Free tools Windows power users keep installed
One-click scans. No signup required.
Ransomware attackers demanded an average of just over $5.2 million per attack in the first half of 2024, according to Comparitech. That figure is historical: it is an average of 56 known demands, not a current 2026 estimate, not a median, and not the amount victims paid.
What the $5.2 million figure measures
Comparitech’s July 2, 2024 roundup reported an average demand of just over $5.2 million across industries in H1 2024. The calculation used 56 attacks for which a demand was known. It measures what attackers asked for, not how much organizations paid or ultimately lost. Read Comparitech’s H1 2024 roundup.
The figure also does not describe a typical victim’s likely bill. It is a mean, and Comparitech did not provide a median for the reported sample. A small number of very large demands can pull an average upward, so the mean cannot tell an organization what demand it might face.
Why it is not a current average
The $5.2 million number applies to the first six months of 2024. The available sources do not establish a comparable 2026 average. Treating it as current—or updating it by extrapolation—would go beyond the evidence.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Any meaningful comparison with a newer figure would need the same definitions: the period covered, geography, industries, whether the number is a demand or a payment, whether it is a mean or median, and how many incidents had known amounts. Different samples or definitions can produce figures that are not directly comparable.
What Comparitech’s sample included
Comparitech reported more than 420 confirmed attacks in H1 2024, affecting over 35.3 million records. It separately tracked 1,920 unconfirmed attacker claims. Those counts provide context for the roundup, but they are not the denominator for the $5.2 million average: that calculation drew on the 56 attacks with known demands. The source also noted that disclosures can arrive after an incident, so the roundup was not a complete census of ransomware activity.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
The largest reported demands were outliers
The roundup listed demands of $100 million for India’s Regional Cancer Center, $50 million for Synnovis, and $25 million for London Drugs. These are specific high-end cases from H1 2024, not a forecast for other victims. Without a reported median or a full distribution, they should not be used to infer what a typical organization was asked to pay.
Ransomware risk is not limited to encrypted files
Ransomware incidents can involve data theft and threats to disclose stolen information, as well as encryption that disrupts access to systems. Teneo’s December 2024 cyber outlook describes data theft for extortion as an expanding tactic and ransomware-as-a-service as a continuing risk driver. In that model, criminal groups can license ransomware operations to other actors. Read Teneo’s 2025 Cyber Outlook.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #3
That means restoring files from backups may address one part of an incident but does not by itself resolve the exposure created by stolen data, operational disruption, or other obligations. Organizations need plans that account for both technical recovery and incident response.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Practical steps organizations can take
Teneo recommends a layered approach to reducing ransomware risk. These are risk-management measures, not guarantees against an attack:
Rank #4
- Protect endpoints: Use endpoint protection suited to the organization’s systems and keep it maintained.
- Patch and update systems: Regularly apply security updates to reduce exposure from known weaknesses.
- Train employees: Provide awareness training so staff can recognize and report suspicious activity.
- Keep offline backups: Maintain offline copies of important data and ensure recovery procedures are usable.
- Prepare an incident-response plan: Define roles, escalation paths, and recovery decisions before an incident occurs.
The right implementation depends on an organization’s technology, operations, and legal obligations. Backup, endpoint protection, and response planning should be treated as parts of a coordinated program rather than as single-product fixes.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




