25 Ransomware Statistics You Should Know in 2026

Ransomware remains one of the most disruptive and expensive forms of cybercrime. The newest full-year datasets mostly reflect attacks observed in 2024 and reporting cycles published in 2025, which already show the trends shaping ransomware risk in 2026.

ransomware statistics
ransomware statistics

Top ransomware statistics

  • Ransomware was present in 44% of breaches analyzed in Verizon’s 2025 DBIR.
  • Among SMB breaches in the same report, 88% involved ransomware.
  • Ransomware was linked to 75% of system intrusion breaches in Verizon’s 2025 DBIR.
  • Chainalysis estimated that ransomware attackers received about $813.55 million in victim payments in 2024, down from $1.25 billion in 2023.
  • Chainalysis also reported that data leak sites posted more victims in 2024 than in any previous year.
  • Recorded Future identified 56 new ransomware data leak sites in 2024, according to Chainalysis.
  • The FBI’s IC3 received 4,878 cyber-threat complaints from critical infrastructure organizations in 2024.
  • The FBI said the most reported cyber threats among critical infrastructure organizations were ransomware and data breaches.
  • The top five ransomware variants by IC3 complaints were Akira, LockBit, RansomHub, FOG, and PLAY.
  • Sophos found that exploited vulnerabilities were the most common technical root cause of ransomware incidents, appearing in 32% of attacks.
  • Compromised credentials accounted for 23% of ransomware incidents in Sophos’ 2025 study.
  • Malicious email caused 19% of incidents, while phishing caused 18%.
  • Sophos said only 50% of attacks resulted in data encryption in 2025, down from 70% in 2024.
  • Among organizations that had data encrypted, 97% were able to recover their data somehow.
  • Backups were used to restore encrypted data in 54% of incidents, the lowest rate in six years.
  • 49% of victims paid the ransom to get data back, down from 56% a year earlier.
  • Sophos put the typical ransom demand at $1,324,439 in 2025, down 34% year over year.
  • Sophos put the typical ransom payment at $1 million in 2025, down 50% year over year.
  • 57% of ransom demands and 52% of ransom payments were still $1 million or more.
  • The average cost to recover from a ransomware attack, excluding any ransom payment, was $1.53 million in 2025.
  • 53% of organizations fully recovered within one week, up from 35% in 2024.
  • Coveware said the median ransom payment in Q4 2024 was $110,890.
  • Coveware also said only 25% of ransomware victims paid in Q4 2024.
  • By Q4 2025, Coveware said payment rates had fallen to about 20%, its lowest tracked level.
  • BlackFog recorded 1,174 publicly disclosed ransomware incidents in 2025, up 49% year over year.
  • BlackFog counted 7,079 undisclosed victims in 2025 and estimated that about 86% of attacks were never publicly reported.
  • Healthcare accounted for 22% of disclosed ransomware attacks in BlackFog’s 2025 data.
  • The United States accounted for 58% of disclosed ransomware attacks in BlackFog’s 2025 dataset.
  • BlackFog said organizations in 135 countries were affected by ransomware in 2025.

Technical root causes of ransomware attacks

Sophos’ 2025 ransomware study shows that vulnerability exploitation and credential theft remain the main ways attackers get in, while email-based delivery is still a major channel.

LabelBarValue
Exploited vulnerability
 
32%
Compromised credentials
 
23%
Malicious email
 
19%
Phishing
 
18%
Brute force attack
 
6%

Max = 32%. Widths: Exploited vulnerability 100.00%, Compromised credentials 71.88%, Malicious email 59.38%, Phishing 56.25%, Brute force attack 18.75%.

Operational weaknesses behind ransomware incidents

Technical entry points matter, but Sophos found that staffing, skills, and security visibility problems were nearly as common as direct technical causes.

LabelBarValue
Lack of expertise
 
40.2%
Unknown security gap
 
40.1%
Lack of people/capacity
 
39.4%
Lack of protection
 
39.0%
Known security gap not addressed
 
38.2%
Poor quality protection
 
37.1%
Human error
 
34.2%

Max = 40.2%. Widths: Lack of expertise 100.00%, Unknown security gap 99.75%, Lack of people/capacity 98.01%, Lack of protection 97.01%, Known security gap not addressed 95.02%, Poor quality protection 92.29%, Human error 85.07%.

Critical infrastructure sectors with the most ransomware complaints

The FBI’s 2024 IC3 data shows ransomware pressure remained especially high across U.S. critical infrastructure, with manufacturing, healthcare, and government facilities near the top.

LabelBarValue
Critical manufacturing
 
258 complaints
Healthcare and public health
 
238 complaints
Government facilities
 
220 complaints
Financial services
 
190 complaints
Information technology
 
138 complaints

Max = 258 complaints. Widths: Critical manufacturing 100.00%, Healthcare and public health 92.25%, Government facilities 85.27%, Financial services 73.64%, Information technology 53.49%.

Recent payment and recovery benchmarks

MetricValueSource
2024 on-chain ransom payments$813.55 millionChainalysis
Typical ransom demand in 2025$1,324,439Sophos
Typical ransom payment in 2025$1,000,000Sophos
Average recovery cost in 2025, excluding ransom$1.53 millionSophos
Median ransom payment in Q4 2024$110,890Coveware
Median ransom payment in Q4 2025$325,000Coveware
Victims paying in Q4 202425%Coveware
Victims paying in Q4 2025About 20%Coveware

What these ransomware statistics mean

The big pattern is that ransomware is still widespread, but victim behavior is changing. Payment volumes and payment rates have been falling, yet recovery costs remain high and critical infrastructure continues to absorb heavy pressure.

The attack path is also becoming clearer. Vulnerability exploitation, credential compromise, and email-based intrusion still drive a large share of incidents, which means patching, identity protection, phishing resistance, and segmentation remain the practical controls that matter most.

Another important takeaway is that public reporting still understates the problem. BlackFog’s 2025 estimates suggest most ransomware incidents never become public, so disclosed attacks only show part of the market.

For businesses, the statistics point to a simple reality: paying less often does not mean ransomware is becoming harmless. Downtime, data theft, recovery work, and sector-specific disruption still make it one of the highest-impact cyber risks.

Sources

  • Verizon. 2025 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/
  • Sophos. The State of Ransomware 2025. https://www.sophos.com/en-us/blog/the-state-of-ransomware-2025
  • Sophos PDF report. The State of Ransomware 2025. https://assets.sophos.com/X24WTUEQ/at/9brgj5n44hqvgsp5f5bqcps/sophos-state-of-ransomware-2025.pdf
  • Chainalysis. 35% Year-over-Year Decrease in Ransomware Payments, Less than Half of Recorded Incidents Resulted in Victim Payments. https://www.chainalysis.com/blog/crypto-crime-ransomware-victim-extortion-2025/
  • FBI IC3. 2024 IC3 Annual Report. https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
  • FBI. FBI Releases Annual Internet Crime Report. https://www.fbi.gov/news/press-releases/fbi-releases-annual-internet-crime-report
  • Coveware. Will Law Enforcement Success Against Ransomware Continue in 2025? https://www.coveware.com/blog/2025/1/31/q4-report
  • Coveware. Mass Data Exfiltration Campaigns Lose Their Edge in Q4 2025. https://www.coveware.com/blog/2026/2/3/mass-data-exfiltration-campaigns-lose-their-edge-in-q4-2025
  • BlackFog. BlackFog’s 2025 State of Ransomware Report Reveals 49% Increase in Attacks Year on Year. https://www.blackfog.com/2025-state-of-ransomware-report-released/

Note: several 2025 reports are based on incidents experienced during the previous 12 months, so some “2025” figures describe attacks that occurred during 2024.

You cannot copy content of this page

Scroll to Top