A new report from Chainalysis shows that ransom payments to ransomware groups decreased by 35% (year-over-year) in 2024, reaching a total of $813.55 million. In 2023, victims had paid $1.25 billion.

According to the same report, only about 30% of victims who participated in negotiations ended up paying the ransom to the hackers.
See also: New York Blood Center Enterprises hit by ransomware
The above findings are encouraging, especially in a difficult year for ransomware. During 2024, a Fortune 50 company paid $75 million to the ransomware Dark Angels group . Additionally, according to NCC Group, 2024 was the year with the highest volume of ransomware breaches, with at least 5,263 successful attacks .
This is also confirmed by Chainalysis, which observed that disclosures on data leak websites increased.
Victims resist and do not pay ransom to ransomware groups
The decline in ransomware payments, despite increased attacks in 2024, shows that victims are becoming more resilient. Organizations are investing more in cybersecurity, adopting better practices, and implementing stronger protections.
See also: Frederick Health hit by Ransomware attack
Additionally, victims have learned that they cannot trust hackers. Even if they say they will decrypt systems or delete stolen data, nothing is certain. Furthermore, legal pressure has increased, resulting in more organizations refusing to negotiate.
Another factor that played a key role in reducing ransom payments was law enforcement operations targeting ransomware gangs last year. Most notably, “OperationCronos” disrupted the most notorious and prolific ransomware group at the time, LockBit.
This, combined with the ALPHV/BlackCat group's exit scam, were significant blows to the threat landscape.
See also: New Akira Linux Ransomware Attacks VMware ESXi Servers
Ultimately, Chainalysis data shows that average payout amounts decreased in 2024 (despite the payment to the Dark Angels hackers), indicating that even when payments were made, downward negotiations were often taking place.

Ransomware protection
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using solutions email security for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Back up your data regularly
- Stay up to date on the latest ransomware trends and tactics used by attackers
Source: www.bleepingcomputer.com
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
