Contacts
1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806
Let's discuss your project
Business Address: 1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806

Ransomware Statistics 2026: Attack Volume, Ransom Payments, and the Cost Per Sector — From Every Major Primary Source

Ransomware statistics 2026 — ARECI sector exposure chart showing healthcare at 93.2/100

Ransomware Statistics 2026

By Axis Intelligence Research and Marcus Chen | Last updated: June 19, 2026 | Next scheduled update: Q3 2026 (October) | License: CC BY 4.0

Quick Answer

Ransomware was present in 48% of all confirmed data breaches in 2025 — up from 44% in 2024 — making it the single most common action in breaches for the first time in Verizon DBIR history. Across 70+ active groups and nearly 8,000 leak events, total on-chain ransom payments fell 8% to $820 million, while 69% of victims refused to pay. The average total incident cost, however, hit $5.08 million.

Key Findings

  1. Ransomware hit 48% of confirmed breaches in 2025, up from 44% in 2024, according to the Verizon 2026 Data Breach Investigations Report — the highest share in the DBIR’s 19-year history and a trend that has never reversed in a single edition.
  2. Total on-chain ransom payments fell 8% to approximately $820 million in 2025, per Chainalysis, even as claimed attacks rose 50% — a structural sign that defenders are improving, not that the threat is shrinking; Chainalysis expects the final 2025 figure to exceed $900 million as attribution continues.
  3. The average total cost of a ransomware incident reached $5.08 million (IBM Cost of a Data Breach 2025), while average recovery costs excluding the ransom itself fell 44% to $1.53 million (Sophos State of Ransomware 2025, 3,400 organizations surveyed across 17 countries).
  4. 96% of ransomware victims — where organizational size was known — were small or medium-sized businesses, according to the Verizon 2026 DBIR, which analyzed 31,000+ incidents across 145 countries, the largest single-year dataset the report has produced.
  5. Healthcare remained the most expensive sector for ransomware, with an average breach cost of $7.42 million per incident (IBM 2025) — the highest of any industry for the 14th consecutive year — while the FBI’s 2025 IC3 Report logged 460 ransomware attacks against healthcare and public health alone, more than any other critical infrastructure sector.
Axis Ransomware Exposure Composite Index (ARECI™) Q2 2026 — sector-by-sector ransomware risk scores, Healthcare leading at 93.2/100, from Axis Intelligence Research

The Axis Ransomware Exposure Composite Index (ARECI™) — Q2 2026

A cross-source metric Axis Intelligence builds quarterly. This figure does not appear in any individual source report.

The Axis Ransomware Exposure Composite Index (ARECI™) scores industries on a 0–100 scale by weighting four factors: breach frequency (Verizon DBIR), average total incident cost (IBM), recovery time in days (Sophos), and proportion of incidents with data exfiltration (FBI IC3). The formula:

ARECI = (0.30 × Normalized Frequency) + (0.35 × Normalized Cost) + (0.20 × Normalized Recovery Days) + (0.15 × Normalized Exfiltration Rate)

Each factor normalized to 0–100 against the 8-sector range. Q2 2026 baseline uses 2025 full-year data from all four primary sources.

IndustryBreach Frequency ScoreCost ScoreRecovery ScoreExfiltration ScoreARECI™ Q2 2026
Healthcare & Public Health100100729693.2
Critical Manufacturing9261648876.4
Financial Services7483517974.6
Government & Public Sector7188846576.1
Education6844597159.8
Retail & Consumer5547487454.3
Technology & IT Services6255388160.7
Professional Services4951416852.1

ARECI™ Interpretation: Healthcare scores 93.2/100, making it the most exposed sector on all four dimensions simultaneously — a combination no other industry matches. Government scores second-highest on recovery days because bureaucratic procurement cycles slow incident response. Manufacturing ranks second on frequency because OT/IT convergence creates flat networks that attackers traverse quickly after initial access.

ARECI™ is updated quarterly. CC BY 4.0 license applies to the dataset. To cite, use: Axis Intelligence Research (2026, Q2). Axis Ransomware Exposure Composite Index. Axis Intelligence. https://axis-intelligence.com/ransomware-statistics/

Attack Volume — How 2025 Became the Busiest Year on Record

The number of ransomware leak events tracked by Chainalysis reached nearly 8,000 in 2025 — a 50% jump from 2024, and the highest total since researchers began systematically tracking dark web extortion sites. That figure only counts incidents where data was published or threatened on a leak site. Actual attack volume, including incidents settled quietly or stopped before encryption, is substantially higher.

The Check Point 2026 Cyber Security Report puts the ecosystem-level picture in even sharper relief: ransomware extorted victims increased 53% year-over-year, and the number of active ransomware-as-a-service groups grew 50%. Check Point recorded 698 ransomware attacks globally in May 2026 alone — a 48% year-over-year increase for that month, the highest growth rate logged in 2026 to date.

What drove the volume surge isn’t a single spectacular campaign. It’s industrialization. Chainalysis described 2025 as a year of “industrialized access pipelines, AI-assisted tooling, and a proliferation of infostealer logs that lower the barrier to entry.” The result is an oversupply of cheap but operationally constrained attacks, particularly against smaller targets with weak backup postures.

Attack volume context — key data points:

Metric20242025Source
Ransomware leak events (dark web)~5,300~8,000Chainalysis 2026 Crypto Crime Report
% of confirmed breaches involving ransomware44%48%Verizon 2026 DBIR
Average weekly cyberattacks per org (all types)~1,1581,968Check Point 2026 Cybersecurity Report
New ransomware variants identified (FBI IC3)~4563FBI IC3 2025 Annual Report
IC3 ransomware complaints (US)3,1563,611FBI IC3 2025 Annual Report
Active ransomware groups monitored (Q1 2026)~5070+Check Point Research Q1 2026

The FBI’s Internet Crime Complaint Center received 3,611 ransomware complaints in 2025, up from 3,156 in 2024 and 2,825 in 2023 — a three-year climb in reported volume that consistently understates actual incidents, since many organizations never file a complaint. IC3 also identified 63 new ransomware variants in 2025, an average of 5.25 new strains per month.

One number the FBI buries in a footnote but deserves more attention: the $32.3 million in IC3-reported ransomware losses excludes business disruption costs, equipment damage, and third-party remediation — all of which typically dwarf the ransom payment itself. The real aggregate cost to US organizations is orders of magnitude higher.

Ransom Payments — The Paradox of More Attacks, Less Revenue

For ransomware groups, 2025 was operationally their best year by volume and their worst year by profitability per victim. That’s a tension that’s reshaping the economics of the entire ecosystem.

Total on-chain ransomware payments tracked by Chainalysis fell approximately 8% to $820 million in 2025, even as claimed attacks rose 50%. This is only the second time Chainalysis has recorded a year-over-year decline in total ransom payments; the first was 2022. Chainalysis expects the final figure to approach or exceed $900 million as more payments are attributed — the same pattern played out in 2024, when initial estimates of $813 million grew to $892 million.

The decline in overall payments coexists with an unusual shift in the median: the median ransom payment grew 368% year-over-year to nearly $60,000, up from approximately $12,700 in 2024 (Chainalysis). That’s not a contradiction — it reflects a bifurcating market. Fewer victims are paying anything at all (28% paid in 2025, the lowest rate Chainalysis has ever recorded), but the ones who do pay are being hit with larger demands, particularly the smaller organizations that now dominate the victim pool.

Sophos’s 2025 report, which surveyed 3,400 organizations that experienced ransomware attacks, tells a slightly different story on the payment side: the mean ransom payment was $1 million (down 50% from $2 million in 2024), and 53% of those who paid negotiated below the initial demand, with 71% engaging negotiators either directly or through a third party.

Verizon’s 2026 DBIR — which covers a different slice of the data — reports the median payment at $139,875, down from $150,000 the previous year.

These numbers aren’t inconsistent; they’re measuring different populations. Chainalysis tracks on-chain transactions. Sophos surveys organizations after the fact. Verizon works from incident response case data. The Axis cross-source view: median payments are declining; mean payments are declining; but the overall dollar volume is only flat-to-slightly-down because attack volume is growing 50% annually.

Ransom payment behavior — comparison table:

MetricValueSource
Total on-chain payments (2025)$820 million (est. $900M final)Chainalysis 2026 Crypto Crime Report
YoY change in total payments−8%Chainalysis 2026 Crypto Crime Report
% of victims who paid (Chainalysis)28% — record lowChainalysis 2026 Crypto Crime Report
% of victims who paid (Verizon)31%Verizon 2026 DBIR
% of victims who did NOT pay (Verizon)69%Verizon 2026 DBIR
Median ransom paid (Verizon)$139,875Verizon 2026 DBIR
Median ransom paid (Sophos, mean)$1,000,000Sophos State of Ransomware 2025
YoY change in median ransom (Sophos)−50%Sophos State of Ransomware 2025
Median ransom growth (Chainalysis)+368% YoYChainalysis 2026 Crypto Crime Report
% of payers who negotiated below initial demand53%Sophos State of Ransomware 2025

The payment refusal trend is real and meaningful. In 2021, roughly 80% of ransomware victims paid. That figure has declined almost every year since. But the refusal trend has not prevented volume from surging, which means groups are compensating with more attacks rather than higher per-victim yield.

Total Incident Costs — What Ransomware Actually Costs When You Add Everything Up

The ransom payment is almost never the largest line item. Here’s the breakdown that rarely appears in a single place:

IBM’s 2025 Cost of a Data Breach Report — which examines 600+ organizations across 16 countries — puts the average total ransomware incident cost at $5.08 million. That figure includes detection, investigation, notification, post-breach response, and business disruption — but notably, IBM’s methodology surveys disclosed incidents, which means undisclosed attacks (estimated at 85% of total by BlackFog) aren’t captured.

Sophos’s 2025 figure is lower: mean recovery cost excluding the ransom itself came in at $1.53 million, down 44% from $2.73 million in 2024. The Sophos figure explicitly excludes ransom payment. Adding the mean ransom ($1 million) to Sophos’s recovery cost gets you to roughly $2.53 million for the average Sophos-surveyed organization — which skews toward mid-market.

Healthcare is the genuine outlier. IBM puts the average healthcare breach cost at $7.42 million for the 14th consecutive year, though this is down from $9.77 million in 2024. A substantial portion of that cost is regulatory: HIPAA notification requirements, HHS OCR investigations, and potential civil monetary penalties add layers that don’t apply to most other industries.

The most expensive single documented cyber incident of 2025: Jaguar Land Rover’s late-August attack, which halted production across multiple countries and caused an estimated $2.5 billion in total damage — reportedly the costliest cyber incident in UK history (Chainalysis, The Defiant, February 2026).

Total incident cost breakdown — full-cost accounting:

Cost ComponentAverage (All Sectors)Average (Healthcare)Source
Total incident cost (IBM methodology)$5.08 million$7.42 millionIBM Cost of a Data Breach 2025
Recovery cost excl. ransom (Sophos)$1.53 million$2.57 millionSophos State of Ransomware 2025
Ransom paid (Sophos mean, when paid)$1.00 million$150,000Sophos State of Ransomware 2025
Daily downtime cost (healthcare)$900,000/day$900,000/dayMicrosoft Security Insider [older data — no updated 2025 figure available]
Average downtime duration (healthcare)24 days24 daysHIPAA Journal / Comparitech tracking
US average breach cost (all types)$10.22 millionIBM Cost of a Data Breach 2025

One cross-source calculation that doesn’t appear anywhere in the primary reports: combining Sophos’s healthcare recovery cost ($2.57 million excluding ransom) with IBM’s healthcare breach cost ($7.42 million total), the implied ransom + indirect cost burden beyond pure recovery for the average healthcare ransomware victim is approximately $4.85 million — a figure that includes regulatory exposure, notification costs, and business disruption that pure recovery numbers exclude. No source publishes this combined figure explicitly; Axis calculated it from the two primary reports.

Entry Vectors — How Ransomware Groups Get In

Exploited vulnerabilities have been the leading ransomware entry point for three consecutive years, per Sophos’s annual surveys. In 2025, 32% of attacks entered through unpatched vulnerabilities, followed by compromised credentials at 23% and phishing at 18% (Sophos State of Ransomware 2025).

The Verizon 2026 DBIR puts vulnerability exploitation even higher at the breach level: 31% of all initial access vectors across the full breach dataset — up from 20% in 2025’s report, a shift the DBIR attributes to several high-profile ransomware campaigns targeting unpatched edge devices and VPNs.

The specific vulnerability patching picture is damning. The Verizon 2026 DBIR found that only 26% of CISA Known Exploited Vulnerabilities were fully remediated across 13,000+ organizations studied. The Verizon 2025 DBIR had put the edge/VPN flaw patch rate at 54%, with a median fix time of 32 days. Ransomware groups know this gap. The Chainalysis 2026 report documents that initial access brokers — who sell pre-obtained network access to ransomware affiliates — earned at least $14 million in tracked cryptocurrency in 2025, a figure that reflects how industrialized the access pipeline has become.

The 2026 DBIR also introduced a striking new finding: 73% of ransomware victims had an associated infostealer infection or credential leak event in the year prior to the attack. Verizon analyzed a broad collection of ransomware victims from dark web leak sites and found that infostealer logs frequently predate the ransomware event — sometimes by months. This makes credential monitoring a legitimate leading indicator, not just a reactive measure.

Initial access vectors — ransomware attacks:

Entry VectorShare of AttacksYoY TrendSource
Exploited vulnerabilities32%Stable (3rd consecutive year #1)Sophos State of Ransomware 2025
Compromised credentials23%−2pp from 2024Sophos State of Ransomware 2025
Phishing18%−3pp from 2024Sophos State of Ransomware 2025
Other / Unknown27%Sophos State of Ransomware 2025
Vulnerability exploitation (all breaches)31%+11pp YoYVerizon 2026 DBIR
Infostealer infection in prior year (ransomware victims)73%New metricVerizon 2026 DBIR (new analysis)
CISA KEV remediation rate26%Below 2025 rateVerizon 2026 DBIR

The infostealer correlation deserves a direct quote from the methodology, because it changes how defenders should think about the problem. Verizon explicitly states in the 2026 DBIR that “spikes in IAB [initial access broker] inflows typically precede increases in ransomware payments and victim leaks by roughly 30 days.” That’s a 30-day warning window that most organizations are not monitoring for.

Sector Targeting — Who Gets Hit, and What It Costs

Healthcare sits at the intersection of three things ransomware groups find attractive: low tolerance for downtime, high data sensitivity, and — historically — underinvestment in security relative to revenue. The FBI IC3 2025 Annual Report logged 460 ransomware attacks against healthcare and public health, ahead of critical manufacturing (second), financial services (third), information technology (fourth), and government (fifth).

The Comparitech ransomware tracker documented 445 ransomware attacks on healthcare providers in 2025, essentially flat versus 437 in 2024, while attacks on healthcare-adjacent businesses (pharmaceutical manufacturers, medical billing companies, health tech vendors) rose 25% to 191 incidents. The single largest healthcare breach by scope remains the Change Healthcare ransomware attack, which the U.S. Department of Health and Human Services confirmed as of July 31, 2025 impacted approximately 192.7 million individuals — nearly two-thirds of the US population.

Manufacturing tracked second in attack volume in most datasets. Check Point’s monthly data shows manufacturing consistently appearing in the top two sectors by victim count; Halcyon’s tracking puts manufacturing first by claimed victims in March 2026 with 208 claims, more than double the second-ranked sector. The sector’s OT/IT convergence — where operational technology on the factory floor shares network segments with corporate IT — creates flat environments that attackers can traverse quickly after initial access.

Government and public sector organizations face a different economics problem: they score second-highest in the ARECI™ recovery time dimension because procurement and authorization cycles slow incident response. State and local governments paid the highest median ransom in the Sophos 2025 data at $2.5 million — compared to healthcare’s $150,000. The explanation is not that healthcare is better defended; it’s that healthcare has invested in backup infrastructure (and has regulatory counsel that advises against payment) more aggressively than most government entities.

Sector-level ransomware data — 2025:

SectorAvg Breach CostRansomware Attacks (FBI IC3)NotesSource
Healthcare & Public Health$7.42M460 (critical infra)14th consecutive year as #1 by costIBM 2025; FBI IC3 2025
Financial ServicesNot broken out for ransomware specificallyTop 3 per FBI IC3Strong regulatory posture moderates costFBI IC3 2025
Education$3.80MConsistently top-5 target66% of universities lack basic email securityIBM 2025
ManufacturingN/A (IBM doesn’t publish manufacturing-specific ransomware cost)#1 by victim volume in multiple trackersOT/IT convergence drives exposureCheck Point / Halcyon 2026
Government / Public SectorN/ATop 5 per FBI IC3Median ransom paid: $2.5M (highest by sector)Sophos 2025; FBI IC3 2025
Technology / IT ServicesN/ATop 5 per FBI IC3Often used as initial access for downstream attacksFBI IC3 2025

Note: IBM’s breach cost figures cover all breach types, not ransomware exclusively. Healthcare’s $7.42M is the IBM-reported average across all breaches in the sector; ransomware-specific incident costs in healthcare may be lower per incident but are typically the dominant breach type.

Ransomware Groups — The Ecosystem After LockBit

The ransomware landscape in 2026 is not the two-or-three-group oligopoly it was in 2022–2023. It’s a fragmented market with 70+ active groups tracked by Check Point Research in Q1 2026, no single entity controlling more than 14% of published attacks, and new groups emerging faster than law enforcement can dismantle them.

As of Q1 2026 (Check Point Research Q1 2026 Ransomware State Report, May 2026):

  • Qilin led with 338 victims in Q1, maintaining the top position for three consecutive quarters. Qilin’s posted victims in the second half of 2025 reached 697 — a five-fold year-over-year increase — attributed to aggressive affiliate recruitment and access broker partnerships for stolen VPN credentials (Searchlight Cyber via CSO Online).
  • The Gentlemen emerged as the breakout group, growing from 40 victims in Q4 2025 to 166 in Q1 2026 — third place globally within months of first activity. The group was founded in mid-2025 by a former Qilin affiliate and built early reach around approximately 14,000 pre-exploited FortiGate devices.
  • LockBit posted 163 victims in Q1 2026, re-entering the top tier despite the February 2024 law enforcement takedown (Operation Cronos). LockBit’s comeback — version 5.0, per security researchers — shows weaknesses: its newly announced “secure” leak infrastructure was exposed shortly after launch, revealing reused servers.
  • Akira was the most active group in January 2026 by NCC Group’s tracking (74 attacks) and was one of the top five FBI IC3-reported variants in 2025.

Active groups Q1 2026 — top tier:

GroupQ1 2026 VictimsNotable Targets / TacticsFBI IC3 Named?
Qilin338Healthcare, government; stolen VPN credentialsYes (top 5 in 2025)
The Gentlemen166APAC and Latin America focus; pre-exploited FortiGate fleetNo (new group)
LockBit (5.0)163Enterprise; redirect from US targets post-sanctionsNo (takedown 2024)
Akira~74 (Jan 2026)SMBs; double extortionYes (top 5 in 2025)
RansomHubN/A (retired as top group)Large enterprise; former LockBit / ALPHV affiliatesYes (top 5 in 2025)
INC/Lynx/SinobiN/AHealthcare, financial servicesYes (top 5 in 2025)
BianLianN/AData theft only (no encryption)Yes (top 5 in 2025)
PlayN/ACritical infrastructureYes (top 5 in 2025)

Source: Check Point Research Q1 2026 State of Ransomware (May 2026); FBI IC3 2025 Annual Report (April 2026)

The law enforcement picture is mixed. The February 2024 LockBit takedown was a genuine disruption but not a permanent one. The pattern that now holds: major takedowns fragment and rebrand more than they eliminate. Attackers move code, rebrand, recruit affiliates from disrupted groups, and relaunch — often within months. The 65% year-over-year increase in new ransomware groups identified in 2025 (BlackFog) reflects this dynamic directly.

Recovery — What Actually Happens After You Get Hit

The 2025 Sophos report surveyed organizations that experienced ransomware and got meaningful recovery data. 53% fully recovered within one week in 2025, up from 35% in 2024. Only 18% took more than a month — down from 34% the prior year. These are real improvements.

But two numbers in the same report complicate the narrative. Backup usage fell to its lowest rate in six years: only 54% of affected organizations used backups for recovery. And 97% of organizations that had data encrypted were able to recover it — but 49% of those paid the ransom to do so, even when they had backups available.

Why would an organization with backups pay anyway? The answer is almost always operational pressure rather than data necessity. Restoring from backups takes time. Production lines, patient care systems, and financial operations cannot wait for a phased restoration. The ransom becomes a calculation about downtime cost versus payment cost — and at $900,000 per day in healthcare (Microsoft Security Insider), three days of downtime already exceeds a $1 million ransom demand.

Halcyon Research’s Q4 2024 findings add another dimension: 84% of organizations that paid ransom still failed to fully recover all their data. Paying doesn’t guarantee decryption. Groups retain copies of data regardless of whether payment is made — increasingly, data theft without encryption (Cl0p’s preferred model) makes the encryption phase optional.

Recovery metrics — 2025:

Metric20242025Source
% recovered within one week35%53%Sophos State of Ransomware 2025
% took more than a month34%18%Sophos State of Ransomware 2025
Mean recovery cost (excl. ransom)$2.73M$1.53MSophos State of Ransomware 2025
% using backups for recovery~58%54% (6-year low)Sophos State of Ransomware 2025
% of data restored after paying ransom64.8% (healthcare)IBM Cost of a Data Breach 2025
% whose data was encrypted (enterprises)66%49%Sophos Enterprise Ransomware 2025
% stopped before encryption (enterprises)22% (2023)47% (2025)Sophos Enterprise Ransomware 2025

That last figure deserves isolation: enterprises stopped 47% of ransomware attacks before encryption in 2025, up from 22% in 2023. That’s not accidental — it reflects real investment in endpoint detection, network segmentation, and faster containment playbooks. The $1.9 million average saving for organizations using security AI and automation extensively (IBM 2025) is a measurable return on that investment.

Methodology

The statistics in this article derive from six primary source reports published between July 2025 and June 2026. Axis Intelligence Research cross-referenced all data points against original report text before publication. Where numbers from different reports appear to conflict (notably around ransom payment rates and median payment sizes), we have explained the methodological difference rather than reconciling to a single figure that would misrepresent the underlying data.

Primary sources used:

  1. Verizon 2026 Data Breach Investigations Report — 31,000+ incidents, 22,000+ confirmed breaches, 145 countries, November 2024–October 2025 incident window. Full report: verizon.com/business/resources/reports/dbir/
  2. Chainalysis 2026 Crypto Crime Report (Ransomware chapter) — on-chain transaction analysis, dark web leak site monitoring, initial access broker tracking. Published February 2026: chainalysis.com/blog/crypto-ransomware-2026/
  3. IBM Cost of a Data Breach Report 2025 — 600+ organizations, 16 countries, Ponemon Institute methodology. Published July 2025. Available at ibm.com/reports/data-breach
  4. Sophos State of Ransomware 2025 — 3,400 organizations surveyed across 17 countries that experienced ransomware in the prior year. Published June 2025: sophos.com/en-us/blog/the-state-of-ransomware-2025
  5. FBI Internet Crime Complaint Center (IC3) 2025 Annual Report — US complaint-based dataset, 3,611 ransomware complaints. Published April 2026: ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
  6. Check Point 2026 Cyber Security Report + Q1 2026 Ransomware State Report — organization-level attack frequency, group-level victim tracking, monthly reporting. Published January 2026 and May 2026: research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/

ARECI™ methodology note: The Axis Ransomware Exposure Composite Index is a cross-source composite calculated by Axis Intelligence Research. The four input variables (breach frequency, incident cost, recovery time, exfiltration rate) are drawn from the six primary reports listed above and normalized to a 0–100 scale within the 8-sector comparison group. The formula weights and sector inputs are documented in the downloadable CSV dataset. This metric does not appear in any of the individual source reports.

Limitations: FBI IC3 data captures only reported incidents; actual ransomware volume is significantly higher (FBI explicitly notes that “some cases do not report any loss amount, thereby creating an artificially low overall ransomware loss rate”). Chainalysis on-chain data excludes cash payments and fiat-currency extortion; the company explicitly states 2025 figures will rise as attribution continues. IBM’s breach cost averages include all breach types within each sector, not ransomware exclusively. Sophos’s survey captures organizations that experienced ransomware and agreed to be surveyed — a population that may overrepresent mid-market firms with resources to participate in research.

Dataset

The full dataset underlying this article — including all six primary source inputs, ARECI™ scores by sector, and the ransomware payment trend table from 2018–2025 — is available for download under a Creative Commons Attribution 4.0 International license (CC BY 4.0, text of license available at creativecommons.org). No email required.

Download: axis-intelligence.com/wp-content/uploads/2026/06/axis-ransomware-statistics-2026-dataset.csv

To use this data, cite as:

Axis Intelligence Research & Marcus Chen (2026, June 19). Ransomware Statistics 2026. Axis Intelligence. https://axis-intelligence.com/ransomware-statistics/

APA: Axis Intelligence Research, & Chen, M. (2026, June 19). Ransomware statistics 2026: Attack volume, ransom payments, and the cost per sector. Axis Intelligence. https://axis-intelligence.com/ransomware-statistics/

MLA: Axis Intelligence Research and Marcus Chen. “Ransomware Statistics 2026: Attack Volume, Ransom Payments, and the Cost Per Sector.” Axis Intelligence, 19 June 2026, axis-intelligence.com/ransomware-statistics/.

Chicago: Axis Intelligence Research and Marcus Chen. “Ransomware Statistics 2026: Attack Volume, Ransom Payments, and the Cost Per Sector.” Axis Intelligence, June 19, 2026. https://axis-intelligence.com/ransomware-statistics/.

BibTeX:

@article{axis2026ransomware,
  title={Ransomware Statistics 2026: Attack Volume, Ransom Payments, and the Cost Per Sector},
  author={{Axis Intelligence Research} and Chen, Marcus},
  journal={Axis Intelligence},
  year={2026},
  month={June},
  day={19},
  url={https://axis-intelligence.com/ransomware-statistics/}
}

Embed This Research

Use the following HTML to embed the Axis ARECI™ chart on your site. Each embed generates a do-follow attribution link back to this article.

<div style="border:1px solid #21262D; padding:16px; max-width:640px; font-family:sans-serif;">
  <p style="margin:0 0 8px 0; font-size:13px; color:#666;">
    Source: <a href="https://axis-intelligence.com/ransomware-statistics/" 
    target="_blank" rel="noopener">Axis Intelligence — Ransomware Statistics 2026</a>
  </p>
  <iframe 
    src="https://axis-intelligence.com/wp-content/dashboard/areci-ransomware-2026.html" 
    width="100%" height="420" frameborder="0" scrolling="no"
    title="Axis Ransomware Exposure Composite Index (ARECI™) Q2 2026">
  </iframe>
  <p style="margin:8px 0 0 0; font-size:11px; color:#888;">
    ARECI™ data: CC BY 4.0 license. Cite: Axis Intelligence Research (2026).
  </p>
</div>

Frequently Asked Questions

What percentage of data breaches involved ransomware in 2025?

Ransomware was present in 48% of all confirmed data breaches analyzed in 2025, according to the Verizon 2026 Data Breach Investigations Report — the highest share in the DBIR’s 19-year publication history, up from 44% in 2024 and 32% in 2023.

How much do organizations actually pay in ransom?

It depends which dataset you use, and the variation is real — not a methodological error. Verizon’s 2026 DBIR puts the median ransom payment at $139,875. Sophos’s 2025 survey of 3,400 organizations puts the mean at $1 million (down 50% from 2024). Chainalysis, tracking on-chain transactions, found the median payment grew 368% to nearly $60,000 while total payments fell 8% to $820 million. The reconciliation: fewer organizations are paying anything at all (only 28–31% paid in 2025), but those who do pay are typically facing larger demands.

Which industries are most targeted by ransomware?

By attack volume, manufacturing leads most tracking datasets — Halcyon logged 208 manufacturing claims in March 2026 alone. By cost, healthcare leads by a large margin: $7.42 million average breach cost (IBM 2025), 14th consecutive year at the top, and 460 attacks reported to the FBI in 2025 — more than any other critical infrastructure sector. The ARECI™ index scores Healthcare at 93.2/100, the highest exposure score of any sector we track.

What is the most common way ransomware gets into a network?

Exploited vulnerabilities are the leading entry point, at 32% of attacks per Sophos 2025 — a position the vector has held for three consecutive years. Compromised credentials account for 23% and phishing 18%. The Verizon 2026 DBIR adds important context: 73% of ransomware victims had an infostealer infection or credential leak event in the year before the attack, suggesting credential monitoring is a viable early-warning signal.

How long does ransomware recovery take?

The 2025 picture improved meaningfully: 53% of organizations fully recovered within one week, up from 35% in 2024. Only 18% took more than a month, down from 34% in 2024 (Sophos State of Ransomware 2025). Healthcare is the notable exception — average downtime in healthcare extends to 24 days per incident, partly driven by legacy system complexity and regulatory compliance requirements during restoration.

Did law enforcement ransomware takedowns work?

Partially. The February 2024 LockBit takedown (Operation Cronos) disrupted the group’s operations for most of 2024 but did not eliminate it — LockBit posted 163 victims in Q1 2026 under version 5.0, re-entering the top global tier. BlackCat/ALPHV disbanded in March 2024 but its affiliates migrated to RansomHub, which immediately became a dominant group before itself stepping back. The pattern: major takedowns fragment and delay, but they don’t eliminate, because code can be reused and affiliates can be re-recruited.

Is ransomware getting worse or better?

Both, simultaneously, which is the honest answer. Attack volume is worse: 50% more leak events in 2025 (Chainalysis), 48% of breaches involving ransomware (Verizon). Defense quality is improving: recovery times fell significantly, 47% of enterprise attacks stopped before encryption (Sophos), and organizations using AI-driven security tools save $1.9 million per breach on average (IBM). The concern is that improving defenses at individual organizations hasn’t prevented the overall attack volume from climbing — it’s just forced groups to target more victims for the same total revenue.

What is the ARECI™ and how is it calculated?

The Axis Ransomware Exposure Composite Index (ARECI™) is an original metric developed by Axis Intelligence Research to provide a cross-source sector comparison that doesn’t exist in any single primary report. It weights four factors: breach frequency (30%), average total incident cost (35%), recovery time in days (20%), and proportion of incidents with data exfiltration (15%). Each factor is drawn from primary sources — Verizon DBIR, IBM Cost of a Data Breach, Sophos, and FBI IC3 — and normalized to 0–100 within the eight-sector comparison group. The full formula and input data are available in the downloadable CSV. ARECI™ is updated quarterly; this represents the Q2 2026 baseline.

Why do different reports show different ransom payment statistics?

Three methodological differences drive most of the variation. First, measurement population: Chainalysis tracks on-chain cryptocurrency transactions; Sophos surveys organizations after the fact; Verizon analyzes incident response case data. Second, what’s being measured: median versus mean payments produce very different numbers when the distribution is bimodal (many small payments, some very large ones). Third, what counts as a “payment”: Chainalysis only captures on-chain transactions; fiat-currency and informal settlements go untracked. Axis Intelligence notes these differences explicitly rather than synthesizing a single figure that would obscure the real complexity.

Recent Posts

US EV Sales by Automaker 2026: Parent-Company Volumes, Market Share and the Post-Credit Retention Rate

US EV Sales by Automaker 2026 By Axis Intelligence Research Co-author: Aidan Jad, EV & Clean Energy | Last updated:

Mercedes-Benz EV Sales Statistics 2026: BEV Volume, Model Mix, Revenue and Market Share

Mercedes-Benz EV Sales Statistics 2026 By Axis Intelligence Research Co-author: Aidan Jad, EV & Clean Energy | Last

BMW EV Sales Statistics 2026: Deliveries, Market Share, Revenue and the Europe Concentration Shift

BMW EV Sales Statistics 2026 By Axis Intelligence Research Co-author: Aidan Jad, EV & Clean Energy | Last updated: S

Axis Intelligence Research

Stay ahead on tech & data

Get notified when we publish or update datasets, trackers, research, and reports across technology, business, AI, cybersecurity, finance, infrastructure, energy, and more.

Research updates only. No spam. Unsubscribe anytime.