Managed ITServices
Statistics

Ransomware Statistics for 2026: Attacks, Payments, Costs, and Trends

Ransomware is now involved in 48% of all data breaches, up from 44% a year earlier, according to the Verizon 2026 Data Breach Investigations Report.

Ransomware is now involved in 48% of all data breaches, up from 44% a year earlier, according to the Verizon 2026 Data Breach Investigations Report. Ransomware gangs collected roughly $820 million in cryptocurrency payments in 2025 per Chainalysis, even as the share of victims who paid fell to an all-time low of 28%. And the average cost of a data breach hit a record $4.99 million in 2026, with US organizations paying $11.5 million on average, according to IBM's 2026 Cost of a Data Breach Report.

The pattern behind these ransomware statistics is consistent across every major dataset released in 2026: more attacks, more victims posted to leak sites, fewer payments, and higher costs for the organizations that get hit. This page collects the freshest ransomware attack statistics available, drawn from 2026 reports wherever one exists and from 2025 reports where the 2026 edition has not been published.

Ransomware statistics at a glance (2026)

  • 48% of breaches involve ransomware, up from 44% the prior year (Verizon DBIR, 2026)

  • 69% of ransomware victims refused to pay, and the median ransom payment fell to $139,875 (Verizon DBIR, 2026)

  • $820 million was paid to ransomware attackers in 2025, down about 8% from a revised $892 million in 2024 (Chainalysis, 2026)

  • 28% of victims paid, the lowest payment rate on record; the median payment nonetheless jumped 368% to $59,556 (Chainalysis, 2026)

  • $4.99 million is the global average cost of a data breach, a 12% rise and a record; the US average is $11.5 million (IBM, 2026)

  • 39% of breached organizations experienced at least one ransomware attack, up from 24% in 2023 (IBM, 2026)

  • 7,419 ransomware attacks were tracked worldwide in 2025, a 32% increase, with the US absorbing 3,810 of them, or 51% (Comparitech, 2025 end-of-year report)

  • 3,611 ransomware complaints reached the FBI in 2025 with $32.3 million in reported losses, up from 3,156 complaints and $12.5 million in 2024 (FBI IC3, 2025 report)

  • 146 active ransomware groups were operating by June 2026, up from 127 at the end of March (Black Kite, 2026)

  • 86% of insured ransomware victims refused to pay while initial demands rose 47% to more than $1 million (Coalition, 2026)

  • 22 seconds is how quickly initial access brokers now hand a compromised network to a ransomware crew (Mandiant M-Trends, 2026)

Ransomware Statistics for 2026: Attacks, Payments, Costs, and Trends infographic

How common are ransomware attacks in 2026?

The most widely cited answer comes from Verizon. The 2026 DBIR found ransomware present in 48% of the breaches it analyzed, continuing a multi-year climb from 44% in the 2025 edition. Verizon describes ransomware as "ubiquitous, stubbornly popular and appearing in unexpected places," and the same report shows that vulnerability exploitation accounted for 31% of breaches while third parties were involved in 48% of them. Both are the primary on-ramps for ransomware crews.

IBM's numbers point the same direction. In IBM's 2026 Cost of a Data Breach Report, 39% of organizations that suffered a breach experienced at least one ransomware attack, up from 24% in 2023. IBM also found that 41% of those ransomware attacks included brand-reputation threats such as data leaks and public shaming, which is the extortion lever attackers reach for when encryption alone no longer forces a payment.

Leak-site tracking gives a raw count. Comparitech's 2025 end-of-year ransomware roundup logged 7,419 ransomware attacks in 2025, a 32% increase over the 5,631 recorded in 2024. Of those, 1,173 were confirmed by the victim organization; the remaining 6,246 were claims posted by gangs that the targets never acknowledged. Confirmed attacks exposed nearly 59.2 million records, and attackers claimed to have stolen 32.7 petabytes of data across all incidents.

Attack volume has not slowed in 2026. Comparitech's Q1 2026 roundup counted 2,200 attacks in the first quarter alone, 193 of them confirmed, with the US accounting for 1,041, or roughly 47% of the global total.

Black Kite's 2026 Ransomware Report, which covers April 2025 through March 2026, tracked 7,551 disclosed victims, a 24.9% year-over-year increase. Volume in the second half of that period outpaced the first half by 60%.

Ransomware payment statistics: fewer victims pay, but demands keep rising

The single most important shift in ransomware statistics 2025 through 2026 is the collapse in payment rates. Per Chainalysis, the share of victims who paid a ransom in 2025 potentially reached an all-time low of 28%. Total on-chain ransomware payments came to roughly $820 million, down about 8% from a revised $892 million in 2024, even though claimed attacks rose 50%.

The median payment tells a different story. Chainalysis reports the median ransom payment climbed 368% year-over-year, from $12,738 in 2024 to $59,556 in 2025. The gap between falling totals and rising medians suggests that attackers are getting less volume from opportunistic small-dollar payments and more from a smaller pool of high-value victims.

Verizon's dataset agrees on the refusal trend. The 2026 DBIR found that 69% of ransomware victims did not pay, and the median payment among those who did fell to $139,875 from $150,000 the prior year.

Insured organizations refuse at even higher rates. Coalition's 2026 Cyber Claims Report found a record 86% of policyholders hit by ransomware in 2025 declined to pay. At the same time, initial ransom demands jumped 47% year-over-year to more than $1 million, and 70% of ransomware claims involved dual extortion (data theft plus encryption). Those dual-extortion incidents were twice as expensive as encryption-only attacks, averaging $302,000 in losses.

Comparitech's tracking of publicly disclosed demands lands in the same range: the average ransom demand in 2025 was $1.04 million, down 26% from $1.4 million in 2024. Only two payments were publicly documented all year ($200,000 to Akira and $150,000 to an unnamed group), while 122 organizations stated on the record that they did not pay.

For organizations weighing the decision, the FBI's position is unchanged and its numbers are worth knowing. The FBI IC3 2025 Internet Crime Report logged 3,611 ransomware complaints with reported losses exceeding $32.3 million, up from 3,156 complaints and $12.5 million in 2024. IC3 counts only direct reported losses and excludes downtime and recovery, which is why its total is far below the breach-cost figures from IBM.

The cost of a ransomware attack in 2026

IBM's 2026 Cost of a Data Breach Report puts the global average cost of a data breach at $4.99 million, a 12% increase over 2025 and the highest figure IBM has recorded. US organizations averaged $11.5 million per breach. Healthcare remained the costliest industry for the thirteenth consecutive year at $6.64 million per incident, though that is down 10.5% from $7.42 million in the 2025 edition.

Time is the multiplier. IBM found the mean time to identify and contain a breach rose to 247 days in 2026, reversing five straight years of improvement. Breaches that ran past the 200-day mark cost about a third more than those closed sooner. Organizations that made extensive use of AI and automation in security saved an average of $1.93 million per breach compared with those that used none.

Industry-level ransom demands vary widely. Comparitech's healthcare ransomware roundup for the first half of 2026 found a median demand of $310,000 against healthcare providers and $300,000 against healthcare businesses, alongside a single $100 million demand against a Japanese medical school. In the 2025 full-year data, the average demand against manufacturers doubled to $1.16 million, and legal-sector demands rose 60% to $611,000.

Black Kite adds a post-incident cost that rarely shows up in headline numbers: 43.5% of ransomware victims still carried critical unpatched vulnerabilities after the attack, and 30.8% still had a Known Exploited Vulnerability exposed, meaning the same door was left open for a second visit.

Ransomware attacks by industry

Manufacturing is the most-attacked industry in every 2026 dataset that breaks out sectors. Black Kite counted 1,660 manufacturing victims, 22% of all disclosures in its April 2025 to March 2026 window. Comparitech recorded 1,466 attacks on manufacturers in 2025, a 56% increase, with the average ransom demand doubling from $523,000 to $1.16 million. Manufacturers are attractive because unplanned downtime on a production line converts directly into a payment incentive, a dynamic covered further in our guide to managed IT services for manufacturing.

Healthcare saw 444 ransomware attacks in 2025 (134 confirmed) exposing 10.1 million records, according to Comparitech's year-end data, and the pace accelerated into 2026. The H1 2026 healthcare roundup counted 410 attacks in six months, an average of 2.3 per day and a 14% increase over the second half of 2025. Qilin was the most active gang against providers, claiming 41 attacks.

Government bodies absorbed 374 attacks in 2025 (196 confirmed, 2.19 million records), and education saw 252 (93 confirmed, 3.9 million records). Comparitech's Q1 2026 data shows average demands of $480,000 against government entities and $224,000 against schools.

Legal services was the fastest-growing target in the business category, with 346 attacks in 2025, up 54%. Food and beverage, retail, and transportation also posted significant increases.

Who ransomware targets: company size and geography

The US is the epicenter. Comparitech attributes 3,810 of 2025's ransomware attacks to US organizations, 51% of the global total and a 33% increase over 2024. Black Kite puts the US share at 49.3% of victims. Canada (392 attacks, up 31%), Germany (303, up 62%), the United Kingdom (251, down 5%), and France (178, up 39%) round out the top five in Comparitech's data, while Chainalysis notes that leak-site claims against critical infrastructure, supply chain and logistics, and government organizations grew between 45% and 56% year-over-year.

Mid-market companies are squarely in the crosshairs. Black Kite found that organizations in the $50 million to $100 million revenue band climbed to 29.3% of ransomware victims, the largest single cohort. These are companies big enough to pay a six- or seven-figure ransom but often too small to staff a 24/7 security operation, which is why many turn to managed IT security services rather than building in-house.

Black Kite's risk modeling adds a predictive datapoint: companies scoring above 0.8 on its Ransomware Susceptibility Index were 291 times more likely to be attacked, and 93.5% of victims showed a meaningful spike in that index before the incident.

The ransomware ecosystem is fragmenting. Black Kite counted 127 active groups at the end of March 2026 and 146 by June 2026, with 61 new groups entering during its reporting period. Even so, the top five actors controlled 43.6% of disclosed victims. Qilin was the dominant brand of the year, with 1,358 victims in Black Kite's data (a 443% jump) and 1,034 attacks in Comparitech's 2025 count, 14% of the global total. The FBI's IC3 2025 report ranked Akira, Qilin, INC/Lynx/Sinobi, BianLian, and Play as the five most-reported variants against US critical infrastructure, and identified 63 new ransomware variants during the year, about 5.25 per month.

Attacks are faster than ever. Mandiant's M-Trends 2026 report found that the hand-off window between an initial access broker and the ransomware operator collapsed to just 22 seconds in 2025, because access brokers now pre-stage the buyer's tooling during the initial break-in. Global median dwell time nonetheless rose to 14 days from 11, a sign that ransomware crews are spending longer inside networks before detonating.

Stolen access is the top ransomware entry point. Mandiant reports that "prior compromise," meaning credentials or access purchased from an earlier intrusion, became the number one initial vector in ransomware operations at 30%, double the 15% seen in 2024. Exploits remained the most common vector across all intrusions for the sixth straight year at 32%, and interactive voice phishing surged to 11%. Verizon's 2026 DBIR similarly attributes 31% of breaches to vulnerability exploitation and reports a 60% increase in supply chain breaches.

Recovery denial is the new extortion tactic. Mandiant documented a systemic shift in 2025 toward what it calls recovery denial: operators deliberately targeting backup infrastructure, identity services, and virtualization management planes so that victims cannot restore without paying. Combined with IBM's finding that 41% of ransomware attacks now include public-shaming threats, the pressure on victims is increasingly about leverage rather than encryption.

AI is on both sides of the fight. IBM's 2026 report recorded a 56% increase in AI-driven attacks, led by deepfake impersonation and AI-enabled malware, and found that breaches driven by AI cost about $1 million more than conventional malicious attacks. Shadow AI incidents more than doubled to 43% of security incidents. On the defensive side, extensive use of AI and automation cut breach costs by $1.93 million on average.

Ransomware complaints to the FBI are climbing. IC3 received 3,611 ransomware complaints in 2025, a 14% increase, including 460 from critical infrastructure organizations. Reported losses more than doubled to $32.3 million. Total IC3 complaints across all cybercrime reached 1,008,597 with $20.877 billion in losses.

How managed IT and security providers can help

Nearly every 2026 dataset traces ransomware back to the same handful of gaps: unpatched edge devices, stolen credentials, unmonitored third-party access, and backups that were reachable from the production network. Those are precisely the controls a competent MSP or MSSP maintains on an ongoing basis.

Looking for a managed security service provider that can help your organization reduce ransomware risk and recover faster if an attack lands? manageditservices.ai connects businesses with vetted MSSPs and cybersecurity consultants across the United States. Find a provider near you to compare options in your area.

Need Help With Your Security Strategy?

Get a free assessment from our team of cybersecurity experts.

Related Articles

HM

Hadley McIntosh

Updated Sep 25, 2026 · 11 min read