Managed ITServices
Statistics

Ransomware Statistics by Year: Trends From 2020 to 2026

Ransomware has evolved from a nuisance into one of the most financially destructive forces in cybersecurity. Every year brings new attack records, shifting payment dynamics, and escalating recovery…

Ransomware has evolved from a nuisance into one of the most financially destructive forces in cybersecurity. Every year brings new attack records, shifting payment dynamics, and escalating recovery costs that ripple across industries worldwide. Whether you run a 50-person firm or oversee IT for a hospital network, understanding how ransomware trends have changed over time is essential for building a defense that actually works.

This article breaks down the most important ransomware statistics by year, drawing on verified data from leading cybersecurity research published in 2025 and 2026. The numbers tell a clear story: attacks are rising, costs are climbing, and the organizations that invest in proactive defense consistently come out ahead.

  • Total ransomware payments reached $892 million in 2024 before declining to $820 million in 2025, according to the Chainalysis 2026 Crypto Crime Report.

  • The percentage of victims who paid a ransom dropped to a record low of 28% in 2025, down from roughly 50% in prior years.

  • Average recovery costs per ransomware incident rose to $1.7 million in 2026, an 11% increase year over year, per the Sophos State of Ransomware 2026 report.

  • The global average cost of a data breach hit $4.99 million in 2026, while US organizations faced an average of $11.5 million, according to IBM's 2026 Cost of a Data Breach Report.

  • Claimed ransomware attacks surged 50% year over year in 2025, even as payment totals stagnated.

  • The median ransom payment jumped 368% from $12,738 in 2024 to $59,556 in 2025.

  • 56% of ransomware attacks in 2026 successfully encrypted victim data, up from 50% the year before.

  • Backup-based recovery accounted for 66% of all encrypted-data recovery cases in 2026, a 12-percentage-point increase from the prior year.

  • One in four malicious data breaches in 2026 was AI-enabled, costing organizations an average of $6.04 million each.

  • Organizations using AI and automation in their security operations cut breach costs by an average of $1.93 million.

  • Mid-market companies with 101 to 1,000 employees represented 35.4% of ransomware victims in Q2 2026, per Veeam's Cyber Extortion Trends Report.

Ransomware Statistics by Year: Trends From 2020 to 2026 infographic

Ransomware Payments by Year: Following the Money

One of the clearest ways to track ransomware's trajectory is through total payments flowing to attackers. The Chainalysis 2026 Crypto Crime Report provides the most comprehensive blockchain-verified view of these flows.

In 2023, ransomware payments crossed the $1 billion mark for the first time. That record year was followed by $892 million in 2024, a figure that initially appeared to be $813 million before additional blockchain attribution filled in the gaps. In 2025, total payments dipped to $820 million, though researchers expect late-arriving data to push the final number closer to $900 million.

The overall payment trajectory from 2020 through 2025 shows a volatile but upward trend. Payments rose sharply in 2021, dipped in 2022 following major law enforcement actions, then surged again in 2023 before settling into the $800 million to $900 million range. Despite this plateau in total dollar volume, the median individual ransom payment surged 368%, jumping from $12,738 in 2024 to $59,556 in 2025. That divergence suggests fewer victims are paying, but the ones who do are paying significantly more.

The victim payment rate tells its own story. In 2025, only 28% of ransomware victims paid, which Chainalysis described as potentially an all-time low. Compare that to the roughly 50% average payment rate that persisted across 2021 through 2024, and it becomes clear that organizations are increasingly choosing recovery over ransom.

Attack Volume: More Incidents, More Pressure

While payment totals leveled off, the volume of ransomware attacks continued to accelerate. Claimed attacks grew 50% year over year in 2025, according to Chainalysis data. A separate analysis from Ontinue researchers found that ransomware attacks surged 132% during the period spanning the second half of 2024 through Q1 2025, even as the number of payments dropped by 35%.

This pattern reveals a strategic shift among ransomware operators. Groups are launching more attacks against more targets, accepting that a smaller percentage will pay. The math still works in their favor because the sheer volume of victims and the size of individual payouts keep revenue high.

Law enforcement disruptions have created temporary dips. The takedowns of LockBit and Noberus (ALPHV/BlackCat) in late 2023 and early 2024 caused a measurable decline in activity during the first half of 2024. But new groups quickly filled the vacuum, and attack volumes rebounded strongly in the second half of that year.

Recovery Costs: The Real Price Tag

Ransom payments represent only a fraction of what ransomware actually costs an organization. Recovery expenses, including downtime, IT remediation, legal fees, regulatory penalties, and lost business, dwarf the ransom itself.

The Sophos State of Ransomware 2026 report found that the average recovery cost per incident reached $1.7 million, up 11% from the prior year. The four-year average payment rate among victims whose data was encrypted held steady at approximately 50%, though the median ransom payment dropped 23% from $1 million in 2025 to $769,000 in 2026. Median ransom demands also fell 65% over a two-year period to $698,000, suggesting attackers are adjusting their pricing to keep payment rates from falling further.

At the broader data breach level, IBM's 2026 Cost of a Data Breach Report paints an even more sobering picture. The global average cost of a data breach reached $4.99 million, a 12% year-over-year increase. In the United States, the average climbed to $11.5 million, a 13% jump from $10.22 million in 2025. The mean time to identify and contain a breach was 247 days, with breaches lasting longer than 200 days costing an average of $5.65 million versus $4.32 million for those resolved faster.

Encryption, Backups, and Recovery Time

How often attackers succeed in encrypting data matters enormously for recovery outcomes. In 2026, 56% of ransomware attacks resulted in successful data encryption, up from 50% the previous year, per the Sophos report. That increase underscores the importance of detection speed and endpoint protection.

On the positive side, backup-based recovery gained significant ground. Sixty-six percent of organizations that had their data encrypted recovered using backups rather than paying a ransom, a 12-percentage-point improvement over the prior year. This shift aligns directly with the declining payment rate and reflects years of industry emphasis on backup hygiene and disaster recovery planning.

Small organizations remain the most vulnerable. Only 34% of companies with 100 to 250 employees managed to stop attacks before encryption occurred, compared to 46% of mid-size firms with 3,001 to 5,000 employees. Resource constraints, limited security staffing, and the absence of dedicated IT operations leave smaller businesses disproportionately exposed.

2026: The Latest Numbers

The first half of 2026 has brought several notable developments. Veeam's Q2 2026 Cyber Extortion Trends report recorded an average ransom payment of $1,880,612, a 176% spike driven by a handful of unusually large payouts targeting law firms. However, the median payment fell 50% to $150,000, showing that most victims paid far less. The data-exfiltration-only payment rate dropped to just 15%, a record low, as organizations grew increasingly skeptical of paying for promises to delete stolen data.

IBM's 2026 report introduced a new dimension: AI-enabled attacks. One in four malicious breaches now involves AI, a 56% increase year over year. These breaches cost an average of $6.04 million, roughly $1 million more than non-AI attacks. On the defensive side, organizations using AI and automation in security operations cut their average breach cost to $4.00 million compared to $5.93 million for those without, and identified threats 65 days faster.

The most targeted sectors in Q2 2026 included software services (17.2%), healthcare (14.1%), and professional services (13.1%). Mid-market organizations with 101 to 1,000 employees bore the brunt, representing 35.4% of all ransomware cases.

How Managed IT Services Can Help

The data across every year points to the same conclusion: organizations that invest in proactive, layered security fare dramatically better than those that react after an attack. But building and maintaining that defense in-house requires expertise, tools, and around-the-clock vigilance that most small and mid-size businesses simply cannot sustain on their own.

That is exactly where managed IT services provide the most value. A managed services partner brings enterprise-grade security infrastructure to organizations that would otherwise lack the budget or headcount to deploy it. This includes 24/7 monitoring and threat detection, automated backup and disaster recovery systems, endpoint protection with rapid response capabilities, employee security awareness training, patch management and vulnerability scanning, and incident response planning.

The statistics make the case clearly. Organizations with security automation cut breach costs by nearly $2 million. Companies that recovered from backups avoided paying ransoms entirely. And those that detected threats within 200 days saved over $1.3 million compared to those that took longer.

Ransomware is not going away. The attackers are more numerous, more sophisticated, and increasingly leveraging AI to find new entry points. But the organizations that partner with experienced managed IT providers consistently land on the right side of every statistic covered in this article. They detect faster, recover cheaper, and avoid paying ransoms altogether.

Need Help With Your Security Strategy?

Get a free assessment from our team of cybersecurity experts.

Related Articles

HM

Hadley McIntosh

Updated Sep 25, 2026 · 7 min read