenders should have done
- Keep Royal/BlackSuit playbooks.
- Do not brief "56 percent US" as 56 percent of all ransomware.
- Read Dragos industrial counts alongside, not instead.
RWP assessment
Confidence: High as telemetry mix; low as industrial-impact measure.
Defensive actions
- Label the chart "sensor alerts."
- Identity + backups still beat a new family name.
- Next Nozomi ransomware post is a different quarter — do not merge.
Sources
- Nozomi Networks Labs — Mapping the ransomware landscape — summer 2025
- CISA — BlackSuit as Royal successor (as cited by Nozomi)
- Dragos — Q3 2025 industrial ransomware analysis