What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Chainalysis initially estimated that ransomware victims paid $813.55 million in cryptocurrency during 2024, about 35% less than the approximately $1.25 billion estimated for 2023. That was a decline in observed ransom payments—not proof that ransomware attacks or their overall damage declined. Chainalysis later revised its 2024 estimate upward to approximately $892 million as more transactions were attributed to ransomware actors.
What the $813 million figure actually measures
The original figure is Chainalysis’s estimate of cryptocurrency sent on-chain to ransomware operators, valued in U.S. dollars. It is not a measure of total ransomware losses.
- It excludes business interruption, restoration, legal, investigative and notification costs.
- It may miss payments made through unidentified wallets, non-crypto channels or transactions that analysts cannot confidently attribute.
- Dollar totals can change as cryptocurrency values, wallet attribution and payment classifications are updated.
- Transfers between criminal-controlled wallets must be separated from genuine victim payments to avoid double counting.
The initial estimate appeared in Chainalysis’s 2025 Crypto Crime Report release. Its later 2026 ransomware analysis put the 2024 total at approximately $892 million. The $813.55 million number is therefore best described as the initial February 2025 estimate, not a final immutable total.
Free tools Windows power users keep installed
One-click scans. No signup required.
How large was the decline?
| Measure | Amount | Qualification |
|---|---|---|
| 2023 ransomware payments | Approximately $1.25 billion | Chainalysis estimate of cryptocurrency payments |
| Initial 2024 estimate | $813.55 million | Initial estimate published in February 2025 |
| Initial year-over-year change | About 35% lower | Calculated against the initial 2024 estimate |
| Later 2024 estimate | Approximately $892 million | Revised as additional payments were attributed |
| First-half 2024 payments | Approximately $459.8 million | Chainalysis estimate |
Payment activity slowed particularly sharply after July. Chainalysis reported an approximately 34.9% decline in the second half compared with the first half. Because blockchain attribution is updated over time, later revisions can change both the annual total and the apparent size of the decline.
#1 Best Overall
- World’s First 6TB 2.5” Portable Hard Drive
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
Why did payments fall after July?
More organizations refused to pay
Improved backups, recovery procedures and incident-response preparation gave some victims an alternative to funding the attacker. A ransom demand can remain high even when a victim decides that restoration, negotiation or legal review is preferable to sending cryptocurrency.
Major criminal operations were disrupted
Law-enforcement action against LockBit and the collapse or exit of BlackCat/ALPHV disrupted large affiliate ecosystems. Affiliates did not immediately recreate a replacement operation with equivalent reach and market share. Such operations can fragment a criminal market and reduce short-term payment flows without eliminating the business model.
Cashing out became harder
Ransomware operators must receive cryptocurrency, move it through intermediary wallets or services, launder it and eventually convert it into usable assets. Sanctions, seizures, exchange enforcement and blockchain tracing increase the risk and cost of that process. Chainalysis reported that centralized exchanges remained important cash-out points, while action affecting Russian-language crypto exchanges impaired laundering activity; The Block provides additional context.
Rank #2
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Smaller actors changed the mix
Newer and smaller groups increasingly targeted small and midsize organizations. More incidents with modest demands can produce less aggregate cryptocurrency revenue than a market dominated by a few large operators.
Fewer payments does not mean fewer attacks
Available reporting indicates that ransomware activity remained widespread in 2024. More than 50 new leak sites appeared, and the number of victims listed on those sites increased, according to SecurityWeek. A leak-site listing is not the same as a verified unique attack: claims can be duplicated, exaggerated, abandoned or impossible to confirm.
The important distinction is between attacks, demands and payments. Attackers can compromise more organizations while converting fewer victims into paying customers. Extortion-only campaigns, in which criminals steal data and threaten publication without encrypting systems, further complicate comparisons based only on payment totals.
Rank #3
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
What the $75 million Dark Angels payment shows
An undisclosed victim paid Dark Angels approximately $75 million, described as a record-breaking ransomware payment in the Chainalysis report. That single case illustrates how concentrated ransomware revenue can be. A few “big-game” incidents can materially affect a yearly total, while the record payment says little about what a typical small business paid.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Were victims paying less, or were fewer victims paying?
The evidence points mainly to a lower share of victims paying, although payment size varies by victim size, sector, ransomware family and negotiation. SecurityWeek cited Kivu Consulting data indicating that roughly 30% of victims paid during the relevant period. That is Kivu’s sample and methodology, not a universal global payment rate and not a directly interchangeable measure with Chainalysis’s blockchain estimate.
A widening gap between ransom demands and actual cryptocurrency transfers also suggests that attackers continued to demand money even when fewer victims completed payment.
Rank #4
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
Why paying is not a guaranteed solution
Payment may allow faster access to a decryptor in some cases, but it carries significant uncertainty. Authorities generally discourage payment because it can fund further crime, create sanctions concerns and fail to produce recovery; see Chainalysis’s ransomware guidance.
- A decryptor may be defective or incomplete.
- Stolen data may be published despite payment.
- The victim may be targeted again.
- Sending funds to an impersonator or incorrect wallet can make recovery impossible.
- Paying a sanctioned or designated actor can create legal exposure, depending on the jurisdiction and facts.
- Investigation, restoration, notification and regulatory duties still remain after payment.
Refusing payment is not automatically safe either. It works best when recovery systems, continuity plans, legal advice, communications procedures and law-enforcement contacts are prepared in advance.
What the trend means for a business’s financial planning
The practical advantage shifted toward organizations that can restore operations without paying. A lower industry payment total does not reduce the need to budget for prevention and recovery; it makes resilience more financially valuable because it can reduce both ransom leverage and downtime.
Best Value
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Build recoverable backups
- Keep offline or immutable copies separated from production credentials and management planes.
- Use distinct backup accounts and multifactor authentication.
- Set recovery-point and recovery-time objectives for critical systems.
- Test full workload restoration, not merely file-level recovery.
Reduce common entry and spread paths
- Enforce multifactor authentication and harden privileged identities.
- Patch exposed systems and remove unnecessary remote-access services.
- Segment networks so one compromised account cannot reach every workload.
- Deploy endpoint detection and response with alert monitoring and tamper protection.
Plan the incident before it happens
- Define who can authorize downtime, negotiation or payment.
- Involve legal counsel, cyber-insurance contacts and law enforcement early.
- Prepare for data theft as well as encryption.
- Document notification, customer-communication and evidence-preservation procedures.
Products such as backup platforms, endpoint security and managed detection can support this program, but no single vendor guarantees ransomware prevention or recovery. Buying decisions should focus on isolation, tested restoration, 24/7 monitoring, identity integration, retention limits, response times and insurance or regulatory requirements.
How to read the headline accurately
“Ransomware payments dropped to $813 million in 2024” is accurate only as a description of Chainalysis’s initial estimate. The later approximately $892 million revision shows why cryptocurrency crime totals are provisional. The durable conclusion is narrower and more useful: ransomware remained widespread, but in 2024 it converted a smaller share of attacks into observable cryptocurrency revenue, helped by refusal to pay, stronger recovery capabilities, criminal-market disruption and tighter control of laundering channels.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute

