Ransomware Statistics 2026: Verified Attack & Cost Data

ObaidaAlsulaiman

Obaida Al-Sulaiman, Information Security Manager at ScanTitan,

Ransomware Statistics 2026 Verified Attack & Cost Data
Table of Contents

Ransomware statistics can look contradictory because attack volume, breach involvement, encryption, ransom demands, payments, recovery costs, and leak-site claims measure different parts of the same problem. The latest 2026 evidence shows a clear pattern: ransomware is involved in more breaches, more attacks reach encryption, and the criminal ecosystem is fragmenting, while a larger share of victims refuses to pay. This guide separates those denominators, compares ransomware statistics by year, and uses primary-source data wherever a current source is available.

Short answer: Ransomware appeared in 48% of breaches in Verizon’s 2026 DBIR, up from 44% in the prior report. Sophos found that 56% of ransomware attacks encrypted data, 48% of encrypted victims paid, and average recovery costs reached $1.7 million. Chainalysis estimated more than $820 million in on-chain ransomware payments during 2025 even as claimed attacks rose 50%.

Last updated: September 2026. Figures are labeled by source population and data year so breach share, survey results, leak-site claims, cryptocurrency flows, and reported losses are not treated as interchangeable.

Key ransomware statistics for 2026 at a glance

The most useful ransomware statistics are the ones with a clear denominator. The table below prioritizes current primary sources and states exactly what each number measures. Some figures describe confirmed breaches, some describe organizations already hit by ransomware, and others describe cryptocurrency flows or FBI complaints. Reading them together gives a broader picture, but combining them into one universal “ransomware rate” would be misleading.

Metric Latest figure What it measures Source
Breaches involving ransomware 48% Share of breaches in Verizon’s 2026 DBIR dataset Verizon 2026 DBIR
Ransomware victims that did not pay 69% Victims in Verizon’s 2026 reporting dataset Verizon 2026 DBIR
Median ransom paid $139,875 Median payment in Verizon’s 2026 reporting dataset Verizon 2026 DBIR
Attacks that encrypted data 56% Organizations hit by ransomware in Sophos’s 2026 survey Sophos 2026
Encrypted victims that paid 48% Organizations whose data was encrypted Sophos 2026
Median ransom demand $698,000 Median attacker demand across Sophos respondents Sophos 2026
Median ransom payment $769,000 Median payment among Sophos respondents that paid Sophos 2026
Average recovery cost $1.7M Average recovery cost excluding ransom across Sophos respondents Sophos 2026
Backup-based recovery 66% Encrypted-data cases recovered using backups Sophos 2026
Identity-based starts 79% Ransomware attacks beginning with an identity-based approach Sophos 2026
Active ransomware/extortion groups 109 Distinct groups identified by IBM X-Force in 2025 IBM X-Force 2026
Growth in active groups 49% Year-over-year increase from 73 groups in 2024 to 109 in 2025 IBM X-Force 2026
On-chain ransomware payments >$820M Cryptocurrency payments attributed to ransomware actors in 2025 Chainalysis 2026
Change in on-chain payments -8% 2025 versus Chainalysis’s updated 2024 estimate Chainalysis 2026
Growth in claimed attacks +50% Year-over-year change in claimed attacks tracked by Chainalysis Chainalysis 2026
FBI ransomware complaints >3,600 Complaints reported to IC3 during 2025 FBI IC3 2025
FBI reported ransomware losses >$32M Direct losses reported to IC3; excludes many downstream costs FBI IC3 2025

Are ransomware attacks increasing in 2026?

Yes by several important measures, but not by every measure. Verizon found ransomware in 48% of breaches in its 2026 DBIR, up from 44% in the prior report. Chainalysis reported a 50% increase in claimed ransomware attacks during 2025, while IBM X-Force identified 109 active ransomware and extortion groups, up from 73 a year earlier. At the same time, ransomware revenue did not grow with attack volume: Chainalysis estimated 2025 on-chain payments fell about 8%. The correct 2026 conclusion is therefore not simply “ransomware is up.” Attack reach and criminal participation are rising while victim willingness to pay is weakening.

How common is ransomware in 2026

What is increasing: breach involvement, encryption success, claimed attacks, and the number of active groups. What is falling: the share of victims paying in Verizon’s dataset and aggregate on-chain ransomware revenue.

Ransomware statistics by year

Year-over-year comparisons are safest when the denominator stays the same. A common SEO mistake is to put a breach-share percentage from Verizon next to a victim survey from Sophos and call it a trend. The tables below keep like with like: Verizon for ransomware’s share of breaches, Sophos for encryption and ransom economics, and Chainalysis for attributed cryptocurrency payments. Report year and underlying incident window can differ, so these are trend indicators rather than a single global census of attacks.

Report year Ransomware share of breaches Source Interpretation
2024 32% Verizon DBIR Baseline before the sharp two-year increase
2025 44% Verizon DBIR 12 percentage-point increase
2026 48% Verizon DBIR Highest share reported in the current series
Sophos report year Encryption rate Median ransom demand Key change
2023 75% Not used here for direct demand comparison Encryption reached the recent peak cited by Sophos
2025 50% $1.32M Lower encryption than the 2023 peak
2026 56% $698K Encryption rose, while median demand fell sharply
Payment year Attributed on-chain payments Change Source
2023 About $1.25B Record-level payment year in Chainalysis reporting Chainalysis
2024 Updated estimate: $892M Down materially from 2023 Chainalysis 2026 update
2025 More than $820M About 8% lower year over year Chainalysis 2026

The ransomware trend

Why ransomware can increase while payments fall

The apparent contradiction is one of the most important ransomware trends of 2026. More groups can attack more organizations without producing more total revenue if fewer victims pay, negotiations reduce settlements, or operators target smaller victims. Chainalysis found 2025 payments fell about 8% while claimed attacks rose 50%. Verizon reported that 69% of ransomware victims in its 2026 dataset did not pay. Sophos, using a different denominator, found 48% of organizations whose data was encrypted paid. Those figures are not inconsistent: they describe different populations. The market is expanding on the attack side while monetization per attempted victim is becoming less reliable.

Ransom demands, ransom payments, and recovery costs

Demand, payment, and recovery cost should never be presented as if they were the same statistic. Sophos’s 2026 study reported a $698,000 median demand and a $769,000 median payment among paying respondents, while average recovery costs reached $1.7 million and excluded the ransom itself. A median payment can exceed a median demand because the two medians are calculated from different subsets; it does not mean victims generally paid more than demanded. Verizon’s separate 2026 incident dataset reported a $139,875 median ransom paid. The spread between sources shows why every ransomware payment statistic needs its population and methodology beside it.

Are ransom payments rising or falling

Measure Figure Population Why it matters
Median ransom demand $698K Sophos respondents hit by ransomware What attackers initially asked for
Median ransom payment $769K Sophos respondents that paid What paying organizations actually transferred
Median ransom payment $139,875 Verizon 2026 reporting dataset Independent incident dataset with a different population
Average recovery cost $1.7M Sophos respondents Recovery expense excluding any ransom
2025 on-chain payments >$820M Attributed cryptocurrency transactions Tracked criminal revenue, not total victim impact

The real cost of a ransomware attack

Ransomware cost statistics are broader than the payment to the attacker. Recovery can include incident response, forensic investigation, system rebuilding, restoration, legal review, customer notification, lost productivity, lost sales, overtime, regulatory work, and reputational damage. Sophos reported an average recovery cost of $1.7 million in 2026, up 11% year over year, excluding the ransom. The FBI’s IC3 recorded more than $32 million in reported ransomware losses for 2025, but explicitly warns that its ransomware loss figure normally excludes lost business, time, wages, files, equipment, and third-party remediation. IC3 therefore represents a reported floor, not the total U.S. economic cost of ransomware.

The real cost of a ransomware attack

How ransomware attacks start in 2026

Sophos’s 2026 research marks a meaningful shift in root cause. Malicious email accounted for 26% of incidents and phishing for 24%, together representing half of surveyed ransomware attacks. Compromised credentials accounted for 23%, exploited vulnerabilities for 18%, and brute-force attacks for 6%. Sophos also reported that 79% of attacks began with an identity-based approach. The important lesson is not that patching stopped mattering. Exploited vulnerabilities remain a major entry route, and Verizon’s broader 2026 DBIR found vulnerability exploitation became the leading initial access vector across breaches overall. For deeper exploitation data, see our Vulnerability Statistics.

Root cause Share in Sophos 2026 Defensive priority
Malicious email 26% Email filtering, attachment and link controls, endpoint detection
Phishing 24% Phishing-resistant authentication, user verification, domain controls
Compromised credentials 23% MFA coverage, conditional access, credential monitoring
Exploited vulnerabilities 18% Exposure discovery, patching, exploit intelligence, scanning
Brute force 6% Rate limiting, MFA, lockout policy, exposed-service reduction

Websites and internet-facing applications are particularly important because they are continuously reachable and can expose vulnerable software to automated scanning. ScanTitan’s website vulnerability scanner is the single service link used in this article, placed here because vulnerability exploitation remains a documented ransomware entry route.

MFA is essential, but partial MFA coverage is not enough

One of the most useful 2026 findings is that MFA presence alone does not equal complete identity protection. Sophos reported that MFA was deployed in some capacity in 97% of incidents where compromised credentials were identified as the root cause. This does not show that MFA is ineffective. It shows that organizations can still have unprotected accounts, bypassable methods, legacy authentication, session theft, help-desk weaknesses, or conditional-access gaps. The practical metric to track is therefore not “Do we have MFA?” but “What percentage of privileged, remote, cloud, vendor, and workforce identities are covered by phishing-resistant MFA with monitored exceptions?”

Ransomware encryption and data recovery statistics

Encryption became more successful again in 2026. Sophos found that 56% of ransomware attacks resulted in encrypted data, up from 50% in the prior report, although still below the 75% peak it reported for 2023. Recovery resilience also improved. Sixty-six percent of encrypted-data cases used backups for recovery, up 12 percentage points from 2025, and 55% of affected organizations returned to operation within one week. These statistics explain why ransomware outcomes can improve even while encryption rises: organizations can fail to stop the payload but still avoid a catastrophic payment decision if tested backups and recovery procedures work.

Recovery takeaway: prevention and recovery are separate controls. Strong backups do not stop ransomware entry, and strong endpoint security does not guarantee restoration. Mature programs measure both.

Ransomware statistics by organization size

Smaller organizations face a measurable prevention gap in Sophos’s 2026 survey. Only 34% of organizations with 100 to 250 employees stopped ransomware before encryption or extortion, compared with 46% of organizations with 3,001 to 5,000 employees. That is a 12 percentage-point difference in the ability to contain an attack before the most damaging stage. The result should not be generalized to every small business worldwide because Sophos surveyed organizations with 100 to 5,000 employees that had already experienced ransomware. It does, however, provide a useful size-based comparison inside one consistent study. Our broader Small Business Cybersecurity Statistics page covers SMB-specific breach, cost, identity, and third-party data.

Ransomware statistics by industry

Industry comparisons vary depending on whether the source measures attack volume, ransom payment behavior, breach cost, or observed incident response cases. Sophos’s 2026 ransomware survey found major differences in payment behavior: 72% of local and state government organizations with encrypted data paid, the highest sector rate reported, while only 32% of retail organizations paid, the lowest. IBM X-Force reported manufacturing remained the most targeted industry in its 2025 threat data, followed by financial services and insurance. These figures should not be ranked in one combined table as if “most targeted” and “most likely to pay” mean the same thing.

Industry signal Latest finding Source Meaning
Highest payment rate in Sophos sector data Local and state government: 72% Sophos 2026 Share of encrypted victims in that sector that paid
Lowest payment rate in Sophos sector data Retail: 32% Sophos 2026 Share of encrypted victims in that sector that paid
Most targeted sector in IBM threat data Manufacturing IBM X-Force 2026 Observed attack concentration, not payment behavior
Next most targeted sector Financial services and insurance IBM X-Force 2026 Observed attack concentration

The ransomware market in 2026

The ransomware economy is becoming more fragmented. IBM X-Force identified 109 ransomware and extortion groups active in 2025, up from 73 in 2024, a 49% increase. IBM also reported that the dominance of attacks attributed to the top 10 groups fell by 25%, indicating that activity is spreading across more operators rather than consolidating around a few brands. This matters because law-enforcement disruption of one major group can be followed by rebranding, splintering, or affiliate migration. Ransomware-as-a-Service lowers the barrier to entry by separating malware development, access acquisition, deployment, negotiation, and laundering into specialized roles.

The ransomware market in 2026

Initial access brokers and the ransomware supply chain

Initial access brokers, or IABs, sell access to already-compromised organizations, allowing ransomware affiliates to skip part of the intrusion process. Chainalysis estimated that IABs received at least $14 million in on-chain payments in 2025 and found that spikes in IAB inflows tended to precede increases in ransomware payments and victim leak posts by roughly 30 days. It also reported that the average price for victim access fell from about $1,427 in Q1 2023 to $439 by Q1 2026, based on Darkweb IQ data. Cheaper access can support higher attack volume even when ransom revenue does not grow at the same rate.

Initial access brokers and the identity supply chain

Ransomware and cryptocurrency statistics

Cryptocurrency data gives one of the clearest views of ransomware monetization, but it is still incomplete because attribution improves over time. Chainalysis initially estimated 2024 ransomware payments at about $813 million; its 2026 analysis revised the 2024 figure upward to $892 million as additional transactions were attributed. For 2025, it estimated more than $820 million in payments, about 8% below the updated 2024 figure, while warning that the total could approach or exceed $900 million as attribution matures. That revision is exactly why a statistics article should date the estimate and avoid presenting an early blockchain total as permanently final.

Important correction: the older $813 million figure was an early estimate for 2024. Chainalysis later revised 2024 to $892 million. The current 2025 estimate is more than $820 million and may rise as attribution improves.

United States ransomware statistics from the FBI

The FBI’s 2025 Internet Crime Report recorded more than 3,600 ransomware complaints and more than $32 million in reported ransomware losses. Those numbers should be treated as a minimum. IC3 states that ransomware adjusted losses normally do not include lost business, time, wages, files, equipment, or third-party remediation services, and some organizations report an incident without reporting a dollar amount. The report also identified 63 new ransomware variants during 2025, averaging 5.25 newly identified variants per month. The top reported variants included Akira, Qilin, INC/Lynx/Sinobi, BianLian, Play, RansomHub, LockBit, DragonForce, SafePay, and Medusa.

FBI IC3 2025 metric Figure Scope note
Ransomware complaints More than 3,600 Voluntarily reported to IC3
Reported ransomware losses More than $32M Does not capture the full downstream business cost
New ransomware variants identified 63 Variants identified via IC3 during 2025
Average new variants per month 5.25 Derived directly from the FBI’s annual count

Ransomware, vulnerabilities, websites, APIs, and CMS exposure

Ransomware is often discussed as an endpoint problem, but the initial foothold can sit in public-facing software, a website, an API, a VPN, a firewall, or a third-party application. Sophos attributed 18% of its 2026 ransomware root causes to exploited vulnerabilities, while Verizon found software vulnerability exploitation became the leading initial access vector across breaches overall. That connects ransomware prevention directly to asset discovery and remediation. Our Website Hacking Statistics cover broader website compromise patterns, while API Security Statistics focus on API attack and breach data.

CMS ecosystems also matter because extensions can create internet-facing weaknesses that attackers automate against. For platform-specific disclosure data, see WordPress Plugin Vulnerability Statistics and WooCommerce Vulnerability Statistics. These pages should not be interpreted as ransomware prevalence studies; they document vulnerability exposure that can become one component of an intrusion chain.

What role is AI playing in ransomware?

The strongest 2026 evidence supports AI as an accelerator rather than a completely separate ransomware category. Verizon reported that generative AI bolstered 15% of attack techniques in its 2026 breach dataset, while IBM described AI as lowering barriers for reconnaissance, vulnerability discovery, credential abuse, and attack automation. IBM also observed more than 300,000 ChatGPT credential sets advertised on the dark web in 2025, illustrating the broader credential-theft ecosystem around AI services. None of those figures means 15% of ransomware attacks were “caused by AI.” The defensible conclusion is that AI can make existing attack stages faster and cheaper without changing the basic need for identity, email, patching, and recovery controls.

Should organizations pay a ransomware demand?

Payment statistics describe behavior, not a recommendation. The FBI and CISA generally discourage paying because payment does not guarantee data recovery, can fund future criminal activity, and may create sanctions or legal complications depending on the recipient. Verizon’s 2026 dataset found 69% of ransomware victims did not pay, while Sophos found 48% of encrypted victims paid. Sophos also reported that 51% of organizations that did pay negotiated below the initial demand. The practical goal is to build enough recovery capacity that payment is not the only path back to operation, while involving legal counsel, insurers, incident responders, and law enforcement when an actual incident occurs.

Statistics to stop citing

Ransomware content is crowded with memorable numbers that are either outdated, derived from opaque estimates, or repeated without the original denominator. Removing weak claims is part of building a better statistics page because it protects citation quality and prevents old numbers from competing with current primary evidence. The following claims should either be retired or heavily qualified.

“60% of small businesses close within six months of a cyberattack.” The National Cybersecurity Alliance has said this figure did not come from its research and that it does not recommend using it. Use current SMB evidence instead.
“A ransomware attack happens every N seconds.” These figures are usually annual estimates divided into seconds, not directly observed successful attacks. Prefer measured complaints, breach involvement, victim claims, or survey attack rates.
“Ransomware cost will reach $X trillion by year Y.” Large projected damage totals can be useful as scenarios but should not be mixed with measured payments or observed losses.
“$813 million was paid to ransomware in 2024.” That was Chainalysis’s early estimate. Its 2026 analysis revised 2024 upward to $892 million as attribution improved.

How to reduce ransomware risk using the 2026 data

The statistics point to a layered control model rather than one product. Identity and email deserve more attention because Sophos attributed half of incidents to malicious email and phishing and found 79% began with an identity-based approach. Vulnerability management still matters because exploited vulnerabilities accounted for 18% of Sophos root causes and software exploitation led initial access across Verizon breaches overall. Recovery controls matter because 56% of attacks still reached encryption. Use the data to prioritize the attack chain rather than buying controls in isolation.

  1. Harden identity coverage. Require phishing-resistant MFA where possible, remove legacy authentication, monitor privileged access, and audit third-party identities and recovery methods.
  2. Secure email and user workflows. Combine technical filtering with domain authentication, attachment controls, user verification, and fast reporting of suspicious messages.
  3. Discover and patch exposed vulnerabilities. Prioritize internet-facing weaknesses with real exploitation evidence. Our guide to How to Prioritize Vulnerability Remediation explains how to combine severity, exploit likelihood, exposure, and business context.
  4. Scan continuously rather than quarterly. New assets and vulnerabilities appear between audit windows. Continuous Vulnerability Scanning reduces the time between exposure, detection, remediation, and verification.
  5. Segment critical systems. Limit lateral movement from user endpoints, vendor accounts, and compromised applications into backups, identity infrastructure, and production systems.
  6. Back up offline and test restoration. A backup that has never been restored under pressure is an assumption, not a recovery plan.
  7. Rehearse incident response. Define legal, executive, technical, insurer, and law-enforcement contacts before an attack so the first hours are not spent deciding who owns the response.

How this ransomware statistics page differs from other lists

Large ransomware-statistics pages often maximize the number of bullets by mixing primary data, old surveys, vendor estimates, secondary articles, projections, and anecdotes. This page uses a different standard: current primary sources first, explicit denominators, year labels, source-lineage corrections, and separate treatment of breach share, survey outcomes, crypto payments, and FBI complaints. That makes the total number of statistics less important than whether a reader can quote one without changing its meaning. It also explains why two credible sources can publish different ransom-payment medians in the same year without either source necessarily being wrong.

Methodology and source notes

This article prioritizes the Verizon 2026 Data Breach Investigations Report, Sophos State of Ransomware 2026, Chainalysis 2026 Crypto Crime ransomware research, IBM X-Force Threat Intelligence Index 2026, and the FBI 2025 Internet Crime Report. Where a prior-year figure is used, it is labeled as historical comparison. Survey statistics are not treated as a global census; leak-site or claimed-attack data are not treated as confirmed total attacks; blockchain payments are not treated as total economic loss; and FBI complaints are not treated as the full U.S. incident count. Figures can change when publishers revise attribution, as Chainalysis did for its 2024 payment estimate.

Frequently asked questions

What percentage of breaches involve ransomware in 2026?

48%. Verizon’s 2026 Data Breach Investigations Report found ransomware involved in 48% of breaches in its dataset, up from 44% in the previous report. This measures ransomware involvement in confirmed breaches, not the percentage of every organization worldwide that was attacked.

Are ransomware attacks increasing?

Yes by attack-reach measures. Verizon’s ransomware breach share increased to 48%, Chainalysis reported claimed attacks up 50% year over year, and IBM X-Force identified 109 active ransomware and extortion groups in 2025, up 49%. However, Chainalysis estimated total on-chain ransomware payments fell about 8%, so attack activity and attacker revenue are moving in different directions.

How much is the average ransomware payment in 2026?

There is no single universal average. Sophos reported a $769,000 median payment among paying respondents in its 2026 survey, while Verizon reported a $139,875 median amount paid in its separate 2026 reporting dataset. The populations and methodologies differ, so the figures should not be blended.

What is the median ransom demand in 2026?

$698,000 in Sophos State of Ransomware 2026. Sophos said the median demand had fallen 65% over two years. A ransom demand is not the same metric as a ransom payment or the total cost of recovery.

How much does ransomware cost to recover from?

Sophos reported an average recovery cost of $1.7 million per incident in 2026, up 11% year over year and excluding the ransom. This is an average across the organizations in Sophos’s survey, not a universal cost for every business size.

What percentage of ransomware victims pay?

The answer depends on the denominator. Verizon’s 2026 dataset found 69% of ransomware victims did not pay, meaning 31% did. Sophos found 48% of organizations whose data was encrypted paid. Sophos’s denominator is specifically encrypted victims, so the two figures should not be presented as contradictory.

How do ransomware attacks usually start?

In Sophos’s 2026 survey, malicious email accounted for 26% of root causes, phishing 24%, compromised credentials 23%, exploited vulnerabilities 18%, and brute force 6%. Sophos also reported that 79% of ransomware attacks began with an identity-based approach.

How many ransomware groups are active?

IBM X-Force identified 109 distinct ransomware and extortion groups in 2025, up from 73 in 2024, a 49% year-over-year increase. The count reflects groups observed and identified by IBM, not every actor operating globally.

How much did ransomware operators receive in cryptocurrency in 2025?

Chainalysis estimated more than $820 million in on-chain ransomware payments during 2025, about 8% below its updated $892 million estimate for 2024. Chainalysis cautions that the 2025 total may rise as more transactions are attributed.

How many ransomware complaints did the FBI receive in 2025?

The FBI’s Internet Crime Complaint Center received more than 3,600 ransomware complaints in 2025, with reported ransomware losses exceeding $32 million. IC3 warns that this loss figure excludes many forms of business disruption and remediation cost, so it is a reported floor.

O
Obaida Al-Sulaiman
Information Security Manager
CISSPGWAPTGXPNGCIHCEH
Reviewed on September 8, 2026

Want vulnerability scanning that prioritizes for you?

ScanTitan continuously matches your site against the CVE/NVD database, then ranks findings by real-world exploitability — so you patch what matters first.

o

Information Security Manager · Dubai, UAE · 12+ years InfoSec experience

Obaida specialises in web application security, vulnerability management, and external attack surface reduction for SMB and mid-market organisations. All ScanTitan content is reviewed against live scan findings before publication.

Share :

Facebook
LinkedIn

Continue reading