A Growing Gap Between Ransomware Attacks and Public Disclosure

Ransomware prevention firm BlackFog has released its Q2 report on global ransomware activity, and the headline figure is striking: undisclosed ransomware attacks rose 40% year on year. In other words, a growing share of ransomware incidents are happening without the public, regulators, or even affected customers ever finding out through official channels.

That distinction matters. Ransomware attacks that make headlines are usually the ones where attackers publicly claim credit, leak stolen data, or force an organization into a disclosure because customers, partners, or media notice the disruption. Undisclosed attacks are different. These are incidents that victim organizations either quietly resolve, pay off, or otherwise manage without triggering a public report, even though data may have been accessed, encrypted, or exfiltrated in the process.

BlackFog's data suggests this quieter category of attack is now growing faster than the more visible, publicly reported ones. For an industry that has spent years trying to improve breach transparency, that's a notable shift, and one with real consequences for anyone whose personal information might be sitting inside a company's systems.

Why "Undisclosed" Doesn't Mean "Contained"

It's tempting to assume that if an attack never makes the news, it must have been minor or successfully contained. BlackFog's findings push back on that assumption. A ransomware incident can involve significant data exfiltration, meaning attackers copy sensitive files before or instead of encrypting systems, without the organization ever formally acknowledging it happened.

There are several reasons a company might avoid public disclosure: uncertainty about whether a breach meets legal reporting thresholds, a desire to avoid reputational damage, or simply a quiet negotiation and payment that resolves the situation before regulators get involved. None of these reasons make the underlying privacy risk disappear. If customer records, employee data, or health and financial information were exposed during an undisclosed attack, the people whose data was taken still face the same downstream risks, identity theft, fraud, targeted phishing, regardless of whether a press release was ever issued.

This is where the ransomware conversation increasingly overlaps with the vulnerability management conversation. Many ransomware operators gain their initial foothold through unpatched or actively exploited software flaws. Agencies like CISA continue to flag vulnerabilities that attackers are actively using to gain elevated access to systems, including issues like CVE-2026-31431, a Linux root access flaw exploited in the wild. When organizations fail to patch known exploited vulnerabilities quickly, they create exactly the kind of opening that leads to the ransomware incidents BlackFog is tracking, disclosed or not.

The Scale of the Undiscovered Problem

One reason undisclosed attacks are becoming more common may simply be the sheer volume of exploitable weaknesses across modern software. Researchers using AI-assisted analysis tools have recently demonstrated just how large that attack surface can be. Anthropic's Project Glasswing, for instance, showed that its Claude Mythos model was able to identify more than 10,000 high- or critical-severity vulnerabilities across major software infrastructure. When there are that many potential entry points, it becomes far easier to understand why ransomware groups keep finding new organizations to target, and why so many of those intrusions never surface publicly.

BlackFog's report reinforces a pattern that privacy and security researchers have warned about for years: the public record of ransomware activity is likely only a partial picture. Every visible attack that gets covered in the news probably has counterparts that were resolved privately, whether through backup restoration, negotiated settlements, or incident response teams working out of public view.

What This Means For You

For everyday consumers, the rise in undisclosed ransomware attacks is a reminder that breach notifications are not a complete early warning system. You may never receive an official notice that your data was involved in an incident, even if it was. That doesn't mean your information is automatically safe; it means the usual signals people rely on, like breach notification emails or news coverage, are becoming less reliable indicators of actual risk.

For businesses and IT teams, the report is a strong argument for closing the gap between known vulnerabilities and patching timelines, since delayed patching is frequently the entry point for the kind of quiet intrusions that never make headlines. It's also a reason to invest in monitoring for data exfiltration specifically, not just ransomware encryption, since attackers increasingly steal data even when they don't lock down systems.

Staying Ahead of Ransomware You Might Never Hear About

BlackFog's Q2 findings make clear that ransomware reporting statistics likely understate the true scope of the problem, given how many attacks go undisclosed. Rather than waiting for a headline or a notification letter, it's worth treating routine privacy hygiene as an ongoing habit rather than a reaction to news events.

A few practical steps worth taking now: use unique, strong passwords with a password manager so a breach at one company doesn't compromise your other accounts; enable multi-factor authentication wherever it's offered; monitor financial and credit accounts regularly for unfamiliar activity; and consider freezing your credit if you suspect your information may have been exposed in any incident, disclosed or not. For organizations, prioritizing patch management for actively exploited vulnerabilities and investing in tools that detect data exfiltration, not just encryption, can help close the gap that undisclosed ransomware attacks are currently exploiting.