patch&proof.
← Field manual

Economics / Field guide

Ransomware attacks are up. Payments are down. Both are true.

Ransomware attacks rose about 50% in 2025 while payments fell to around $820M and the payment rate hit a record low near 28%. Here is what drove the split.

From the supplied September 2026 research package. Historical figures and evolving policy require source review; see the correction record.

In 2025, claimed ransomware attacks rose roughly 50% to record levels. Over the same period, traced ransom payments fell 8% to about $820 million, and the share of victims who paid hit an all-time low of around 28%.

Activity and revenue have decoupled. That's the most encouraging development in security economics in years, and it's worth understanding why it happened — because the reasons are things defenders did on purpose.

The seven-year picture

Single-year figures mislead here. The series is what matters.

Year Traced payments What was happening
2019 ~$174M Double extortion invented
2020 ~$765M Big-game hunting matures; ~70% of victims paid
2021 ~$766M Colonial Pipeline; ~50% paid
2022 ~$567M Ukraine invasion fractures the ecosystem; ~41% paid
2023 ~$1.25B Record year, driven by the MOVEit campaign
2024 ~$892M ~35% collapse after the LockBit and ALPHV takedowns
2025 ~$820M Down 8% more, while attacks rose ~50%

One note on reading these: Chainalysis revises prior years upward as it identifies more wallets, so the same year appears differently across editions. These are the latest revised figures, and all of them are a floor rather than a total.

The trend that matters most: the payment rate fell from roughly 70% in 2020 to under 28% in 2025, and just 15% for attacks where data was stolen but nothing was encrypted.

Why fewer victims pay

Five reasons, roughly in order of significance.

Backups got better, and got tested. The organizations that can restore don't need to negotiate. This is the single biggest factor, and it's the one entirely within a defender's control.

The evidence that paying works got worse. Change Healthcare is the definitive case: the company paid $22 million, and the criminal group then defrauded its own affiliate and disappeared — leaving the victim having paid without the outcome. Vendor survey data from Fortinet suggests most payers recover some data but only a small minority recover all of it, and a large share are attacked again within a year — figures worth treating as directional rather than precise.

Legal exposure rose. Paying an entity under sanctions can violate US law on a strict-liability basis — meaning it doesn't matter whether you knew. That reality has put counsel in every payment conversation.

Insurers pushed back, both on paying and on the controls that make paying necessary.

And victims now have six years of precedent to reason from. As Coveware put it: after years of the industry preaching it, companies finally understand that paying rarely ends well.

Why attacks rose anyway

Because the cost of attempting one collapsed. Ransomware-as-a-service lowered the skill floor; access brokers sell the way in as a commodity; infostealer malware supplies credentials at scale. When each attempt is cheap, a falling success rate is survivable — you just run more attempts.

The result is a barbell. Chainalysis's median payment jumped to roughly $59,500 as crews chased smaller, faster-paying victims. Meanwhile Coveware's Q2 2026 data showed an average of $1.88 million against a median of $150,000 — a handful of very large payments pulling the mean, driven by groups targeting law firms.

Always read the median. Averages in this data are distorted by a few outliers, and vendors quoting only the average are usually quoting the scarier number.

Where the money isn't: the ransom is the cheap part

This is the most consistently underappreciated fact about ransomware, and it should change how organizations budget.

Sophos found the average recovery cost excluding the ransom was $1.53 million. Recovery timelines run to weeks; in some sectors, Sophos found median full restoration running over 100 days. Jaguar Land Rover's 2025 shutdown produced a £196 million direct charge and an estimated £1.9 billion in wider economic impact — with no ransom payment reported as the dominant cost at all.

The costs that actually accumulate: downtime, rebuilding identity infrastructure from scratch, notification and legal work, regulatory response, customer attrition, insurance disputes, and staff burnout.

When someone asks whether to budget for a possible ransom, the answer is that they're budgeting for the wrong line item.

The tactical shift: attacking recovery

Because backups became the effective defence, attackers adapted. Current casework describes deliberate "recovery denial" — going after backup infrastructure, identity systems, virtualization management planes, and cloud backup objects before deploying encryption.

This has a direct implication. Backups reachable with ordinary production credentials aren't backups from a ransomware perspective. What works:

  • Three copies, two media types, one offsite, one immutable or genuinely offline, zero errors on a tested restore
  • Backup infrastructure on separate credentials, not domain-joined
  • Identity and hypervisor management treated as your most sensitive systems
  • A restore actually performed, timed against the recovery target you committed to

Only 54% of ransomware victims successfully restored from backups in 2025 — a six-year low, per Sophos's annual survey. Usually because nobody had tried.

Law enforcement: disruption, not elimination

The takedown record is genuinely mixed, and honest coverage says so.

LockBit's infrastructure was seized in February 2024 and its leader sanctioned; the group returned in degraded form by September 2025. Lumma Stealer was taken down in May 2025 and partially resurged within months. ALPHV seized, then exit-scammed itself.

What does seem to work durably is arrests of Western-based actors. After UK police arrested four suspects over the M&S and Co-op attacks in July 2025, analysts observed months without new attributable intrusions from that crew, and described the arrests as having "spooked" others. Infrastructure is replaceable. People facing prosecution are less so.

The cumulative effect of disruption also shows up in the data: fragmentation into smaller, less professional operations, running weaker malware — some of it now decryptable.

What this means for you

If you're a small or mid-sized organization, you're the target profile. Coveware's caseload shows 75% of cases in the mid-market, with a median victim of around 750 employees. The controls that matter are in minimum viable security, and the one to do first is a tested restore.

If you're hit, the ransomware response playbook covers the first hour, who to call, and the payment decision. The short version: isolate but don't power off, protect backups immediately, call your insurer before engaging anyone, and report to law enforcement early — it's both useful and a mitigating factor if payment is ever considered.

If you're deciding whether to pay, that decision runs through counsel, your insurer, and a sanctions screen. Never alone, and never fast.


What to do next: Schedule a restore test this quarter — a real one, timed, from your offline copy. That single exercise does more to change your ransomware exposure than any purchase.

Related: Ransomware response playbook · The 2026 threat landscape · Minimum viable security · What security actually costs

Sources: Chainalysis Crypto Crime Report 2026 (Feb 2026) — payment totals 2019–2025, payment rates, median payments. Coveware by Veeam Q2 2026 (Jul 2026) — negotiated-case averages and medians, exfiltration-only payment rate. Sophos State of Ransomware 2025 (Jun 2025) — recovery costs, restoration rates, payment survey. Verizon 2026 DBIR. Mandiant M-Trends 2026 — recovery-denial tactics and access-broker handoff. Company disclosures for Change Healthcare and Jaguar Land Rover.

Evidence & dates

Follow the source.

Source published
See individual source / original research
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval