Ransomware Payments
What Ransomware Actually Costs
Fewer Payments, Higher Stakes
The ransomware market expanded, even as payment behavior became harder for attackers to rely on.
Black Kite observed 7,551 ransomware victims during the reporting period, alongside 61 new ransomware groups. That scale matters because it shows a market that continued to grow in volume, brands, and operating models. But growth in public victim disclosures does not necessarily mean every actor became more profitable. The economics of extortion became more uneven.
Some groups leaned into a simpler message: we do not need to encrypt you, we can publish you. Data theft only extortion remained visible across the year, especially in campaigns tied to SaaS, supply chain, and enterprise application exposure. The logic was clear. If attackers could steal sensitive data from many victims through one access path, they could apply pressure without the operational complexity of encrypting each environment.
External Payment Signals from Incident Response Datasets
Sources: Coveware Q2 2025, Veeam Q3 2025, Sophos State of Ransomware 2025. Black Kite does not directly measure payment data. These figures come from different incident-response and survey populations and are not directly comparable. They are presented as directional signals of payment behavior.
Payment Rates Are Falling
But the payment picture was mixed. Incident response firms reported that overall payment rates remained low compared with earlier ransomware cycles. Coveware reported that 26% of organizations paid in Q2 2025, while Veeam reported a historical low of 23% in Q3 2025 across encryption, data exfiltration, and other extortion scenarios. For data exfiltration only incidents, Veeam reported that payment rates fell to 19% in Q3. Those figures suggest that organizations, counsel, insurers, and incident response teams are becoming more skeptical of paying purely to suppress stolen data.
Share of organizations that paid ransomware demands in Q2 2025
Historical low payment rate reported across all extortion scenarios in Q3 2025
Lowest payment rate recorded for data exfiltration-only incidents in Q3 2025
But the Amounts Are Rising
Coveware reported sharp increases in average and median ransom payments in Q2 2025, driven in part by larger organizations affected by data-exfiltration-only incidents. Sophos separately reported a median payment of $1 million among surveyed organizations that paid to recover data. Because these sources cover different populations and methodologies, they should not be read as a single market-wide trend. The common signal is that low payment conversion has not eliminated high-value payments.
Why Actors Shifted Tactics
This tension helps explain some of the behavior observed in Black Kite data. Reported pressure on payment conversion may help explain why actors leaned into volume, data theft, brand churn, and mass disclosure tactics. It should not be read as proof that lower margins caused group proliferation. The safer conclusion is that attackers are experimenting with different ways to create leverage when payment certainty is lower than it was during earlier double extortion cycles.
The Clop Case: When the Technical Model Worked but the Payment Model Didn't
Clop's Oracle EBS campaign, described in Chapter 06, illustrates this tension directly. The technical playbook remained viable: one exposed enterprise platform, many downstream victims. But the economic outcome looked different. The campaign did not appear to reproduce the business impact or payment conversion of earlier Clop mass exploitation campaigns. External incident response reporting reached a similar conclusion, noting unusually low victim engagement and monetization. The technical model still worked. The payment model weakened.
The Market Diversified Its Pressure Tactics
Encryption therefore remains central to ransomware economics. Data theft adds pressure, but encryption still creates urgency, disruption, and business continuity risk. The most successful groups did not choose one lever. Qilin and Akira used both encryption and exfiltration, combining operational disruption with data exposure to increase pressure on victims.
The economics of 2026 ransomware were not defined by one trend. Victim volume increased. New brands entered. Data theft only extortion remained visible. Payment rates declined in some datasets. Encryption remained the strongest pressure mechanism for mature operators. The market became more adaptive, not simpler.
Next: The incident closed. The exposure didn't.
Paying — or recovering — doesn't reset the clock. See what the before-and-after security posture data shows about what actually changed (or didn’t) after disclosure.