Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Cybersecurity Companies Report a Surge in Ransomware Attacks—but the Numbers Tell Different Stories

Several cybersecurity reports show ransomware activity rising, but their counts measure different things. Here is what the figures mean—and what households and small businesses can do.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Several cybersecurity firms report sharp increases in ransomware activity, but the evidence does not show that attacks are rising everywhere or that every organization faces the same odds. Public victim trackers and vendor reports show an upward trend; a UK government survey found fewer businesses reporting ransomware. The results differ because the sources count different things, over different periods and populations.

What the latest reports count—and what they find

The figures below are not a single, interchangeable measure of ransomware prevalence. Some count public claims, some count observed incidents, and the UK survey estimates how many surveyed businesses reported an experience.

Source and reporting period Measure Reported result Scope and collection detail
Black Kite, 2025 report Victims in its ransomware dataset 6,046 victims; 24% year-over-year increase The report does not state the dataset’s geographic coverage or collection method.
ThreatDown, July 2024–June 2025 Ransomware attacks reported in its annual report 25% year-over-year increase; more than 1,000 incidents in February 2025 The report does not state its geographic coverage or precisely how an incident is counted.
NCC Group, 2026 publication covering 2025 Attack volume 50% increase during 2025 NCC Group describes its finding as global; the report does not state the underlying collection method or unit in more detail.
GuidePoint Security GRIT, December 2025 Victims claimed publicly 814 claimed victims, 42% more than in December 2024 This is a public-claim count. Geographic coverage is not stated.
UK Cyber Security Breaches Survey, 2025/26 Share of surveyed businesses reporting ransomware 1%, down from 3% in each of 2024/25 and 2023/24 A government survey of businesses in the UK, rather than a count of public claims. Its population and method differ from the trackers above.

These results support a qualified surge in several vendor and public-claim datasets, not a universal increase in every country or business population. NCC Group called 2025 a “record-breaking year for ransomware activity globally,” while the UK survey shows why that headline should not be treated as a measure of every business’s experience.

Why ransomware reports can disagree

A percentage increase can be accurate for one dataset and still say little about a different population. Before comparing two ransomware headlines, check five things:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Geography: A UK business survey cannot be directly compared with a tracker described as global or with a report whose geographic coverage is not stated.
  • Period: Reports may use a calendar year, a rolling 12-month span, a single month or a survey year. A one-month jump is not the same as a year-long trend.
  • Unit counted: A “victim” or public claim is not necessarily the same as a confirmed incident, an attack event or an organization that reported an incident in a survey.
  • Collection method: A survey estimates responses from a defined sample; a leak-site tracker counts disclosed victims; an insurer analyzes claims from its policyholders; and a security vendor may count activity seen in its telemetry. Each method has blind spots.
  • Disclosure coverage: A company that appears on a leak site has been publicly claimed by an attacker. Victims who are not disclosed there will not appear in that count, and a claim is not by itself independent confirmation of every detail.

For personal-finance readers, this distinction matters: these reports do not provide a reliable probability that a particular household or small business will be attacked. They do signal that ransomware remains a material operational and financial risk, especially for organizations whose records, systems or income depend on digital access.

What the reports identify as risk factors

The reports point to several pressures on defenders, but they do not prove that any one factor caused the overall rise or every individual attack.

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling
  • A larger, changing criminal ecosystem: Black Kite counted 96 active groups in its 2025 dataset. It also reported that 67% of breaches in that dataset involved third parties; that is a dataset-specific finding, not a claim that 67% of all ransomware attacks use a supplier as the entry point.
  • Exposed remote access: At-Bay’s 2026 report, based on 2025 data, says 73% of ransomware attacks in its analysis began with a VPN. That finding makes VPN access a priority to secure, but it should not be generalized to every attack population.
  • Faster exploitation: Check Point says the interval between vulnerability disclosure and exploitation is narrowing. For organizations, that raises the stakes of tracking and patching internet-facing systems promptly.
  • Less time to respond: In CrowdStrike’s 2025 survey of 1,100 security leaders, 76% said becoming fully prepared was getting harder, and nearly half worried they could not detect or respond as quickly as AI-driven attacks execute. This is a survey of security leaders’ assessments, not a measured rate of AI-caused ransomware.

ENISA’s 2026 Threat Landscape calls ransomware “the most short-term impactful type of incident.” That assessment reinforces the potential severity; it does not turn the separate reports’ counts into one comparable global total.

Ransom demands are not the same as losses or payments

At-Bay reports an average ransom demand near $1 million in its 2026 analysis of 2025 data, and says no ransom was paid in 68% of cases it examined. A demand is what an attacker asks for, not what a victim pays, and that average should not be read as the typical bill for every organization or incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check Point cites more than $820 million in on-chain ransomware payments during 2025 in its Q2 2026 report. That figure tracks cryptocurrency payments visible on-chain; it is not an estimate of all business losses, recovery costs or the total amount demanded. Together, these measures show that the financial stakes can be high even though many analyzed victims did not pay.

For a small business, the costs can extend beyond a ransom: interrupted sales, unavailable records, restoration work and downtime can all affect cash flow. The reports do not quantify those costs for every business, so an organization should assess its own dependence on systems and its ability to recover rather than budget around a headline ransom average.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Practical steps to reduce financial and operational exposure

No control guarantees prevention. A layered plan can make an intrusion harder, limit what an attacker can reach and shorten recovery time.

  1. Keep recoverable backups. Maintain offline or otherwise resilient copies of essential files and systems. Rehearse restoring them; a backup that cannot be restored is not a recovery plan.
  2. Protect accounts and identity systems. Use phishing-resistant multifactor authentication where available, especially for administrator and remote-access accounts. Restrict privileges and remove accounts that no longer need access.
  3. Secure remote access. Review who can use the VPN, require strong authentication, remove unused access and monitor for unusual logins. The At-Bay finding makes this a useful priority, not a guarantee that VPNs are the only route into a network.
  4. Patch exposed systems quickly. Keep an inventory of internet-facing software and devices, follow vendor security advisories and prioritize fixes for vulnerabilities being exploited in the wild.
  5. Practice detection and response. Decide who can isolate affected systems, contact technical and legal support, notify insurers or regulators where required, and communicate with customers. Keep the plan available if normal systems are inaccessible.
  6. Protect household essentials too. Keep separate, recoverable copies of important personal documents and photos, use unique passwords with multifactor authentication for email and financial accounts, and know how to contact your bank if you lose access to a device or account.

For a small organization, the useful planning question is not whether one headline proves attacks are surging everywhere. It is whether a ransomware incident could interrupt income or access to records—and whether the organization can contain it and restore essential operations without relying on a payment to the attacker.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.