HomeSecurityRansomware attacks are increasing, ransom payments are decreasing

Ransomware attacks are increasing, ransom payments are decreasing

Despite the explosive growth of ransomware attacks, the percentage of victims who end up paying the ransom has plummeted to 28% in 2025, a record low. The data comes from Chainalysis, which tracks blockchain payment flows over time and outlines a market that is radically changing its face.

The picture is contradictory: more attacks, but fewer victims giving in. However, behind the numbers lies a more complex reality, with cybercriminals adapting their business model.

Historical low in payments, but not in costs

According to Chainalysis, in 2024 the payout rate was 62.8%, while in 2022 it was 78.9%. The drop in three years is impressive and is attributed to improved incident response, increased regulatory scrutiny, international law enforcement operations practices , and intense fragmentation of the ransomware market

See also: Steaelite RAT: Data theft and ransomware in one tool

Ransomware attacks are increasing, ransom payments are decreasing

Despite the decline in victim compliance, total payouts for 2025 are estimated to approach or exceed $900 million, with $820 million in on-chain transactions recorded so far. The relative stability in total revenue, despite a 50% increase in attacks year-on-year, suggests that the ecosystem is in a restructuring phase.

Fewer pay, but they pay more

One of the most alarming findings is the explosive increase in average ransoms. From $12,738 in 2024, the average demand skyrocketed to $59,556 in 2025, a 368% increase.

This trend suggests that attackers are now targeting organizations with greater financial resilience and a higher risk of data breaches. Victims who decide to pay appear to be doing so not only to restore their systems, but also to from being disclosed or sensitive data.

Ransomware has become a double blackmail: data encryption and threat of leakage. In this context, the amount of payment is increasingly linked to the value of the stolen information.

Market fragmentation and 85 active groups

In 2025, 85 active ransomware groups, a significant increase from previous years, when the space was dominated by a few powerful Ransomware-as-a-Service (RaaS) platforms. This fragmentation makes coordinated prosecutions difficult and creates a more chaotic threat landscape.

ransomware ransom payments

Among the incidents that stood out were the attack on Jaguar Land Rover with estimated damages of $2.5 billion, the breach of Marks & Spencer by the Scattered Spider group, and the incident at DaVita Inc., where 2.7 million patient records were exposed.

See also: Google “hit” Chinese hacking group that has breached 53 organizations

The United States remains the main target, followed by Canada, Germany and the United Kingdom, confirming that developed economies continue to attract the interest of threat actors.

The role of Initial Access Brokers (IABs)

Of particular importance is the activity of Initial Access Brokers (IABs), who sell access to compromised networks. In 2025, they are estimated to have generated $14 million in revenue, a similar amount to the previous year and representing just 1.7% of total ransomware revenue.

However, analysis shows that increases in payment inflows to IAB often precede spikes in ransom payments and victim postings on leak sites by about 30 days, making their activity an indicator of upcoming attacks.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Also interesting is the drop in the average price of network access: from $1,427 in the first quarter of 2023 to just $439 in the first quarter of 2026. The decrease is attributed to automation, the use of artificial intelligence tools, and the oversupply of credentials from infostealer logs.

See also: SURXRAT: The expansion of an LLM-based Trojan into Android Malware

Ransomware attacks are increasing, ransom payments are decreasing

Ransomware in an adaptation phase

Despite the decline in payout rates, Chainalysis notes that the scale and sophistication of attacks are increasing. Groups are adapting, targeting fewer but higher-quality victims, with higher demands and more aggressive extortion tactics.

Researchers believe that ransomware is not declining, but rather entering a new phase of maturity. In an environment where fewer and fewer organizations are willing to pay, attackers are looking for ways to extract more value from each successful breach.

The result is a market smaller in payment volume, but more aggressive, more targeted, and potentially more dangerous for businesses that still underestimate risk.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS