Despite the explosive growth of ransomware attacks, the percentage of victims who end up paying the ransom has plummeted to 28% in 2025, a record low. The data comes from Chainalysis, which tracks blockchain payment flows over time and outlines a market that is radically changing its face.
The picture is contradictory: more attacks, but fewer victims giving in. However, behind the numbers lies a more complex reality, with cybercriminals adapting their business model.
Historical low in payments, but not in costs
According to Chainalysis, in 2024 the payout rate was 62.8%, while in 2022 it was 78.9%. The drop in three years is impressive and is attributed to improved incident response, increased regulatory scrutiny, international law enforcement operations practices , and intense fragmentation of the ransomware market
See also: Steaelite RAT: Data theft and ransomware in one tool

Despite the decline in victim compliance, total payouts for 2025 are estimated to approach or exceed $900 million, with $820 million in on-chain transactions recorded so far. The relative stability in total revenue, despite a 50% increase in attacks year-on-year, suggests that the ecosystem is in a restructuring phase.
Fewer pay, but they pay more
One of the most alarming findings is the explosive increase in average ransoms. From $12,738 in 2024, the average demand skyrocketed to $59,556 in 2025, a 368% increase.
This trend suggests that attackers are now targeting organizations with greater financial resilience and a higher risk of data breaches. Victims who decide to pay appear to be doing so not only to restore their systems, but also to from being disclosed or sensitive data.
Ransomware has become a double blackmail: data encryption and threat of leakage. In this context, the amount of payment is increasingly linked to the value of the stolen information.
Market fragmentation and 85 active groups
In 2025, 85 active ransomware groups, a significant increase from previous years, when the space was dominated by a few powerful Ransomware-as-a-Service (RaaS) platforms. This fragmentation makes coordinated prosecutions difficult and creates a more chaotic threat landscape.

Among the incidents that stood out were the attack on Jaguar Land Rover with estimated damages of $2.5 billion, the breach of Marks & Spencer by the Scattered Spider group, and the incident at DaVita Inc., where 2.7 million patient records were exposed.
See also: Google “hit” Chinese hacking group that has breached 53 organizations
The United States remains the main target, followed by Canada, Germany and the United Kingdom, confirming that developed economies continue to attract the interest of threat actors.
The role of Initial Access Brokers (IABs)
Of particular importance is the activity of Initial Access Brokers (IABs), who sell access to compromised networks. In 2025, they are estimated to have generated $14 million in revenue, a similar amount to the previous year and representing just 1.7% of total ransomware revenue.
However, analysis shows that increases in payment inflows to IAB often precede spikes in ransom payments and victim postings on leak sites by about 30 days, making their activity an indicator of upcoming attacks.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Also interesting is the drop in the average price of network access: from $1,427 in the first quarter of 2023 to just $439 in the first quarter of 2026. The decrease is attributed to automation, the use of artificial intelligence tools, and the oversupply of credentials from infostealer logs.
See also: SURXRAT: The expansion of an LLM-based Trojan into Android Malware

Ransomware in an adaptation phase
Despite the decline in payout rates, Chainalysis notes that the scale and sophistication of attacks are increasing. Groups are adapting, targeting fewer but higher-quality victims, with higher demands and more aggressive extortion tactics.
Researchers believe that ransomware is not declining, but rather entering a new phase of maturity. In an environment where fewer and fewer organizations are willing to pay, attackers are looking for ways to extract more value from each successful breach.
The result is a market smaller in payment volume, but more aggressive, more targeted, and potentially more dangerous for businesses that still underestimate risk.
Source: www.bleepingcomputer.com
