Sophos, a global cybersecurity firm, has raised fresh concerns over the growing complexity of ransomware threats in the retail sector, as it released its fifth annual State of Ransomware in Retail report on Tuesday.

The report, based on a survey of 361 IT and cybersecurity leaders across 16 countries, revealed that 46% of ransomware attacks in the retail industry originated from unknown security gaps, highlighting persistent visibility challenges.
According to the findings, 58% of organizations whose data was encrypted paid the ransom — the second-highest rate in five years — while the median ransom demand doubled to $2 million compared to 2024.
Sophos also noted that 30% of attacks exploited known vulnerabilities, marking the third consecutive year this has been the top technical root cause.
“Retailers globally are facing a more complex threat landscape where adversaries are constantly on the lookout for and exploiting existing vulnerabilities,” said Chester Wisniewski, Global Field CISO at Sophos. “The need to implement comprehensive security strategies is even more apparent.”
The report identified Akira, Cl0p, Qilin, PLAY, and Lynx as the most active ransomware groups targeting retailers. Account compromise and business email compromise (BEC) were also cited as major threats.
Despite the challenges, the report highlighted signs of progress. The percentage of attacks stopped before encryption reached a five-year high, and the average cost of recovery (excluding ransom) dropped by 40% to $1.65 million.
Sophos recommends that retailers adopt proactive measures such as patching known vulnerabilities, deploying endpoint protection, maintaining reliable backups, and partnering with Managed Detection and Response (MDR) providers for 24/7 threat monitoring.
The full report is available on Sophos.com, with additional industry insights expected later this year.










