Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Blog

Ransomware Victims Are Getting Better at Haggling With Hackers—but Paying Is Still a Last Resort

By TheFinanceBase Team6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Yes, ransomware victims are increasingly negotiating lower payments—but that does not mean ransomware is becoming cheap or safe. Sophos reported that 53% of organizations that paid a ransom in its 2025 survey paid less than the opening demand, and 71% of those reductions involved negotiation. Its newer 2026 reporting found 51% settled below the initial demand. Yet recovery costs rose, encryption increased, and 18% of paying organizations in the 2025 research paid more than attackers first requested.

The real improvement is not clever bargaining. It is having backups, expert response, legal advice and enough recovery capability to make payment unnecessary—or at least delay it while the facts are checked.

What the headline numbers actually measure

Sophos surveyed 3,400 IT and cybersecurity leaders at organizations with 100 to 5,000 employees across 17 countries during January–March 2025. Among respondents that had experienced ransomware and paid to recover data:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • 53% paid less than the initial demand.
  • 29% paid the amount first requested.
  • 18% paid more than the opening demand.
  • Among those paying less, 71% attributed the reduction to negotiation, either internally or through a third party.
  • The median ransom payment was about $1 million.
  • Average recovery cost excluding the ransom was $1.53 million.

These are survey results, not a census of every ransomware incident. “Paid less” also does not prove that a victim negotiated skillfully: a lower demand may reflect a less powerful criminal group, a smaller victim, law-enforcement pressure, insurance limits or the attacker’s fear that the victim can restore independently.

Sophos’s latest reporting complicates the story further. It found that 51% of paying organizations negotiated below the initial demand, while the median payment fell to $769,000. At the same time, average recovery costs rose to $1.7 million, and encryption increased. A cheaper ransom did not produce a cheaper incident. See Sophos’s 2026 State of Ransomware report for its methodology and population details.

Why victims have more leverage

Negotiation works when the attacker is not the victim’s only path back to normal operations. Several changes can create that leverage.

Usable, protected backups

Isolated, immutable or offline backups reduce the pressure to pay immediately. But a backup that has never been restored is only an assumption. Attackers increasingly target backup consoles, delete snapshots and steal administrative credentials. Restoration drills and separate backup access are essential. CISA’s ransomware guide recommends recovery planning, incident response, reporting and checking for available decryptors.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Faster incident response

Forensic responders can establish whether files were encrypted, whether data was stolen, which systems remain compromised and whether the attacker still has access. They can also test a decryptor on representative files and identify whether multiple affiliates or extortion channels are involved. That turns an emotional emergency into a documented risk decision.

More skepticism about criminal promises

A leak-site post does not prove that every listed file was stolen. A payment does not guarantee deletion, confidentiality or a working decryption tool. Criminal groups can disappear, sell data anyway or demand more after discovering additional systems. Those realities make verification and delay valuable.

Specialist negotiators

Experienced negotiators may know a ransomware family’s affiliates, typical demands and communication patterns. They can coordinate with legal counsel, insurers, forensic teams and law enforcement. Their success claims should still be examined carefully: independent, comparable performance data is rarely public.

Why some victims pay more

The 18% that paid above the initial demand is a critical warning against a triumphalist “haggling” narrative. Prices can rise when attackers discover more valuable data, add a second extortion demand, exploit delays or learn that backups are unusable. Internal confusion can also weaken a victim’s position: multiple employees contacting criminals, unsupported promises or disclosures about the company’s finances may signal desperation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Negotiation can buy time and information, but it can also reveal that the victim has few alternatives. It should never begin before the organization contains the incident and determines whether attackers still have access.

Negotiating is not the same as recommending payment

A negotiation may seek to verify a threat, obtain a sample decryption, clarify what data is allegedly stolen or reduce an unavoidable payment. None of those goals makes payment automatically wise or lawful.

In the United States, the Treasury Department’s Office of Foreign Assets Control guidance warns that ransomware payments involving sanctioned people, groups or jurisdictions can create sanctions exposure for victims and service providers. Legal counsel and sanctions screening should be involved before any transfer. Organizations may also have regulatory, contractual, insurance and public-sector reporting duties. CISA recommends coordinating response and reporting with appropriate authorities.

Payment also does not repair the underlying compromise. Even if a decryptor works, the attacker’s persistence, stolen credentials and backdoors must be removed before systems are trusted again.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The practical decision: can you recover without paying?

Leaders should document answers to these questions rather than rely on a ransom discount:

  1. Are backups isolated, intact and successfully tested?
  2. Can identity systems, privileged accounts and remote access be secured?
  3. Was data encrypted, exfiltrated, or both?
  4. Is the attacker still present?
  5. Has a decryptor worked on representative files?
  6. Would payment materially reduce downtime, or merely add another uncertain step?
  7. Could the wallet, group or intermediary be sanctioned?
  8. What do counsel, insurers, regulators and law enforcement require?
  9. Would payment increase the chance of repeat extortion?

There is no universal “never pay” or “always negotiate” rule. The defensible choice depends on the safety of recovery, the harm of prolonged outage and the legal consequences of the payment route.

What to do in the first 24 hours

  • Isolate affected systems without destroying evidence.
  • Protect identity and backup infrastructure; reset compromised privileged credentials through a controlled process.
  • Call the incident-response provider, legal counsel and insurer.
  • Contact law enforcement and preserve ransom notes, logs, malware and communications.
  • Determine the facts: encryption, theft, persistence and attacker identity.
  • Test restoration and assess the time and completeness of recovery.
  • Screen sanctions exposure before discussing or making any payment.
  • Use one authorized communications channel if negotiation is pursued.
  • Document the decision, including alternatives considered and approvals.
  • Eradicate access and monitor rebuilt systems even if a ransom is paid.

Where the numbers vary

Ransom amounts are not a universal price list. Sophos reported a 2025 median payment of $2.5 million for state and local government and $150,000 for healthcare. Organizations with more than $1 billion in revenue faced a median initial demand of $5 million, while those with $250 million or less faced a median below $350,000. These are survey medians affected by sector, size, disclosure and selection—not quotes any particular victim should expect.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

The bigger win is refusing payment

Sophos found that 44% of surveyed organizations stopped attacks before encryption and 53% fully recovered within a week. Those outcomes depend less on bargaining talent than on preparation: phishing-resistant MFA, least privilege, segmentation, vulnerability management, endpoint detection, 24/7 monitoring, immutable backups, restoration rehearsals and an incident-response retainer.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Identity deserves particular attention. Sophos’s 2026 reporting identified compromised identities and missing MFA as recurring contributors in its incident-response and managed-detection cases. A hardened identity layer can prevent an attacker from reaching both production and backup systems.

How to judge a negotiation or response provider

Ask whether the provider can supply 24/7 availability, preserve evidence, coordinate with counsel and insurers, test decryption, screen sanctions and support eradication—not just send messages to criminals. Treat reported discount percentages cautiously. GuidePoint Security’s GRIT 2026 report notes that negotiation observations can have selection bias because victims seeking attacker communications are more likely to be considering payment and able to pay.

For most organizations, the highest-return spending is the work that creates alternatives before an incident: recovery testing, identity protection and practiced response authority. Negotiation is a contingency, not a resilience strategy.

The Bottom Line

Bottom line: Ransomware victims are getting better at reducing demands, but a lower ransom is not the same as a successful outcome. The strongest bargaining position comes from tested recovery, contained access and expert legal and forensic support. Measure progress by how quickly and safely the organization can restore operations without paying—not by how much it can talk an attacker down.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.