For years the advice given to ransomware victims was easy to say and hard to follow: don’t pay. Paying funds the next attack, marks you as a soft target, and buys a criminal’s promise as your only guarantee. Everyone nodded, and then most companies paid anyway, because the alternative was watching the business stop.
Something changed. According to Chainalysis figures published in early 2026, only 28 percent of identified ransomware victims paid in 2025, down from 78.9 percent in 2022. Incident-response firm Coveware, which sees these negotiations from the inside, measured the rate falling to 20 percent by the fourth quarter of 2025. In three years, refusal went from the exception to the overwhelming norm.
This is one of the more successful acts of collective defiance in the history of cybercrime. It is also, on its own, not remotely the victory it sounds like — because the attacks did not stop. They hit a record.
The criminals didn’t quit. They restructured.
Even as payments dried up, 2025 set a record for ransomware activity, with 7,874 victims claimed on leak sites while on-chain payments fell about 8 percent to roughly $820 million. Attackers hit more targets and collected less. That is not a defeated industry. It is an industry responding to a collapsing conversion rate the way any business would — by increasing volume.
The structural response is even more telling. Check Point counted 85 active extortion groups in the third quarter of 2025, with the ten most active accounting for just 56 percent of published victims — a sharp drop in concentration. Read that as a market signal rather than a threat statistic. When an industry’s economics deteriorate, the big operators lose their advantage and the field fragments into smaller players chasing thinner margins. Law-enforcement takedowns accelerated it, but the underlying cause is that running a large, recognizable ransomware brand stopped paying well enough to justify the exposure.
There is a second adaptation visible in the numbers, and it is the one defenders should watch. As the many-small-payments model broke down, the survivors pivoted toward fewer, larger scores. Coveware’s average payment in the fourth quarter of 2025 rose 57 percent over the prior quarter, and the largest confirmed single ransom on record remains the $75 million paid by a Fortune 50 victim to the Dark Angels group. The business model is shifting from volume extortion toward big-game hunting: fewer targets, each researched, each capable of paying an enormous sum to avoid catastrophe.
Why refusing works even when it doesn’t feel like it
It is worth being precise about what the refusal trend actually accomplished, because “attacks went up” invites the wrong conclusion. Non-payment does not protect the individual company that refuses — that company still eats the downtime and the recovery. What it does is degrade the economics of the industry attacking everyone, which is a benefit that accrues to the group rather than the refuser. It is a genuine collective-action success, and collective-action successes always look unimpressive from inside any single organization’s incident.
And the case for refusing has gotten stronger on the merits, not just the ethics. Paying buys far less than victims imagine: 84 percent of paying victims failed to fully recover their data in one late-2024 analysis. You are purchasing a decryption tool of uncertain quality from someone who already lied to you about their access to your network. Meanwhile the FBI’s distribution of decryption keys has helped victims avoid hundreds of millions in payments, giving refusal an increasingly practical fallback.
The cost that didn’t go down
Here is the part that should reframe how boards think about this entirely. Ransom payments fell dramatically. Ransomware costs did not — because the ransom was never the expensive part.
The average cost of a ransomware incident in 2025 was about $5.08 million, against a median payment measured in the low hundreds of thousands. The ransom, in other words, is a rounding error against the downtime, the forensics, the rebuild, the legal exposure, and the customers who leave. A company that proudly refuses to pay and then spends four months restoring systems has not saved money. It has changed which line item the money came out of.
That arithmetic is the actual lesson of the payment-rate collapse, and it points somewhere unglamorous. The reason more companies can refuse now is not that they got braver. It is that more of them had working backups, tested restoration procedures, and segmented networks — the capacity to say no is purchased in advance, during the boring years, and it is the only part of this whole equation a company fully controls. Organizations that invested there gained the option to refuse. Everyone else still faces the same terrible choice, and the criminals hunting big scores are specifically looking for them.
Related reading: Passkeys Won. The Password Still Isn’t Dead. The Reason Is the Whole Point.
