Two in five companies that pay cybercriminals to decrypt ransomware fail to recover their data, according to a survey of thousands of small and medium-sized businesses by insurance company Hiscox . The survey also revealed that ransomware remains a significant threat, with 27% of businesses surveyed reporting an attack in the past year.
See also: Hackers sell Monolock Ransomware on Dark Web forums

Of those affected, 80% — including both insured and uninsured businesses — paid ransom in an attempt to recover or protect critical data. However, only 60% were able to recover all or part of their data, according to Cybersecurity Readiness Report . A QBE Insurance earlier this month on cybercrime and cloud-based threats revealed that ransomware incidents almost tripled year-on-year in the first quarter of 2025, reaching 1,537 in the first quarter of 2025 compared to 572 in the same quarter last year.
CrowdStrike ’s 2025 State of Ransomware Survey , released this month, also found that 93% of victims who paid ransom had their data stolen anyway. Flawed ransomware encryption often frustrates recovery. Hiscox’s statistics on the state of ransomware victims highlight just one of the myriad challenges organizations face when trying to recover from ransomware attacks, industry experts say.
See also: AI-powered ransomware attacks: The top security concern

Even when decryption tools are provided, they may contain bugs or leave files corrupted or inaccessible. Many organizations also rely on untested — and vulnerable — backups. Making matters worse, many ransomware victims discover that their backups were also encrypted as part of the attack.
Modern ransomware attacks now include double or triple extortion routines, where attackers threaten to leak stolen data or launch distributed denial-of-service (DDoS) attacks even after payment. This fundamentally changes the calculus of what victims can expect in cases where they decide to make a ransomware payment, which often fails to resolve many of the problems that arise from a ransomware attack.
Some experts advise maintaining an agreement with an incident response company as part of disaster recovery plans that anticipate the very real possibility of a ransomware attack. Harper James’s Tsang warns against storing funds to pay criminals in the event of ransomware attacks. A more secure legal and strategic position comes from investing in resilience through strong security measures, well-tested recovery plans, clear reporting protocols, and cybersecurity insurance.
See also: MalTerminal malware with LLM creates GPT-4 for Ransomware

Cyberattack recovery after a ransomware attack should be treated similarly to disaster recovery with a fully defined, internal recovery plan, fully documented, where uncompromised data can be restored with confidence, experts advise.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
