Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Ransomware Payment Rate Drops to a Record Low as Claimed Attacks Surge

Ransomware payment rates may have hit 28% in 2025 while claimed victims rose 50%. The divergence reflects better resilience, fragmented criminals and larger payments from selected victims—not a defeated threat.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fewer ransomware victims paid in 2025, but ransomware did not go away. Chainalysis estimates that the payment rate may have fallen to 28%, while publicly claimed victims rose about 50%. Observed on-chain ransom payments declined roughly 8% to approximately $820 million, yet the median payment jumped 368%, from $12,738 in 2024 to $59,556 in 2025.

Those figures describe different parts of the market. The payment estimate comes from Chainalysis’ attribution model, while the attack increase is based mainly on leak-site claims recorded by eCrime.ch. A leak-site post is not proof of a verified intrusion, encryption, or refusal to pay.

What actually fell to 28%

The 28% figure is an estimated payment rate: the share of observed or estimated ransomware victims who paid. It is not a census of every incident worldwide, and Chainalysis says it may have reached an all-time low in its series. The estimate should therefore be reported as “potentially 28%,” not as an incontestable global measurement. Chainalysis’ 2026 Crypto Crime Report also notes that later attribution can change the totals.

Measure What it means 2025 result
Payment rate Share of victims that paid Potentially 28%, according to Chainalysis
Claimed victims Organizations posted on public extortion sites Up approximately 50% year over year
On-chain ransom payments Cryptocurrency payments attributed to ransomware Approximately $820 million, provisional
Median payment The middle value among observed payments, not the average $59,556, up from $12,738 in 2024

How attacks can rise while ransom revenue falls

More claims and fewer payments are compatible because the numbers have different denominators. Better backups, restoration plans and incident response can let victims recover without negotiating. Regulatory scrutiny, sanctions concerns, international disruption efforts and publicly available decryptors can also reduce the incentive or ability to pay.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Attackers may simultaneously launch more inexpensive, opportunistic attacks. A larger number of low-value incidents can increase the apparent victim count without generating comparable revenue. Leak sites can also contain reposted, duplicated, old or unverified claims, and a posting does not show whether an organization paid, refused, negotiated or was ever encrypted.

The money declined, but the remaining payments got larger

Chainalysis counted approximately $820 million in 2025 on-chain ransomware payments, about 8% below its updated 2024 estimate of $892 million. The 2025 figure is incomplete and could approach or exceed $900 million as additional transactions are attributed. It also excludes non-cryptocurrency payments and transactions that investigators have not identified.

The median payment rose 368% to $59,556. A median is not a typical invoice and does not mean most victims paid that amount. It indicates that the distribution shifted: a smaller paying group produced substantially larger payments. Possible explanations include more selective targeting of organizations with greater ability to pay, stronger leverage from stolen data and operational shutdowns, and a split between high-volume low-value attacks and fewer high-value intrusions. Chainalysis reports the increase but does not establish one single cause.

Ransom payments also understate the damage. Downtime, restoration, legal work, customer notification, lost production, regulatory exposure and supplier disruption can exceed the cryptocurrency transferred. Chainalysis cited an estimate that the 2025 Jaguar Land Rover incident caused approximately £1.9 billion (about $2.5 billion) in economic damage; that is an impact estimate, not a ransom payment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Why a lower payment rate does not mean a safer threat

Extortion no longer requires encryption

Criminals can steal data and threaten disclosure without locking systems. A victim may need no decryptor yet still face pressure over trade secrets, personal information or business interruption. Payment also does not guarantee working decryption, deletion of copies or permanent non-disclosure.

The criminal market is fragmenting

Chainalysis describes a move away from a few dominant ransomware-as-a-service brands toward many smaller and more independent extortion actors. Some analyses tracked as many as 85 active groups in 2025, although counts depend on how “active” and “group” are defined. Rebrands, splits, shared code and reused infrastructure make attribution difficult. Takedowns of one famous brand therefore do not remove the broader capability, and smaller organizations may become more attractive targets.

Access to victims is becoming cheaper

Initial-access brokers (IABs) sell credentials or network access to already-compromised organizations. Chainalysis estimated at least $14 million in IAB on-chain payments in 2025, roughly flat year over year. It observed that spikes in IAB inflows tended to precede increases in ransomware payments and U.S. leak-site posts by about 30 days. That is an association, not proof that IAB activity causes every later attack.

Darkweb IQ, as cited by Chainalysis, estimated that the average price of network access fell from about $1,427 in the first quarter of 2023 to $439 in the first quarter of 2026. This is a third-party estimate, not a complete market price index, and not all broker activity leads to ransomware.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

What the “50% surge” can and cannot prove

The approximately 50% increase refers to claimed victims recorded by eCrime.ch, principally from leak sites. It is a useful signal of extortion activity, but it is not a definitive global count of successfully executed ransomware attacks.

  • Some posts may be false, duplicated, reposted or attributed to the wrong group.
  • A claim may describe data theft without encryption.
  • Compromised organizations that are never listed are missing from the series.
  • One incident can generate several payment transactions or listings.
  • Public attribution can change when investigators learn more.

Likewise, “record low” describes Chainalysis’ estimate within its relevant series. Payment rates can differ sharply by sector, geography, organization size, backup quality and outage tolerance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Should an organization refuse a ransom?

Refusing payment avoids directly funding criminals, but a blanket rule cannot resolve every incident. Poor recovery capability can turn refusal into a prolonged outage, while payment can create sanctions and legal exposure depending on the recipient. A payment may not restore systems or stop disclosure.

Incident-specific decisions should involve legal counsel, experienced responders, insurers, law enforcement and sanctions-screening specialists. Organizations should preserve evidence and document who authorized any negotiation or transfer. A policy preference to avoid payment is different from an emergency decision made under verified operational and legal constraints.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

How to make payment unnecessary

The practical objective is resilience: reduce the chance that paying becomes the only workable route to recovery.

  1. Protect and test backups. Keep offline or otherwise isolated copies, protect backup administration, and regularly restore critical systems in a realistic exercise. A backup that attackers can delete or encrypt is not a recovery plan.
  2. Strengthen identity controls. Require phishing-resistant multifactor authentication for privileged, administrative and remote access. Remove stale accounts and separate administrative identities from everyday work.
  3. Segment critical systems. Limit pathways between user networks, production systems, backup infrastructure and management planes so one stolen credential cannot reach everything.
  4. Watch identity, remote access and data movement. Alert on unusual logins, privilege changes, new remote tools, mass file access and large outbound transfers. Preserve logs long enough for forensic review.
  5. Prepare response authority. Maintain an incident-response retainer or named emergency contacts, with clear authority for technical containment, legal review, communications, insurance notification and law-enforcement escalation.
  6. Map dependencies and outage limits. Identify essential applications, suppliers and managed-service providers. Define the maximum tolerable outage and test whether critical operations can continue if a third party is compromised.
  7. Review payment and sanctions procedures. Establish in advance how wallets, counterparties, sanctions screening, evidence preservation and executive approval will be handled.

What the trend means for financial planning

For a business, a lower average willingness to pay is not a reason to cut resilience spending. The remaining paying incidents can be larger, while a non-paying incident can still produce weeks of interruption and substantial recovery costs. Budgeting should therefore cover protected backups, endpoint or managed detection, specialist response and appropriate insurance as complementary controls rather than substitutes for one another.

Cyber insurance can help fund response, but policies differ on security requirements, exclusions, ransom conditions and sanctions clauses. Emergency incident-response services are valuable during a compromise but are not a replacement for asset inventories, tested restoration and decision authority established beforehand.

The clearest conclusion is that ransomware appears to be converting fewer victims into payers, not disappearing. Attackers are compensating through volume, fragmentation, cheaper access and higher-value extortion. Defenders gain the most by making recovery reliable enough that payment is not the organization’s only viable option.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.