Skip to content

Ransomware Statistics 2026: Attack Rates, Ransom Payments, Recovery Costs and Root Causes

Ransomware statistics for 2026 from Verizon, Sophos, Chainalysis, the FBI and Coalition: share of breaches, who pays, median ransoms, recovery costs.

Invadel TeamSeptember 14, 20267 min read

Ransomware numbers disagree with each other more than any other category of security statistic, because each report counts a different population: confirmed breaches, survey respondents who were hit, insurance claims, or payments traced on a blockchain. This page lays them side by side with the population stated, so the right number can be used for the right argument. Sources are the 2026 editions of Verizon’s DBIR, Sophos’s State of Ransomware and Chainalysis’s Crypto Crime Report, the FBI’s 2025 Internet Crime Report, Coalition’s 2026 claims data, IBM’s Cost of a Data Breach and Hiscox. We update the page as each is published.

How to cite: link to this page or to the primary source beside each figure. Always state which population a figure describes.

1. How common ransomware is

  • Ransomware was present in 48% of confirmed data breaches in 2025, up from 44%. (Verizon 2026 Data Breach Investigations Report, 22,000 breaches)
  • 96% of ransomware victims whose organization size was known were small and medium-sized businesses. The previous year’s report put ransomware in 88% of small business breaches against 39% at large organizations. (Verizon 2026 and 2025 DBIR)
  • Ransomware affected 39% of breached organizations in IBM’s study, up from 34% the year before and 24% in 2023. (IBM Cost of a Data Breach Report 2026, 602 organizations)
  • 27% of small and medium-sized enterprises across seven countries were hit by ransomware in the past twelve months. (Hiscox Cyber Readiness Report 2025, 5,750 businesses)
  • More than 52% of cyberattacks with a known motive were driven by extortion or ransomware; espionage accounted for 4%. (Microsoft Digital Defense Report 2025)
  • Claimed victims posted to ransomware leak sites rose 50% in 2025, the most active year on record. Claimed victims in US critical infrastructure, supply chain and logistics, and government rose 45 to 56%. (Chainalysis 2026 Crypto Crime Report)
  • The FBI received 3,611 ransomware complaints in 2025, up from 3,156 in 2024 and 2,825 in 2023, and identified 63 new ransomware variants, about five a month. The variants hitting critical infrastructure most often were Akira, Qilin, RansomHub, LockBit and Medusa; the most affected sectors were critical manufacturing, healthcare and government facilities. (FBI IC3 2025 Internet Crime Report)

2. Who pays, and how much

The payment figures differ by report because the denominators differ. All five are shown.

Source Population Share that paid Ransom figure
Verizon 2026 DBIR confirmed breaches with ransomware 31% median payment below $140,000
Sophos 2026 2,158 organizations hit, data encrypted 48% median demand $698,000, median payment $769,000
Coalition 2026 insured policyholders, 2025 claims 14% (86% refused) initial demands up 47%
Chainalysis 2026 payments traced on-chain 28% (all-time low) median payment $59,556, total $820 million
Hiscox 2025 SMEs hit by ransomware, survey 80% 60% recovered all or part of their data; 31% of payers got further demands
  • Total ransomware payments fell to about $820 million in 2025, down 8% from a revised $892 million in 2024, the second consecutive annual decline, even as attacks reached record levels. (Chainalysis 2026)
  • The median payment traced on-chain rose to $59,556 from $12,738, a 368% increase: fewer victims pay, but the ones who do pay more. (Chainalysis 2026)
  • Sophos’s median ransom demand fell 65% over two years to $698,000, and 51% of organizations that paid negotiated the amount down. (Sophos 2026)
  • State and local government paid most often (72%); retail least often (32%). (Sophos 2026)
  • Initial access brokers, who sell the footholds ransomware crews use, received at least $14 million on-chain in 2025; the average price of access to a victim fell from $1,427 in early 2023 to $439 in early 2026. (Chainalysis 2026)

3. What an attack actually costs

  • The average cost to recover from a ransomware attack, excluding any ransom, was $1.7 million, up 11% year over year. (Sophos 2026)
  • Ransomware was the most expensive type of cyber insurance claim at an average loss of $269,000. Claims involving data theft cost more than twice as much as encryption-only claims. (Coalition 2026)
  • Ransomware incidents at small and medium-sized enterprises accounted for 81% of insurance claims that included business interruption. (NetDiligence Cyber Claims Study 2025, 10,402 claims)
  • Reported ransomware losses to the FBI rose 159% to $32.3 million, a figure that excludes lost business, downtime and remediation, which is why it is a small fraction of the insurer numbers. (FBI IC3 2025)
  • 56% of attacks succeeded in encrypting data, up from 50%. Organizations of 100 to 250 employees stopped the attack before encryption 34% of the time. Backups were used to recover in 66% of encryption cases, up 12 points. (Sophos 2026)
  • Extortion now leans on reputation as much as data: 41% of ransomware attacks threatened brand reputation, 35% employee data, 31% intellectual property. 70% of ransomware claims were dual extortion, encryption plus data theft. (IBM 2026Coalition 2026)

4. How ransomware gets in

  • Root causes in 2025: malicious email 26%, phishing 24%, compromised credentials 23%, exploited vulnerabilities 18%, brute force 6%. Exploited vulnerabilities fell 14 points and are no longer the leading cause for the first time in four years; email and phishing together are half of all incidents. (Sophos 2026)
  • The technical entry point was an exposed application or system in 38% of attacks, a user device in 30%, a firewall in 21%, a VPN in 8%, an IoT device in 3%. (Sophos 2026)
  • 79% of attacks began with an identity-based approach. 97% of victims whose credentials were compromised had MFA enabled somewhere; the Active Adversary data shows it was missing where it mattered in 59% of cases. (Sophos 2026)
  • Across all breaches, vulnerability exploitation was the initial vector in 31% and a third party was involved in 48%. (Verizon 2026 DBIR)
  • The average time from initial access to lateral movement fell to 29 minutes; the fastest observed was 27 seconds. (CrowdStrike 2026 Global Threat Report)

What this means for testing: every entry point on that list is in scope for a standard engagement. An external network penetration test covers the exposed systems, firewalls and VPNs; an internal network test shows how far an attacker gets from one compromised device in 29 minutes; a phishing test measures the inbox.

5. Healthcare, the sector attackers prefer

  • Healthcare was among the three critical sectors most affected by ransomware in FBI complaints, alongside critical manufacturing and government facilities. (FBI IC3 2025)
  • The average healthcare breach cost $6.64 million, the highest of any industry even after falling 10.5% from $7.42 million. (IBM 2026)
  • Hacking and IT incidents caused more than 80% of large healthcare breaches in 2025, up from 49% in 2019; the DaVita ransomware attack alone affected 2,689,826 people. (HIPAA Journal)

The full healthcare set is on our data breach statistics page, and the testing requirements are on the HIPAA penetration testing page.

6. What the numbers say to do

  1. Remove the exposed entry points. 38% of attacks came through an exposed application or system and 31% of breaches through an unpatched vulnerability. Test the perimeter before the ransomware crew’s scanner does: external penetration testing.
  2. Fix identity where it matters. 79% of attacks started with identity and 97% of victims had MFA somewhere. Enforce it on VPNs, remote access and admin accounts first.
  3. Test the inbox. Half of ransomware starts with email. A phishing test gives the real click rate.
  4. Rehearse the 29 minutes. An internal penetration test or a red team exercise shows how far one compromised workstation reaches, and whether detection fires before encryption.
  5. Do not plan to pay. The organizations that paid least often (Coalition’s 14%) were the ones with backups, a plan and insurance. Backups recovered 66% of encrypted victims.

Our explainer on how ransomware attacks work walks through a real attack chain step by step.

Sources

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

All articlesRansomware

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation