July 2025 was another reminder that ransomware is not slowing down. From global construction firms to healthcare networks and SaaS giants, attackers showed once again that no industry is safe.
China Harbour Engineering Company was the first major victim of the month. The Devman group breached its systems on July 5, stealing sensitive engineering documents and threatening to leak them.
Just days later, Tyree Oil in the U.S. suffered a massive breach. Over 530 GB of financial and personal data was exfiltrated by the Play group from tax details to payroll files.
Finally, Mailchimp closed out the month with a major breach. Everest leaked a database of nearly one million lines of customer data, shaking trust in a leading SaaS provider.
Devman: a new player, but already aggressive, often stealing credentials with infostealers before encrypting files.
Play: veteran operators known for targeting VPNs and moving laterally via stolen RDP credentials.
Everest: persistent and well-equipped, using tools like Cobalt Strike and Metasploit for intrusions.
Lynx: a successor to the INC ransomware, expanding rapidly with dozens of confirmed victims.
Direwolf: 2025’s rising star in the ransomware world, combining phishing with zero-day exploits and advanced encryption.
The July incidents highlight three critical realities:
Double extortion is the norm stealing and leaking data to force ransom payments.
Healthcare and energy remain prime targets, with life and death consequences.
Attackers are refining their techniques, blending phishing, credential theft, and VPN exploitation into powerful attack chains.
Defending against ransomware requires more than just firewalls. Organizations must:
Patch systems promptly.
Train employees to recognize phishing campaigns.
Implement zero trust architectures.
Share intelligence across industries to stay ahead of evolving threats.
Ransomware in July 2025 was not just a collection of isolated incidents. It was a coordinated demonstration of how cybercriminals can disrupt economies, industries, and even healthcare systems. The message is clear: resilience is no longer optional it’s essential.