Ransomware Statistics 2026: Verified Attack & Cost Data

Ransomware Statistics 2026 Verified Attack & Cost Data
ObaidaAlsulaiman

Information Security Manager · CISSP · CEH · OSCP

Table of Contents

Ransomware statistics are unusually easy to misread because several different numbers, the ransom demanded, the ransom paid, the recovery cost, and the payment rate, all describe the same incident from different angles and rarely agree. This page separates those measurements, sources each to its primary publisher, and shows why 2026 is a story of falling payments and rising damage at the same time. Ransomware now appears in a larger share of breaches than ever recorded, yet fewer victims pay, encryption rates climb, and the criminal market has splintered into more groups than at any point on record.

Short answerRansomware was present in 48% of confirmed breaches in the Verizon 2026 DBIR, the highest share on record. In Sophos State of Ransomware 2026, 56% of attacks succeeded in encrypting data and 48% of encrypted victims paid, while the average recovery cost reached 1.7 million dollars per incident. Payment rates are falling even as total damage rises.

Last updated: August 2026. This page is a source audit, reviewed quarterly. You are welcome to cite it with a link back to ScanTitan.

Key ransomware statistics at a glance

Each row states the figure, what it actually measures, the year of the underlying data, and the source, so an editor can quote it without misreading it. Where a figure is an all sizes average, the row says so.

Metric Figure What it measures Data year Source
Ransomware share of breaches 48% Share of confirmed breaches involving ransomware 2025 data Verizon 2026 DBIR
Attacks succeeding in encryption 56% Share of attacks that encrypted data (all sizes) 2026 Sophos State of Ransomware 2026
Encrypted victims who paid 48% All sizes; of organizations whose data was encrypted 2026 Sophos State of Ransomware 2026
Average recovery cost per incident $1.7M All sizes; excludes ransom; up 11% year over year 2026 Sophos State of Ransomware 2026
Median ransom demand $698,000 Median amount demanded (all sizes) 2026 Sophos State of Ransomware 2026
Median ransom payment $115,000 Median amount actually paid (broad incident dataset) 2025 Verizon DBIR
Attacks starting with an identity approach 79% All sizes; identity-based initial access 2026 Sophos State of Ransomware 2026
Active ransomware groups 109 Distinct active groups tracked in the year 2025 IBM X-Force 2026
Named victims on public leak sites ~8,159 Organizations listed on leak sites, up 58% 2025 Leak-site trackers
Total cryptocurrency ransom payments $813M On-chain payments to operators, down 35% 2024 Chainalysis

What these numbers actually measure

Ransomware statistics get misused when demand, payment, cost, and prevalence are treated as one thing. Five distinctions carry most of the risk.

  • Demand vs payment vs recovery cost. Read the ransom demand, the amount actually paid, and the recovery cost as three separate numbers. In 2026 the median demand, the median payment, and the average recovery cost are all different figures with different sources.
  • Prevalence vs cause. Note that “ransomware in 48% of breaches” means ransomware was present, not that it was the initial entry point. Entry vectors are measured separately.
  • Payment rate denominators. Distinguish the payment rate among all tracked victims from the payment rate among encrypted victims only. Verizon and Sophos count different populations, so their payment figures are not interchangeable.
  • Leak-site listings vs total attacks. Treat the count of organizations named on leak sites as a floor, not a total, since many victims never appear publicly and extortion-only attacks may not be listed.
  • On-chain payments vs total cost. Read Chainalysis crypto totals as tracked on-chain payments, which undercount the full economic damage of downtime, recovery, and legal exposure.

How common is ransomware in 2026?

Ransomware reached its highest recorded share of breaches this cycle. Verizon’s 2026 Data Breach Investigations Report (DBIR), built on more than 22,000 confirmed breaches across 145 countries in the window from November 2024 to October 2025, found ransomware present in 48% of breaches, the highest share in the dataset’s history. For a dated comparison, the 2025 DBIR put that figure at 44%, up from 32% the year before, which was the largest single year jump on record at the time. That is a prevalence measure, meaning ransomware was involved in the breach, not that it was always the way attackers got in.

Volume tells the same story from the criminal side. Public leak sites named roughly 8,159 organizations in 2025, an increase of about 58% year over year and the most active year on record according to leak-site trackers. That count is a floor rather than a total, because victims who negotiate quietly or who face extortion without a public listing never appear on it.

How common is ransomware in 2026

Are ransom payments rising or falling?

Payments are falling while damage rises, and holding both ideas at once is the key to reading 2026 correctly. The share of victims choosing to pay has dropped steadily. Verizon’s 2025 DBIR found that 64% of ransomware victims refused to pay, up from 50% two years earlier, and Sophos State of Ransomware 2026 reported that 48% of organizations whose data was encrypted paid the ransom, the second lowest rate on record. On-chain data agrees: Chainalysis measured total cryptocurrency payments to ransomware operators at 813 million dollars in 2024, down about 35% from the prior year.

Are ransom payments rising or falling

Demands and payments are also separate numbers that should never be merged. The table below shows the 2026 ransom economics side by side, each with its source and population, because a single blended figure would misrepresent all of them.

Figure Amount What it measures Source
Median ransom demand $698,000 Median amount demanded (all sizes) Sophos 2026
Mean ransom demand $3.13M Average amount demanded (all sizes) Sophos 2026
Median ransom payment $115,000 Median amount actually paid (broad dataset) Verizon DBIR 2025
Total crypto payments $813M On-chain payments to operators, 2024 Chainalysis

Sophos also reported that among organizations that chose to pay, 51% negotiated a settlement below the attacker’s initial demand, and that median demands have fallen 65% over two years. The direction is clear: victims are negotiating harder and refusing more often, which reduces attacker revenue per victim even as the number of victims grows.

The real cost of a ransomware attack

The real cost of a ransomware attack

The ransom is rarely the largest line item, which is why payment figures understate impact. Sophos State of Ransomware 2026 put the average recovery cost at 1.7 million dollars per incident across all organization sizes, up 11% year over year, a figure that excludes any ransom paid. Recovery covers downtime, forensics, restoration, legal exposure, and lost revenue, and it lands regardless of whether a ransom changes hands. IBM’s Cost of a Data Breach research reinforces the pattern from the breach angle, and IBM has reported that involving law enforcement measurably lowers the total cost of a ransomware related breach.

Operational recovery is improving even as costs rise. Sophos found that 55% of affected organizations were operational again within a week, a better result than in prior years, which reflects stronger backup and recovery practices. The human cost stayed high regardless: among organizations that had data encrypted, 99% reported lasting repercussions for their security teams, and in more than one in five cases the leadership team was replaced as a direct result. Cost, in other words, is not only financial.

The ransomware trend

The ransomware trend

The five year direction explains why 2026 feels contradictory: victims are resisting more effectively while the criminal market grows. The share of victims paying has fallen steadily, as Verizon found 64% of victims refused to pay in its 2025 dataset, up from 50% two years earlier, and Sophos found only 48% of encrypted victims paid in 2026. At the same time, attacks are more likely to reach encryption, rising to 56% in Sophos 2026 from 50% the year before, and demands are falling, with the median ransom demand down 65% over two years. The supply side moved the other way: IBM’s X-Force Threat Intelligence Index 2026 counted 109 active ransomware groups in 2025, a 49% increase, as takedowns splintered large operations into smaller ones.

The result is a market that extracts less per victim but reaches more of them.

Measure Prior period Latest Source
Victims refusing to pay 50% (two years earlier) 64% Verizon 2025 DBIR
Attacks encrypting data 50% 56% Sophos 2026
Median ransom demand baseline down 65% over two years Sophos 2026
Active ransomware groups fewer 109 (up 49%) IBM X-Force 2026

Should you pay the ransom?

The data argues against paying wherever backups make it avoidable, and most authorities including the FBI advise against it. Payment does not guarantee recovery: independent incident research has found that a large share of organizations that paid still failed to recover all of their data, so a ransom buys a decryption key of uncertain quality rather than a clean restoration. Payment also carries legal exposure, since transferring funds to a sanctioned group can breach regulations regardless of intent, and it funds the next wave of attacks. There is a measurable upside to a different path: IBM has reported that involving law enforcement in a ransomware related breach lowers the average total cost by a significant margin, an action that costs nothing. The consistent recommendation across primary sources is to prepare so that paying is never the only option, by maintaining tested offline backups, rehearsing recovery, and engaging law enforcement early. Falling payment rates suggest more organizations are reaching exactly that position.

How ransomware attacks begin

The entry points shifted decisively in 2026, and the change reshapes where defense should start. Sophos State of Ransomware 2026 found that 79% of ransomware attacks began with an identity based approach, and that for the first time in four years exploited software vulnerabilities were no longer the top root cause. The ranking instead placed malicious email at 26% and phishing at 24%, which together account for half of all incidents, followed by compromised credentials at 23%, exploited vulnerabilities at 18%, and brute force attacks at 6%.

That shift does not retire patching, it reframes it. Multi factor authentication (MFA) remains essential but is not sufficient on its own: Sophos found that MFA was deployed in some capacity in 97% of incidents where compromised credentials were the root cause, which shows that coverage gaps and bypasses still leave exposure. Because exploited vulnerabilities remain a major vector, closing internet facing weaknesses still matters, and the deeper treatment of exploitation timing lives on our vulnerability statistics page. A scheduled website vulnerability scanner closes the software side of the entry surface that ransomware operators buy access to.

Ransomware by industry

Attack volume and cost concentrate unevenly across sectors, and the two do not track together. By reported volume, manufacturing led global ransomware incidents in 2025, followed by technology and retail, with manufacturing showing a sharp year over year surge. By cost per incident, healthcare consistently ranks highest, carrying the most expensive breaches of any sector in IBM’s data for a long running streak, with IBM reporting healthcare breach costs well above 11 million dollars per incident, more than double the cross industry average. Government agencies show a distinct pattern: among sectors, local and state government organizations paid at the highest rate, at 72% of encrypted victims in Sophos data, even as overall payment rates fell.

The FBI’s Internet Crime Complaint Center (IC3) provides the United States reported-loss picture. IC3 recorded roughly 20.9 billion dollars in reported cybercrime losses in 2025 across all crime types, a 26% increase over 2024, and passed one million complaints for the first time. Those are voluntarily reported figures, so they function as a confirmed floor rather than a ceiling, and IC3 named healthcare, manufacturing, and government among the sectors most affected by ransomware specifically.

The ransomware market in 2026

The ransomware market in 2026

The criminal ecosystem fragmented rather than consolidated, which changes the threat picture. IBM’s X-Force Threat Intelligence Index 2026 identified 109 active ransomware groups in 2025, a 49% year over year increase, as law enforcement disruptions splintered major operations into smaller ones. No single actor exceeded roughly 13% market share, the most fragmented state the ecosystem has reached, with Qilin emerging as the most active group of the year after a sharp rise. Fragmentation matters for defenders because it means fewer predictable playbooks and more entrants using rented Ransomware as a Service (RaaS) infrastructure.

The RaaS model is what makes this scale possible. A core developer maintains the ransomware payload and licenses it to affiliates who handle targeting, initial access, and negotiation, which lowers the skill needed to run a campaign. Affiliates increasingly buy network access from initial access brokers rather than breaking in themselves, and identity based access has become the dominant procurement method, which is consistent with the 79% identity finding above.

Initial access brokers and the identity supply chain

Initial access brokers and the identity supply chain

The 79% identity finding has a supply chain behind it. Modern ransomware affiliates rarely break in themselves; they buy access. Initial access brokers compromise organizations, often through phishing or stolen credentials, then sell that foothold on criminal markets to ransomware operators who deploy the payload. Threat intelligence research has tracked a steady rise in access broker advertising year over year, and a large share of intrusions now begin with no malware at all, relying instead on valid credentials to log in as a legitimate user. Infostealer malware, built to harvest credentials at scale, feeds this market by supplying the raw material that brokers resell. The practical consequence for defenders is that stopping ransomware increasingly means protecting identity before encryption is ever possible, through monitoring for leaked credentials, enforcing strong authentication, and watching for the anomalous logins that mark a broker sale being cashed in. This is why the 2026 data keeps returning to identity as the decisive control point.

Statistics to stop citing

Honest ransomware statistics means refusing to repeat numbers that do not hold up.

“60% of small businesses close within six months of a ransomware attack.”The National Cybersecurity Alliance stated in 2022 that this figure did not come from its research and that it does not recommend using it. Use current incident data on recovery and cost instead, and see our small business cybersecurity statistics page for the SMB specific picture.

“A ransomware attack every N seconds.”These cadence figures are derived by dividing an annual estimate into seconds, not measured directly, and they do not describe confirmed successful attacks. Use measured attack volume and leak-site counts with their sources instead.

Single “total ransomware damage” mega figures.Very large annual damage totals are usually cross-source estimates or projections rather than measured numbers. If a total damage figure has no transparent methodology and named primary source, treat it as an estimate, not a measurement.

Source-lineage verification table

Popular claim Verdict What the source actually supports Use instead
60% of SMBs close within 6 months Do not cite The National Cybersecurity Alliance disavowed it (2022) Current recovery and cost data
A ransomware attack every N seconds Derived, not measured Division of annual estimates into seconds Measured attack volume and leak-site counts
Mega “total damage” annual totals Usually estimated Often a cross-source projection, not a measurement Named primary figures (IC3 losses, Chainalysis payments)
Ransom demand equals ransom paid Misleading Demand, payment, and recovery cost are separate Cite each with its source and population

How to reduce ransomware risk

The 2026 data points to a layered, identity first checklist rather than any single control.

1

Harden identity first.

With 79% of attacks starting from an identity approach, enforce MFA across privileged, remote, and high risk access, and close the coverage gaps that leave 97% of credential-root-cause victims exposed despite having some MFA.

2

Secure email and train staff.

Malicious email and phishing together drive half of incidents, so advanced email protection, authentication standards, and user awareness training belong near the top of the list.

3

Patch internet facing software.

Exploited vulnerabilities remain a major vector, so scheduled scanning and fast virtual patching close the software side of the entry surface.

4

Back up and rehearse recovery.

Falling payment rates track improving backups, so tested, offline backups and a rehearsed recovery plan are what turn an encryption event into a contained incident. If a site is compromised, professional website malware removal is more reliable than a surface cleanup.

Methodology and sources

This page is a source audit of ransomware statistics, built on a few principles: it prioritizes primary reports and links them where possible; it labels all sizes averages so they are not mistaken for a single segment; it keeps demand, payment, and recovery cost as separate figures; it treats leak-site counts as a floor and on-chain totals as tracked payments; it marks 2025 figures as dated comparisons where a 2026 figure exists; and it refuses to repeat a claim it cannot attribute to a named primary source. Primary and named sources include the Sophos State of Ransomware 2026, the Verizon 2025 and 2026 Data Breach Investigations Report, the IBM Cost of a Data Breach Report and X-Force Threat Intelligence Index 2026, the FBI Internet Crime Complaint Center 2025 Annual Report, and Chainalysis crypto crime research. This page is reviewed quarterly. You are welcome to cite it with a link back to ScanTitan.

Frequently asked questions

What percentage of breaches involve ransomware?

Ransomware was present in 48% of confirmed breaches in the Verizon 2026 DBIR, the highest share on record, up from 44% in the 2025 report and 32% the year before. That figure means ransomware was involved in the breach, not that it was always the initial entry point, which is measured separately.

How much is the average ransomware payment in 2026?

The numbers differ by source and population. Sophos State of Ransomware 2026 reported a median ransom demand of 698,000 dollars across all sizes, while Verizon’s broad incident dataset put the median amount actually paid at 115,000 dollars in 2025. Chainalysis measured total on-chain payments to operators at 813 million dollars in 2024, down about 35%. Demand, payment, and total crypto flow are three different measurements.

How much does a ransomware attack cost to recover from?

Sophos State of Ransomware 2026 put the average recovery cost at 1.7 million dollars per incident across all organization sizes, up 11% year over year, excluding any ransom paid. Recovery covers downtime, forensics, restoration, and lost revenue, which is why it typically exceeds the ransom itself. This is an all sizes average, not a small business specific figure.

Are ransomware payments going up or down?

Down. Sophos found that 48% of encrypted victims paid in 2026, the second lowest rate on record, and Verizon’s 2025 DBIR found 64% of victims refused to pay, up from 50% two years earlier. Chainalysis measured a 35% drop in total crypto payments in 2024. Payment rates are falling as backups improve, even though total damage continues to rise.

How do ransomware attacks usually start?

In Sophos State of Ransomware 2026, 79% of attacks began with an identity based approach. The root cause ranking placed malicious email at 26% and phishing at 24%, together half of incidents, followed by compromised credentials at 23% and exploited vulnerabilities at 18%. Multi factor authentication helps but is not sufficient alone, since it was present in some form in 97% of incidents where compromised credentials were the root cause.

O
Obaida Al-Sulaiman
Information Security Manager
CISSPGWAPTGXPNGCIHCEH
Reviewed onAugust 19, 2026

 

Want vulnerability scanning that prioritizes for you?

ScanTitan continuously matches your site against the CVE/NVD database, then ranks findings by real-world exploitability — so you patch what matters first.

o

Information Security Manager · Dubai, UAE · 12+ years InfoSec experience

Obaida specialises in web application security, vulnerability management, and external attack surface reduction for SMB and mid-market organisations. All ScanTitan content is reviewed against live scan findings before publication.

Share :

Facebook
LinkedIn

Continue reading

Your security score

?
/10
Unknown
Most sites we scan for the first time carry 3–7 OWASP findings they weren’t aware of.
Table of Contents

Weekly security digest

New CVEs, scan methodology updates, practical guides. One email per week — no sales pitch.

GDPR compliant · Unsubscribe any time