Ransomware remains one of the most disruptive and expensive forms of cybercrime. The newest full-year datasets mostly reflect attacks observed in 2024 and reporting cycles published in 2025, which already show the trends shaping ransomware risk in 2026.
ransomware statistics
Top ransomware statistics
Ransomware was present in 44% of breaches analyzed in Verizon’s 2025 DBIR.
Among SMB breaches in the same report, 88% involved ransomware.
Ransomware was linked to 75% of system intrusion breaches in Verizon’s 2025 DBIR.
Chainalysis estimated that ransomware attackers received about $813.55 million in victim payments in 2024, down from $1.25 billion in 2023.
Chainalysis also reported that data leak sites posted more victims in 2024 than in any previous year.
Recorded Future identified 56 new ransomware data leak sites in 2024, according to Chainalysis.
The FBI’s IC3 received 4,878 cyber-threat complaints from critical infrastructure organizations in 2024.
The FBI said the most reported cyber threats among critical infrastructure organizations were ransomware and data breaches.
The top five ransomware variants by IC3 complaints were Akira, LockBit, RansomHub, FOG, and PLAY.
Sophos found that exploited vulnerabilities were the most common technical root cause of ransomware incidents, appearing in 32% of attacks.
Compromised credentials accounted for 23% of ransomware incidents in Sophos’ 2025 study.
Malicious email caused 19% of incidents, while phishing caused 18%.
Sophos said only 50% of attacks resulted in data encryption in 2025, down from 70% in 2024.
Among organizations that had data encrypted, 97% were able to recover their data somehow.
Backups were used to restore encrypted data in 54% of incidents, the lowest rate in six years.
49% of victims paid the ransom to get data back, down from 56% a year earlier.
Sophos put the typical ransom demand at $1,324,439 in 2025, down 34% year over year.
Sophos put the typical ransom payment at $1 million in 2025, down 50% year over year.
57% of ransom demands and 52% of ransom payments were still $1 million or more.
The average cost to recover from a ransomware attack, excluding any ransom payment, was $1.53 million in 2025.
53% of organizations fully recovered within one week, up from 35% in 2024.
Coveware said the median ransom payment in Q4 2024 was $110,890.
Coveware also said only 25% of ransomware victims paid in Q4 2024.
By Q4 2025, Coveware said payment rates had fallen to about 20%, its lowest tracked level.
BlackFog recorded 1,174 publicly disclosed ransomware incidents in 2025, up 49% year over year.
BlackFog counted 7,079 undisclosed victims in 2025 and estimated that about 86% of attacks were never publicly reported.
Healthcare accounted for 22% of disclosed ransomware attacks in BlackFog’s 2025 data.
The United States accounted for 58% of disclosed ransomware attacks in BlackFog’s 2025 dataset.
BlackFog said organizations in 135 countries were affected by ransomware in 2025.
Technical root causes of ransomware attacks
Sophos’ 2025 ransomware study shows that vulnerability exploitation and credential theft remain the main ways attackers get in, while email-based delivery is still a major channel.
Label
Bar
Value
Exploited vulnerability
32%
Compromised credentials
23%
Malicious email
19%
Phishing
18%
Brute force attack
6%
Max = 32%. Widths: Exploited vulnerability 100.00%, Compromised credentials 71.88%, Malicious email 59.38%, Phishing 56.25%, Brute force attack 18.75%.
Technical entry points matter, but Sophos found that staffing, skills, and security visibility problems were nearly as common as direct technical causes.
Label
Bar
Value
Lack of expertise
40.2%
Unknown security gap
40.1%
Lack of people/capacity
39.4%
Lack of protection
39.0%
Known security gap not addressed
38.2%
Poor quality protection
37.1%
Human error
34.2%
Max = 40.2%. Widths: Lack of expertise 100.00%, Unknown security gap 99.75%, Lack of people/capacity 98.01%, Lack of protection 97.01%, Known security gap not addressed 95.02%, Poor quality protection 92.29%, Human error 85.07%.
Critical infrastructure sectors with the most ransomware complaints
The FBI’s 2024 IC3 data shows ransomware pressure remained especially high across U.S. critical infrastructure, with manufacturing, healthcare, and government facilities near the top.
Label
Bar
Value
Critical manufacturing
258 complaints
Healthcare and public health
238 complaints
Government facilities
220 complaints
Financial services
190 complaints
Information technology
138 complaints
Max = 258 complaints. Widths: Critical manufacturing 100.00%, Healthcare and public health 92.25%, Government facilities 85.27%, Financial services 73.64%, Information technology 53.49%.
Recent payment and recovery benchmarks
Metric
Value
Source
2024 on-chain ransom payments
$813.55 million
Chainalysis
Typical ransom demand in 2025
$1,324,439
Sophos
Typical ransom payment in 2025
$1,000,000
Sophos
Average recovery cost in 2025, excluding ransom
$1.53 million
Sophos
Median ransom payment in Q4 2024
$110,890
Coveware
Median ransom payment in Q4 2025
$325,000
Coveware
Victims paying in Q4 2024
25%
Coveware
Victims paying in Q4 2025
About 20%
Coveware
What these ransomware statistics mean
The big pattern is that ransomware is still widespread, but victim behavior is changing. Payment volumes and payment rates have been falling, yet recovery costs remain high and critical infrastructure continues to absorb heavy pressure.
The attack path is also becoming clearer. Vulnerability exploitation, credential compromise, and email-based intrusion still drive a large share of incidents, which means patching, identity protection, phishing resistance, and segmentation remain the practical controls that matter most.
Another important takeaway is that public reporting still understates the problem. BlackFog’s 2025 estimates suggest most ransomware incidents never become public, so disclosed attacks only show part of the market.
For businesses, the statistics point to a simple reality: paying less often does not mean ransomware is becoming harmless. Downtime, data theft, recovery work, and sector-specific disruption still make it one of the highest-impact cyber risks.
Sources
Verizon. 2025 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/
Sophos. The State of Ransomware 2025. https://www.sophos.com/en-us/blog/the-state-of-ransomware-2025
Sophos PDF report. The State of Ransomware 2025. https://assets.sophos.com/X24WTUEQ/at/9brgj5n44hqvgsp5f5bqcps/sophos-state-of-ransomware-2025.pdf
Chainalysis. 35% Year-over-Year Decrease in Ransomware Payments, Less than Half of Recorded Incidents Resulted in Victim Payments. https://www.chainalysis.com/blog/crypto-crime-ransomware-victim-extortion-2025/
FBI. FBI Releases Annual Internet Crime Report. https://www.fbi.gov/news/press-releases/fbi-releases-annual-internet-crime-report
Coveware. Will Law Enforcement Success Against Ransomware Continue in 2025? https://www.coveware.com/blog/2025/1/31/q4-report
Coveware. Mass Data Exfiltration Campaigns Lose Their Edge in Q4 2025. https://www.coveware.com/blog/2026/2/3/mass-data-exfiltration-campaigns-lose-their-edge-in-q4-2025
BlackFog. BlackFog’s 2025 State of Ransomware Report Reveals 49% Increase in Attacks Year on Year. https://www.blackfog.com/2025-state-of-ransomware-report-released/
Note: several 2025 reports are based on incidents experienced during the previous 12 months, so some “2025” figures describe attacks that occurred during 2024.
Make your studio sessions extraordinary with the top 10 closed-back headphones that combine superior sound quality and comfort—discover which ones made the cut!
Stay connected outdoors with the top 10 mesh WiFi systems designed for seamless coverage; discover which one will enhance your connectivity experience.