RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Defense

Defense / Reference · Method analysis · prepared 16 September 2026

Ransomware payment data disagrees because it measures different things

Coveware's payment rate keeps falling while Chainalysis's tracked total rose, and neither figure is a full ransomware count.

Visual for this record: Ransomware payment data disagrees because it measures different things
Visual published by bleepstatic.com, shown for identification of the record. Credit: bleepstatic.com · source page ↗ Rights: owner-review-pending.

What the document says

Three organisations publish recurring ransomware figures built on different data and different definitions. Coveware, a ransomware incident-response and negotiation firm, reports the share of its own handled cases in which a victim paid: 76 percent in 2019 falling to 41 percent across all of 2022 and 37 percent in that year's final quarter, based on the scores of ransomware victims it worked with directly. By the third quarter of 2025, Coveware reported that rate had fallen further, to a historical low of 23 percent across all impact scenarios. Chainalysis, a blockchain analytics firm, instead tracks total dollar value moving into cryptocurrency wallets it has identified as ransomware-linked, and reported that this total exceeded one billion dollars in 2023, a record, after falling to 567 million dollars in 2022. The FBI's Internet Crime Complaint Center reported a far smaller figure for 2024: 12.4 million dollars in direct ransomware losses from 3,156 complaints, which it explicitly states excludes business disruption, remediation and third-party recovery costs.

Confidence and limits

Each figure is well supported for the specific population its publisher actually measures: Coveware's negotiated caseload, Chainalysis's identified on-chain wallets, and IC3's self-reported US complaints. They are not measuring the same thing, so a falling Coveware payment rate and a rising Chainalysis dollar total are not necessarily in tension: fewer victims paying can coexist with a higher total paid if the payments that do happen have grown larger, or if more attacks occurred overall. Chainalysis states its own totals are conservative estimates likely to increase as new ransomware addresses are discovered, and previously revised its 2022 figure upward by 24.1 percent once more wallets were identified. IC3's ransomware figure is explicitly a floor, not an estimate of full economic damage.

Why it mattered

A reader who compares these series without their methods can reach contradictory-sounding conclusions from data that is not actually in conflict. Coverage that quotes a payment-rate decline as proof ransomware is retreating, or a rising blockchain total as proof it is worsening, can both be accurate descriptions of their own metric while missing that neither metric alone describes total ransomware harm.

Defensive takeaway

State which series, and which population, any ransomware statistic describes before citing it in a board report, and avoid combining figures from different publishers into one trend line.

  • Does our reporting distinguish a payment rate from a payment total, since a falling rate and a rising total can both be true at once?
  • Are we citing a vendor's identified-wallet total as if it were a complete measure of ransomware revenue?
  • Have we filed our own incidents with IC3, so the government figure reflects more of what actually happened?

None of these three sources is wrong; each measures its own defined population honestly and says so. The error is treating any one of them as a total, rather than as one labelled slice of a larger picture that no single publisher fully captures.

Defensive takeaway

Name the specific series and population behind any ransomware statistic you cite, rather than treating one publisher's figure as the total picture.

Each figure is confirmed directly from the vendor or agency that produced it, for the population that vendor or agency actually measures. None of the three sources measures the same population as another, so their trends are directionally informative but should not be averaged together.

Sources & reading trail

Improved Security and Backups Result in Record Low Number of Ransomware Payments ↗

States that 41 percent of victims paid in 2022 versus 76 percent in 2019, and that Q4 2022 fell to 37 percent, based on Coveware's negotiated-case data.

vendor-primary · Source published: 20 January 2023 · Retrieved: 16 September 2026

Insider Threats Loom while Ransom Payment Rates Plummet ↗

States a Q3 2025 ransom payment rate of 23 percent, described as a historical low across all impact scenarios.

vendor-primary · Source published: 24 October 2025 · Retrieved: 16 September 2026

Ransomware Payments Exceed $1 Billion in 2023, Hitting Record High After 2022 Decline ↗

States 2023 on-chain ransomware payments exceeded one billion dollars, revises the 2022 total upward by 24.1 percent, and explains the estimate's revision-over-time limitation.

vendor-primary · Source published: 7 February 2024 · Retrieved: 16 September 2026

2024 Internet Crime Report ↗

Reports 3,156 ransomware complaints and about 12.4 million dollars in direct reported losses for 2024, explicitly excluding business disruption and remediation costs.

government-primary · Source published: 1 April 2025 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.