Cybersecurity News and Headlines
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityNewsRansomware Payment Rate Drops to Record Low as Attacks Surge
Ransomware Payment Rate Drops to Record Low as Attacks Surge
CybersecurityDefense

Ransomware Payment Rate Drops to Record Low as Attacks Surge

•February 26, 2026
0
BleepingComputer
BleepingComputer•Feb 26, 2026

Why It Matters

Fewer victims are paying, yet larger ransoms and more groups amplify financial risk for enterprises, reshaping cyber‑risk strategies. Regulators and security teams must adapt to a threat landscape that extracts greater value from a shrinking pool of paying victims.

Key Takeaways

  • •Payment rate fell to 28% in 2025.
  • •Median ransom rose 368% to $59,556.
  • •85 extortion groups active, up from prior years.
  • •US remains top ransomware target.
  • •IAB activity predicts payment spikes 30 days later.

Pulse Analysis

The declining payment rate signals a strategic shift in the ransomware economy. As organizations improve incident response and face tighter regulatory scrutiny, attackers are forced to extract more value per breach, driving the median ransom to nearly $60,000. This trend underscores the growing importance of proactive defenses, cyber‑insurance negotiations, and rapid containment capabilities to deter payments and limit exposure.

Simultaneously, the ransomware ecosystem is fragmenting. Chainalysis identified 85 active extortion groups in 2025, a stark contrast to the previous dominance of a handful of RaaS platforms. This diversification, coupled with the rise of initial access brokers, creates a more volatile market where threat actors compete on price and speed. The observed 30‑day lag between IAB activity and ransom payments offers a predictive signal that security operations centers can exploit for early warning and threat hunting.

For businesses, the implications are twofold. First, the financial impact of attacks is no longer measured solely by the frequency of payments but by the magnitude of each payout and the collateral damage, as illustrated by the $2.5 billion loss at Jaguar Land Rover. Second, the concentration of attacks on developed economies, especially the United States, demands tailored risk assessments and sector‑specific resilience planning. Companies that invest in comprehensive breach response playbooks, threat intelligence integration, and continuous employee training will be better positioned to navigate this evolving ransomware landscape.

Ransomware payment rate drops to record low as attacks surge

Read Original Article
0

Comments

Want to join the conversation?

Loading comments...