• ABOUT
  • CONTACT
  • BLOG
techpinions_logo_transparent techpinions__white_logo_transparent
  • TECH SECTOR PERFORMANCE HEATMAP
  • UPCOMING TECH IPOs
  • AI
  • Technology
  • Invest
  • Future
  • Opinions
  • Podcast
Reading: 79% of Ransomware Victims Used to Pay. Now It’s 28%. The Attacks Hit a Record Anyway.
Share
TechpinionsTechpinions
Font ResizerAa
  • AI
  • Technology
  • Invest
  • Future
  • Opinions
  • Podcast
Search
  • AI
  • Technology
  • Invest
  • Future
  • Opinions
  • Podcast
Follow US
© Copyright 2026, Techpinions. All Rights Reserved.
Home » Blog » 79% of Ransomware Victims Used to Pay. Now It’s 28%. The Attacks Hit a Record Anyway.
NewsTechnology

79% of Ransomware Victims Used to Pay. Now It’s 28%. The Attacks Hit a Record Anyway.

david_graff
Last updated: August 18, 2026 10:23 AM
David Graff
Published: August 28, 2026
Share
person using laptop computers

For years the advice given to ransomware victims was easy to say and hard to follow: don’t pay. Paying funds the next attack, marks you as a soft target, and buys a criminal’s promise as your only guarantee. Everyone nodded, and then most companies paid anyway, because the alternative was watching the business stop.

Something changed. According to Chainalysis figures published in early 2026, only 28 percent of identified ransomware victims paid in 2025, down from 78.9 percent in 2022. Incident-response firm Coveware, which sees these negotiations from the inside, measured the rate falling to 20 percent by the fourth quarter of 2025. In three years, refusal went from the exception to the overwhelming norm.

This is one of the more successful acts of collective defiance in the history of cybercrime. It is also, on its own, not remotely the victory it sounds like — because the attacks did not stop. They hit a record.

The criminals didn’t quit. They restructured.

Even as payments dried up, 2025 set a record for ransomware activity, with 7,874 victims claimed on leak sites while on-chain payments fell about 8 percent to roughly $820 million. Attackers hit more targets and collected less. That is not a defeated industry. It is an industry responding to a collapsing conversion rate the way any business would — by increasing volume.

The structural response is even more telling. Check Point counted 85 active extortion groups in the third quarter of 2025, with the ten most active accounting for just 56 percent of published victims — a sharp drop in concentration. Read that as a market signal rather than a threat statistic. When an industry’s economics deteriorate, the big operators lose their advantage and the field fragments into smaller players chasing thinner margins. Law-enforcement takedowns accelerated it, but the underlying cause is that running a large, recognizable ransomware brand stopped paying well enough to justify the exposure.

There is a second adaptation visible in the numbers, and it is the one defenders should watch. As the many-small-payments model broke down, the survivors pivoted toward fewer, larger scores. Coveware’s average payment in the fourth quarter of 2025 rose 57 percent over the prior quarter, and the largest confirmed single ransom on record remains the $75 million paid by a Fortune 50 victim to the Dark Angels group. The business model is shifting from volume extortion toward big-game hunting: fewer targets, each researched, each capable of paying an enormous sum to avoid catastrophe.

Why refusing works even when it doesn’t feel like it

It is worth being precise about what the refusal trend actually accomplished, because “attacks went up” invites the wrong conclusion. Non-payment does not protect the individual company that refuses — that company still eats the downtime and the recovery. What it does is degrade the economics of the industry attacking everyone, which is a benefit that accrues to the group rather than the refuser. It is a genuine collective-action success, and collective-action successes always look unimpressive from inside any single organization’s incident.

And the case for refusing has gotten stronger on the merits, not just the ethics. Paying buys far less than victims imagine: 84 percent of paying victims failed to fully recover their data in one late-2024 analysis. You are purchasing a decryption tool of uncertain quality from someone who already lied to you about their access to your network. Meanwhile the FBI’s distribution of decryption keys has helped victims avoid hundreds of millions in payments, giving refusal an increasingly practical fallback.

The cost that didn’t go down

Here is the part that should reframe how boards think about this entirely. Ransom payments fell dramatically. Ransomware costs did not — because the ransom was never the expensive part.

The average cost of a ransomware incident in 2025 was about $5.08 million, against a median payment measured in the low hundreds of thousands. The ransom, in other words, is a rounding error against the downtime, the forensics, the rebuild, the legal exposure, and the customers who leave. A company that proudly refuses to pay and then spends four months restoring systems has not saved money. It has changed which line item the money came out of.

That arithmetic is the actual lesson of the payment-rate collapse, and it points somewhere unglamorous. The reason more companies can refuse now is not that they got braver. It is that more of them had working backups, tested restoration procedures, and segmented networks — the capacity to say no is purchased in advance, during the boring years, and it is the only part of this whole equation a company fully controls. Organizations that invested there gained the option to refuse. Everyone else still faces the same terrible choice, and the criminals hunting big scores are specifically looking for them.

Related reading: Passkeys Won. The Password Still Isn’t Dead. The Reason Is the Whole Point.

Streaming Prices Keep Rising and Nobody’s Leaving. The Price Isn’t the Point.
The UAE and US announce joint AI campus to boost global tech collaboration
U.S. and U.K. to sign tech pact during Trump visit, focus on AI and space technology
Woman arrested at Salt Lake City airport for allegedly assaulting Delta employee
Affluense AI secures ₹3 crore pre-seed funding led by Zeropearl VC
david_graff
ByDavid Graff
Follow:
David is the editor-in-chief of Techpinions.com. Technologist, writer, journalist.
Previous Article best free laser engraving software Free Laser Engraving Software I Reach For in the Garage

Listen to The Techpinions Podcast

Spotify Podcast

Join thousands of followers on X

X-twitter
techpinions_logo_transparent techpinions__white_logo_transparent
Insight, Perspective, and Analysis from influential and respected industry analysts.

About Techpinions

  • About
  • Contact
  • Editorial Policy
  • Financial Disclaimer
  • Follow us on X
  • Privacy Policy
  • Terms of Service

Topics

  • AI
  • Technology
  • Invest
  • Future
  • Opinions
  • Podcast
© Copyright 2026, Techpinions. All Rights Reserved.