The essentials
- In its 2025 Panorama, ANSSI records 128 ransomware compromises; micro, small, and mid-sized businesses account for 48% of victims, versus 37% in 2024.
- Attackers often try to encrypt, erase, or disable backup infrastructure to slow recovery and improve their odds of collecting a ransom.
- ANSSI’s 3-2-1 rule: three copies on different media, including one offline—and a restore that is actually tested.
The figure: size is not protection
In its 2025 cyber threat panorama, published in March 2026, ANSSI reports 128 ransomware compromises in 2025, slightly fewer than in 2024. The threat remains significant, and the breakdown is telling: micro, small, and mid-sized businesses are the largest victim category at 48% of cases (37% in 2024), ahead of local authorities (11%) and healthcare (8%, rising).
Sophos’s annual survey in France, covering 185 companies hit by ransomware, gives a sense of entry points: vulnerability exploitation (30% of cases), malicious email (24%), and compromised credentials (23%). It also reports that 60% of companies used backups to recover encrypted data, versus 70% the previous year.
Why backups are targeted first
ANSSI’s guide on information-system backup states plainly: it is common for an attacker to try to encrypt, erase, or disable backup infrastructure in order to slow rebuilding the information system and increase the chance of obtaining a ransom. A backup reachable from the compromised network is, in practice, a backup at risk.
What ANSSI recommends
- 01The 3-2-1 rule: three distinct copies of data (production plus two backups), on different media, including one offline.
- 02An offline backup, even if less frequent than regular local backups.
- 03Treat backup as administration: dedicated administrator accounts for each backup instance, with secure administration practices.
- 04Back up the backup infrastructure itself: catalogues, import procedures, hardware lists, encryption keys.
- 05Practise restoring, regularly, rather than discovering on incident day that a copy is unusable.
Sources
This note was drafted with AI tools from the cited sources, then reviewed and published under the responsibility of Jordan FOUASSIER, publication director. We summarise the facts and add our reading; source text and images are not reproduced. An error? Write to contact@aigyrosgroup.com.