Ransomware attacks hit a record 7,874 tracked incidents worldwide in 2025, up roughly 50% year over year (NCC Group, Annual Threat Intelligence Report 2025). Yet the money is moving the other way: Chainalysis traced about $820 million in on-chain ransom payments in 2025, down 8% from 2024, as the share of victims who paid fell to an all-time low of 28% (Chainalysis, 2026 Crypto Crime Report). For the businesses that do get hit, the average ransomware-related breach still cost $5.08 million (IBM, Cost of a Data Breach 2025). This analysis consolidates data from Sophos, Chainalysis, the FBI’s Internet Crime Complaint Center (IC3), the Verizon Data Breach Investigations Report, IBM, and 9 other primary sources into one reference, with every figure traced to the report that published it.
This roundup is ransomware-specific. For the wider threat landscape - phishing, DDoS, insider risk, and overall breach volume - see our cybersecurity statistics roundup.
TL;DR
- Ransomware incidents worldwide hit a record 7,874 in 2025, up about 50% (NCC Group, 2025).
- On-chain ransom payments fell to roughly $820 million, down 8% year over year (Chainalysis, 2026 Crypto Crime Report).
- Only 28% of victims paid in 2025, an all-time low, even as the median payment jumped 368% to $59,556 (Chainalysis, 2026 Crypto Crime Report).
- 79% of ransomware attacks in 2026 started with compromised identities (Sophos, State of Ransomware 2026).
- The average ransomware-related breach cost $5.08 million (IBM, Cost of a Data Breach 2025).
- Ransomware was present in 44% of all data breaches, up from 32% a year earlier (Verizon, 2025 DBIR).
- The FBI logged 3,611 ransomware complaints and $32.3 million in reported losses, up 259% year over year (FBI IC3, 2025 Internet Crime Report).
- Healthcare was the most-targeted critical-infrastructure sector with 460 ransomware attacks (FBI IC3, 2025).
- Coveware’s Q4 2025 payment rate fell to about 20%, the lowest it has ever recorded (Coveware, Q4 2025).
- Cybersecurity Ventures pegs global ransomware damage at $57 billion for 2025, rising to a projected $74 billion in 2026 (Cybersecurity Ventures, 2025).
1. Attack Volume Hit an All-Time High in 2025
The headline of 2025 is a widening gap between how often ransomware strikes and how much it earns. Tracked incidents set records while dollars collected slid, a sign that defenders are recovering from backups more often and refusing to pay. NCC Group counted 7,874 ransomware incidents in 2025, roughly 50% more than 2024, with February alone setting a monthly record of 886 attacks (NCC Group, Annual Threat Intelligence Report 2025). Data theft is now near universal in these incidents, which effectively turns every ransomware case into a reportable data-loss event - the reason we cover the overlap in our data breach statistics roundup.
| Metric | Value | Source |
|---|---|---|
| Tracked ransomware incidents worldwide, 2025 | 7,874 (about +50% YoY) | NCC Group, Annual Threat Intelligence Report 2025 |
| Year-over-year change in claimed victims | +50% (most active year on record) | Chainalysis, 2026 Crypto Crime Report |
| Disclosed leak-site victims, 2025 | 7,307 across 138 groups | Breachsense, Annual Ransomware Report 2025 |
| Most active ransomware group, 2025 | Qilin, 1,022 attacks (13% of total) | NCC Group, 2025 |
| Next most active groups | Akira 755; CL0P 517 | NCC Group, 2025 |
| Distinct active ransomware groups | 85 in Q3 2025 | Check Point Research, 2025 |
| Groups tracked hitting industrial orgs | 119 groups, 3,300 organizations | Dragos, 2026 OT/ICS Report |
| Highest-activity month, 2025 | February, 886 attacks (monthly record) | NCC Group, 2025 |
Note: Qilin and Akira drove a near-50% jump in leak-site postings versus 2024, and the ecosystem keeps fragmenting as brands splinter and rebrand.
2. Fewer Victims Pay, But the Ones Who Do Pay More
The payment picture is the clearest evidence that ransomware economics are under pressure. Payment rates fell to record lows across three independent datasets built from different methodologies - blockchain tracing, incident-response casework, and survey data - which is a rare consensus. Chainalysis put the 2025 payment rate at just 28%, an all-time low, while the median payment still climbed 368% to $59,556 (Chainalysis, 2026 Crypto Crime Report). Coveware’s frontline casework tells the same story from a different angle: its Q4 2025 quarterly report recorded a payment rate near 20%, the lowest it has ever measured.
| Metric | Value | Source |
|---|---|---|
| Total on-chain ransom payments, 2025 | ~$820M (down ~8% from $892M) | Chainalysis, 2026 Crypto Crime Report |
| Share of victims who paid, 2025 | 28% (all-time low) | Chainalysis, 2026 Crypto Crime Report |
| Median ransom payment, 2025 | $59,556 (+368% YoY) | Chainalysis, 2026 Crypto Crime Report |
| Coveware payment rate, Q4 2025 | ~20% (historic low) | Coveware, Q4 2025 Report |
| Coveware average / median payment, Q4 2025 | $591,988 / $325,000 | Coveware, Q4 2025 Report |
| Orgs with encrypted data that paid, 2026 | 48% | Sophos, State of Ransomware 2026 |
| Median ransom payout (breach corpus) | $115,000 | Verizon, 2025 DBIR |
| Victims who refused to pay | 64% (Verizon) / 63% (IBM) | Verizon 2025 DBIR; IBM 2025 |
Outlier: median payment figures diverge sharply by methodology - $59,556 on-chain (Chainalysis), $115,000 in the breach corpus (Verizon), and $325,000 in incident-response engagements (Coveware Q4) - so always read a “median ransom” number alongside its source.
3. What a Ransomware Attack Actually Costs
Ransom demands are only part of the bill. The larger cost sits in downtime, remediation, forensics, and lost business - which is why the all-in figures dwarf the payments Chainalysis traces on-chain. IBM measured the average ransomware-related breach at $5.08 million in 2025, well above the $4.44 million global average for all breaches (IBM, Cost of a Data Breach 2025). Zoomed out to the macro level, Cybersecurity Ventures estimates total global ransomware damage at $57 billion for 2025, a figure it projects will climb 30% to $74 billion in 2026.
| Metric | Value | Source |
|---|---|---|
| Average ransomware-related breach cost, 2025 | $5.08M | IBM, Cost of a Data Breach 2025 |
| Global average data breach cost, 2025 | $4.44M (down 9%) | IBM, Cost of a Data Breach 2025 |
| US average data breach cost, 2025 | $10.22M (up 9%, record high) | IBM, Cost of a Data Breach 2025 |
| Mean recovery cost excl. ransom (cross-sector) | $1.7M (2026) / $1.53M (2025) | Sophos, State of Ransomware 2026 / 2025 |
| Highest median ransom demand by country | UK, $2.5M | Sophos, State of Ransomware 2026 |
| Global ransomware damage (all-in), 2025 | $57 billion | Cybersecurity Ventures, 2025 |
| Projected global ransomware damage, 2026 | $74 billion (+30%) | Cybersecurity Ventures, 2025 |
Context: Cybersecurity Ventures projects the annual toll will reach $275 billion by 2031. Recovery has sped up sharply - Sophos found 55% of victims fully back within a week and 16% within a day (Sophos, State of Ransomware 2026), which is part of why fewer victims feel forced to pay.
4. How Attackers Get In: Identity Is the New Front Door
The initial-access story flipped in 2026. For years, unpatched vulnerabilities led the root-cause charts; now stolen and abused credentials do. Sophos found 79% of ransomware attacks in 2026 began with compromised identities, and 97% of credential-based intrusions occurred at organizations that had multi-factor authentication deployed - meaning MFA existed but was bypassed, phished, or misconfigured (Sophos, State of Ransomware 2026). Verizon’s corpus reinforces the pattern: 54% of ransomware victims had corporate credentials previously exposed in infostealer logs (Verizon, 2025 Data Breach Investigations Report). The takeaway for defenders maps directly onto credential hygiene, covered in our password security statistics roundup.
| Metric | Value | Source |
|---|---|---|
| Attacks starting with compromised identities, 2026 | 79% | Sophos, State of Ransomware 2026 |
| Top technical root causes, 2026 | Malicious email 26%; phishing 24% | Sophos, State of Ransomware 2026 |
| Credential intrusions where MFA was deployed | 97% | Sophos, State of Ransomware 2026 |
| Ransomware victims with prior infostealer exposure | 54% | Verizon, 2025 DBIR |
| Encryption events occurring outside business hours | 88% | Sophos, Active Adversary/Identity Report 2026 |
| Median time from intrusion to reach Active Directory | 3.4 hours | Sophos, Active Adversary/Identity Report 2026 |
| Median attacker dwell time | 3 days | Sophos, Active Adversary/Identity Report 2026 |
| Attacks/IR cases involving data exfiltration, 2025 | 96% | Arctic Wolf / BlackFog, 2025 |
Outlier: as recently as the 2025 survey, exploited vulnerabilities were the top technical root cause at 32% (Sophos, State of Ransomware 2025). The 2026 shift toward email and stolen identities marks the first time in four years that vulnerabilities were not number one.
5. Sector Deep Dive: Healthcare, Retail, Manufacturing, and Education
Ransomware does not hit every industry the same way, and 2025’s sector surveys show payment behavior splitting by vertical. Retail remains the most likely to pay; healthcare and education are increasingly likely to restore from backups instead. Retailers paid the ransom in 58% of cases - nearly double the 32% rate of 2021 - while just 36% of healthcare providers paid, down from 61% in 2022 (Sophos, State of Ransomware in Retail 2025 and Healthcare 2025). Education posted the strongest defensive gains of any sector.
| Metric | Value | Source |
|---|---|---|
| Healthcare - paid the ransom, 2025 | 36% (down from 61% in 2022) | Sophos, State of Ransomware in Healthcare 2025 |
| Healthcare - median ransom paid | $150K (lowest across all sectors) | Sophos, Healthcare 2025 |
| Retail - paid the ransom, 2025 | 58% (vs 49% cross-sector) | Sophos, State of Ransomware in Retail 2025 |
| Retail - median ransom demand | $2M (doubled from $1M in 2024) | Sophos, Retail 2025 |
| Manufacturing - paid the ransom, 2025 | 51% | Sophos, Manufacturing 2025 |
| Manufacturing - data encrypted | 40% (down from 74% in 2024) | Sophos, Manufacturing 2025 |
| Lower education - stopped attack before encryption | 67% (up from 14%) | Sophos, State of Ransomware in Education 2025 |
| Higher education - median ransom demand | $697K (down from $3.55M) | Sophos, Education 2025 |
Note: extortion-only attacks, where data is stolen but never encrypted, tripled to 12% of healthcare incidents and rose to 10% in manufacturing - evidence that gangs increasingly skip encryption and go straight to blackmail.
6. The 2026 Front Line and Government Reporting
Government and commercial trackers agree the pace has not slowed into 2026. The FBI’s IC3 figures capture only a fraction of real losses - they exclude downtime, remediation, and third-party costs - yet even that narrow slice jumped sharply. The FBI logged 3,611 ransomware complaints in 2025 with $32.3 million in directly reported losses, a 259% year-over-year increase, plus 63 brand-new ransomware variants (FBI IC3, 2025 Internet Crime Report). Early 2026 data from commercial trackers shows the surge continuing, driven in part by AI-assisted reconnaissance and voice-based social engineering - the latter examined in our vishing statistics roundup.
| Metric | Value | Source |
|---|---|---|
| FBI IC3 ransomware complaints, 2025 | 3,611 (up from 3,156 in 2024) | FBI IC3, 2025 Internet Crime Report |
| FBI IC3 reported ransomware losses, 2025 | $32.3M (+259% YoY) | FBI IC3, 2025 |
| New ransomware variants identified, 2025 | 63 (about 5.25 per month) | FBI IC3, 2025 |
| Healthcare ransomware attacks (critical infra) | 460 (most of 16 sectors) | FBI IC3, 2025 |
| Ransomware present in all data breaches, 2025 | 44% (up from 32%) | Verizon, 2025 DBIR |
| Ransomware in SMB breaches | 88% (vs 39% for large enterprises) | Verizon, 2025 DBIR |
| Claimed ransomware victims, Q2 2026 | 2,279 (+43% YoY, +7% QoQ) | Cyble, 2026 Threat Intelligence |
| Americas claimed ransomware attacks, Q1 2026 | 1,138 (of 1,305 cyber incidents) | Cyble, 2026 Threat Intelligence |
Note: the United States remained the most-targeted country by a wide margin in 2025, absorbing more disclosed victims than the next several countries combined (Chainalysis, 2026 Crypto Crime Report; Breachsense, 2025).
Summary: Ransomware by the Numbers
| Metric | Value | Source |
|---|---|---|
| Tracked ransomware incidents worldwide, 2025 | 7,874 (about +50% YoY) | NCC Group, 2025 |
| On-chain ransom payments, 2025 | ~$820M (down ~8%) | Chainalysis, 2026 Crypto Crime Report |
| Share of victims who paid, 2025 | 28% (all-time low) | Chainalysis, 2026 Crypto Crime Report |
| Median ransom payment, 2025 | $59,556 (+368% YoY) | Chainalysis, 2026 Crypto Crime Report |
| Attacks starting with compromised identities, 2026 | 79% | Sophos, State of Ransomware 2026 |
| Average ransomware-related breach cost | $5.08M | IBM, Cost of a Data Breach 2025 |
| Mean recovery cost excl. ransom, 2026 | $1.7M | Sophos, State of Ransomware 2026 |
| Ransomware present in all data breaches | 44% (up from 32%) | Verizon, 2025 DBIR |
| Ransomware in SMB breaches | 88% | Verizon, 2025 DBIR |
| FBI IC3 ransomware complaints, 2025 | 3,611 | FBI IC3, 2025 Internet Crime Report |
| FBI IC3 reported ransomware losses, 2025 | $32.3M (+259% YoY) | FBI IC3, 2025 |
| New ransomware variants, 2025 | 63 | FBI IC3, 2025 |
| Coveware payment rate, Q4 2025 | ~20% (historic low) | Coveware, Q4 2025 |
| Most active ransomware group, 2025 | Qilin, 1,022 attacks (13%) | NCC Group, 2025 |
| Retail ransom-payment rate, 2025 | 58% | Sophos, Retail 2025 |
| Healthcare ransom-payment rate, 2025 | 36% | Sophos, Healthcare 2025 |
| Data exfiltration in ransomware cases, 2025 | 96% | Arctic Wolf / BlackFog, 2025 |
| Global ransomware damage, 2025 / 2026 (projected) | $57B / $74B | Cybersecurity Ventures, 2025 |
Methodology and Sources
Data was gathered by aggregating figures directly from the primary reports, surveys, and datasets published by the organizations below, cross-referencing headline numbers (attack volume, payment rates, breach costs) across two or more independent sources where possible and flagging methodological divergences inline.
Sources cited:
- Sophos, State of Ransomware 2026 (seventh annual survey, 2,158 IT/cybersecurity leaders, 17 countries)
- Sophos, State of Ransomware 2025 (3,400 leaders, 17 countries)
- Sophos, State of Ransomware in Healthcare, Retail, Education, and Manufacturing 2025
- Sophos, Active Adversary / Identity-Driven Breaches Report 2026 (661 IR cases, Nov 2024-Oct 2025)
- Chainalysis, 2026 Crypto Crime Report - Crypto Ransomware
- FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report
- Verizon, 2025 Data Breach Investigations Report (DBIR) (22,052 incidents; 12,195 breaches; 139 countries)
- IBM, Cost of a Data Breach Report 2025 (600+ organizations, 16 countries)
- NCC Group, Annual Threat Intelligence Report 2025
- Coveware, Ransomware Quarterly Reports (Q2-Q4 2025)
- Cybersecurity Ventures, Ransomware Damage Cost Projections 2025-2031
- Cyble, 2026 Threat Intelligence Trends
- Check Point Research (active-group count, Q3 2025), Dragos 2026 OT/ICS Report, Arctic Wolf and BlackFog (exfiltration rates, 2025), and Breachsense Annual Ransomware Report 2025 (disclosed-victim totals)
Data watch: Several of these are recurring editions with new releases expected soon. The Verizon DBIR typically publishes its next annual edition in spring, IBM’s Cost of a Data Breach lands mid-year, the FBI IC3 Internet Crime Report arrives the following spring, Coveware issues quarterly updates within weeks, and both Chainalysis (Crypto Crime Report) and Sophos (State of Ransomware) run on annual cycles. We will refresh figures as each drops.
Last updated: July 16, 2026.
We review and update this page quarterly as new data is published.