Fewer ransomware victims paid in 2025, but ransomware did not go away. Chainalysis estimates that the payment rate may have fallen to 28%, while publicly claimed victims rose about 50%. Observed on-chain ransom payments declined roughly 8% to approximately $820 million, yet the median payment jumped 368%, from $12,738 in 2024 to $59,556 in 2025.
Those figures describe different parts of the market. The payment estimate comes from Chainalysis’ attribution model, while the attack increase is based mainly on leak-site claims recorded by eCrime.ch. A leak-site post is not proof of a verified intrusion, encryption, or refusal to pay.
What actually fell to 28%
The 28% figure is an estimated payment rate: the share of observed or estimated ransomware victims who paid. It is not a census of every incident worldwide, and Chainalysis says it may have reached an all-time low in its series. The estimate should therefore be reported as “potentially 28%,” not as an incontestable global measurement. Chainalysis’ 2026 Crypto Crime Report also notes that later attribution can change the totals.
| Measure | What it means | 2025 result |
|---|---|---|
| Payment rate | Share of victims that paid | Potentially 28%, according to Chainalysis |
| Claimed victims | Organizations posted on public extortion sites | Up approximately 50% year over year |
| On-chain ransom payments | Cryptocurrency payments attributed to ransomware | Approximately $820 million, provisional |
| Median payment | The middle value among observed payments, not the average | $59,556, up from $12,738 in 2024 |
How attacks can rise while ransom revenue falls
More claims and fewer payments are compatible because the numbers have different denominators. Better backups, restoration plans and incident response can let victims recover without negotiating. Regulatory scrutiny, sanctions concerns, international disruption efforts and publicly available decryptors can also reduce the incentive or ability to pay.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Attackers may simultaneously launch more inexpensive, opportunistic attacks. A larger number of low-value incidents can increase the apparent victim count without generating comparable revenue. Leak sites can also contain reposted, duplicated, old or unverified claims, and a posting does not show whether an organization paid, refused, negotiated or was ever encrypted.
The money declined, but the remaining payments got larger
Chainalysis counted approximately $820 million in 2025 on-chain ransomware payments, about 8% below its updated 2024 estimate of $892 million. The 2025 figure is incomplete and could approach or exceed $900 million as additional transactions are attributed. It also excludes non-cryptocurrency payments and transactions that investigators have not identified.
The median payment rose 368% to $59,556. A median is not a typical invoice and does not mean most victims paid that amount. It indicates that the distribution shifted: a smaller paying group produced substantially larger payments. Possible explanations include more selective targeting of organizations with greater ability to pay, stronger leverage from stolen data and operational shutdowns, and a split between high-volume low-value attacks and fewer high-value intrusions. Chainalysis reports the increase but does not establish one single cause.
Ransom payments also understate the damage. Downtime, restoration, legal work, customer notification, lost production, regulatory exposure and supplier disruption can exceed the cryptocurrency transferred. Chainalysis cited an estimate that the 2025 Jaguar Land Rover incident caused approximately £1.9 billion (about $2.5 billion) in economic damage; that is an impact estimate, not a ransom payment.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsRank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Why a lower payment rate does not mean a safer threat
Extortion no longer requires encryption
Criminals can steal data and threaten disclosure without locking systems. A victim may need no decryptor yet still face pressure over trade secrets, personal information or business interruption. Payment also does not guarantee working decryption, deletion of copies or permanent non-disclosure.
The criminal market is fragmenting
Chainalysis describes a move away from a few dominant ransomware-as-a-service brands toward many smaller and more independent extortion actors. Some analyses tracked as many as 85 active groups in 2025, although counts depend on how “active” and “group” are defined. Rebrands, splits, shared code and reused infrastructure make attribution difficult. Takedowns of one famous brand therefore do not remove the broader capability, and smaller organizations may become more attractive targets.
Access to victims is becoming cheaper
Initial-access brokers (IABs) sell credentials or network access to already-compromised organizations. Chainalysis estimated at least $14 million in IAB on-chain payments in 2025, roughly flat year over year. It observed that spikes in IAB inflows tended to precede increases in ransomware payments and U.S. leak-site posts by about 30 days. That is an association, not proof that IAB activity causes every later attack.
Darkweb IQ, as cited by Chainalysis, estimated that the average price of network access fell from about $1,427 in the first quarter of 2023 to $439 in the first quarter of 2026. This is a third-party estimate, not a complete market price index, and not all broker activity leads to ransomware.
Recommended Free Tools
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
What the “50% surge” can and cannot prove
The approximately 50% increase refers to claimed victims recorded by eCrime.ch, principally from leak sites. It is a useful signal of extortion activity, but it is not a definitive global count of successfully executed ransomware attacks.
- Some posts may be false, duplicated, reposted or attributed to the wrong group.
- A claim may describe data theft without encryption.
- Compromised organizations that are never listed are missing from the series.
- One incident can generate several payment transactions or listings.
- Public attribution can change when investigators learn more.
Likewise, “record low” describes Chainalysis’ estimate within its relevant series. Payment rates can differ sharply by sector, geography, organization size, backup quality and outage tolerance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Should an organization refuse a ransom?
Refusing payment avoids directly funding criminals, but a blanket rule cannot resolve every incident. Poor recovery capability can turn refusal into a prolonged outage, while payment can create sanctions and legal exposure depending on the recipient. A payment may not restore systems or stop disclosure.
Incident-specific decisions should involve legal counsel, experienced responders, insurers, law enforcement and sanctions-screening specialists. Organizations should preserve evidence and document who authorized any negotiation or transfer. A policy preference to avoid payment is different from an emergency decision made under verified operational and legal constraints.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
How to make payment unnecessary
The practical objective is resilience: reduce the chance that paying becomes the only workable route to recovery.
- Protect and test backups. Keep offline or otherwise isolated copies, protect backup administration, and regularly restore critical systems in a realistic exercise. A backup that attackers can delete or encrypt is not a recovery plan.
- Strengthen identity controls. Require phishing-resistant multifactor authentication for privileged, administrative and remote access. Remove stale accounts and separate administrative identities from everyday work.
- Segment critical systems. Limit pathways between user networks, production systems, backup infrastructure and management planes so one stolen credential cannot reach everything.
- Watch identity, remote access and data movement. Alert on unusual logins, privilege changes, new remote tools, mass file access and large outbound transfers. Preserve logs long enough for forensic review.
- Prepare response authority. Maintain an incident-response retainer or named emergency contacts, with clear authority for technical containment, legal review, communications, insurance notification and law-enforcement escalation.
- Map dependencies and outage limits. Identify essential applications, suppliers and managed-service providers. Define the maximum tolerable outage and test whether critical operations can continue if a third party is compromised.
- Review payment and sanctions procedures. Establish in advance how wallets, counterparties, sanctions screening, evidence preservation and executive approval will be handled.
What the trend means for financial planning
For a business, a lower average willingness to pay is not a reason to cut resilience spending. The remaining paying incidents can be larger, while a non-paying incident can still produce weeks of interruption and substantial recovery costs. Budgeting should therefore cover protected backups, endpoint or managed detection, specialist response and appropriate insurance as complementary controls rather than substitutes for one another.
Cyber insurance can help fund response, but policies differ on security requirements, exclusions, ransom conditions and sanctions clauses. Emergency incident-response services are valuable during a compromise but are not a replacement for asset inventories, tested restoration and decision authority established beforehand.
The clearest conclusion is that ransomware appears to be converting fewer victims into payers, not disappearing. Attackers are compensating through volume, fragmentation, cheaper access and higher-value extortion. Defenders gain the most by making recovery reliable enough that payment is not the organization’s only viable option.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




