Two numbers from the same year tell you most of what you need to know about ransomware in 2026. According to Chainalysis, victims paid roughly $820 million in tracked ransomware payments during 2025, an 8% drop from the year before. Over the same period, the number of victims named on extortion leak sites rose by about 50%, making it the most active year on record.
More attacks, less money. The share of claimed victims who paid anything fell to around 28%, which Chainalysis described as potentially an all-time low. Refusing to pay has become the majority position, helped along by better backups, tighter insurance underwriting and a growing recognition that paying buys a promise from a criminal.
The response from the criminal side has been to change tactics rather than volume: more theft and less encryption, more pressure applied outside the IT department, and a deliberate effort to destroy the recovery options that let organizations say no. This article walks the attack lifecycle as defenders see it, using verified incident data, so you can work out where your own gaps are. It describes what happens conceptually. It contains no instructions for doing any of it.
The business model behind the attack
Ransomware stopped being a hobby a decade ago. The dominant structure is ransomware-as-a-service, where a core group builds the encryption software, runs the leak site and handles payments, while affiliates carry out intrusions and take a cut of the proceeds.
Feeding that pipeline are initial access brokers, who compromise organizations and sell the foothold on rather than extorting anyone themselves. Chainalysis tracked at least $14 million flowing to initial access brokers in 2025, roughly one dollar for every 58 dollars of ransom paid. The price of access has collapsed: the average listing fell from about $1,427 in the first quarter of 2023 to about $439 in the first quarter of 2026. Cheap access means affiliates can afford to attack organizations that would never have justified the effort before.
The ecosystem is also more fragmented than it was. Chainalysis counted roughly 85 active extortion groups in 2025 after law enforcement disruption of several large brands. Fragmentation is not good news for defenders. It means fewer predictable playbooks, more inexperienced affiliates causing collateral damage, and less chance that a disrupted group’s decryption keys ever surface.
Coveware’s second-quarter 2026 report found that no single group held more than 17% of observed cases, and that data-theft-focused operations dominated the top of the table. That is a meaningful shift from an era when a handful of encryption-first brands accounted for most incidents.
Stage one: getting in
Two of the largest data sets on this disagree in an instructive way.
Google’s Mandiant, drawing on more than 500,000 hours of incident response in its M-Trends 2026 report published in March 2026, found exploitation of vulnerabilities as the leading initial infection vector at 32%, the sixth consecutive year it has topped the list. Voice phishing came second at 11%, prior compromise at 10%, and email phishing at just 6%. For ransomware incidents specifically, prior compromise was the leading route at 30%, roughly double the previous year.
Sophos, surveying 2,158 IT and security leaders across 17 countries in the first quarter of 2026 for its State of Ransomware 2026, put malicious email at 26%, phishing at 24%, compromised credentials at 23% and exploited vulnerabilities at 18%.
The gap reflects who is answering. Incident responders see the intrusions serious enough to call in Mandiant, which skews toward edge-device exploitation. Survey respondents report what they believe happened. Both are true.
Where they agree is identity. Sophos found that 79% of ransomware attacks began with an identity-based approach, and that in its incident response work, 59% of cases involved MFA missing on critical systems. Mandiant’s rise in “prior compromise” points the same direction: the credential was stolen earlier, by someone else, and the ransomware affiliate simply logged in.
The most expensive illustration is Change Healthcare. UnitedHealth’s chief executive told US lawmakers that attackers entered in February 2024 using stolen credentials on a remote access portal that was not protected by multi-factor authentication. The breach ultimately affected more than 100 million people, the largest known theft of US medical records.
Stage two: dwell time
Dwell time is the gap between an attacker getting in and being detected. Mandiant put the 2025 global median at 14 days, up from 11 days in 2024. Where an outside party had to notify the victim, the median stretched to 25 days.
Two weeks sounds short until you consider what it is used for. That window is when an intruder maps the network, identifies where the valuable data lives, finds the backup infrastructure, works out which accounts have administrative reach, and quietly stages data for removal. Encryption happens at the end, because it is the loudest possible action.
The handoff between specialists has become extraordinarily fast. Mandiant measured a median of 22 seconds in 2025 between initial access and transfer to a second group, compared with more than eight hours in 2022, in the 9% of investigations where that division of labour appeared. Automation has removed the human pause that defenders used to be able to exploit.
Stage three: escalation and lateral movement
The goal at this stage is not clever technique. It is administrative control over the systems that manage everything else.
In practice that means the identity layer. In a typical Windows environment, control of the directory service means the ability to create accounts, change permissions and reach every domain-joined machine through legitimate management channels. Mandiant’s 2026 report specifically calls out attacks on identity services, including certificate services, alongside virtualization management planes.
That last target matters more than it used to. If an environment runs hundreds of servers as virtual machines, compromising the hypervisor management layer lets an attacker affect all of them without ever touching the guest operating systems, and without triggering endpoint security that lives inside those guests.
Much of this movement uses tools that already exist on the network. Remote management software and administrative utilities are legitimate, signed and expected, which is precisely why they are used. Detection depends less on spotting malware than on noticing that a service account started behaving like an administrator at three in the morning.
Stage four: exfiltration and the extortion ladder
Data theft before encryption is now standard practice, because it gives the attacker leverage that survives a successful restore.
The escalation usually runs in stages. Single extortion is encryption alone: pay for the decryption key. Double extortion adds stolen data: pay, or we publish it. Triple extortion adds pressure from outside, which in practice means contacting the victim’s customers, partners, employees or journalists, and in some documented cases filing complaints with data protection regulators against the victim.
Some groups have dropped encryption altogether. Coveware found that exfiltration-only extortion accounted for about 15% of its Q2 2026 cases, and named data-theft-focused groups as the most active. Theft-only attacks are quieter, faster and avoid the operational disruption that tends to trigger law enforcement involvement.
This is also the point where paying stops making obvious sense. A decryption key can be tested. A promise to delete data cannot be verified, and the same data has in several documented cases resurfaced under a different group after the original operation collapsed. That is what happened after Change Healthcare: UnitedHealth paid $22 million to the ALPHV/BlackCat group, whose leadership then disappeared with the money, and a successor operation calling itself RansomHub extorted the company a second time with samples of the same stolen files.
Stage five: recovery denial
The clearest strategic shift in the last two years is that attackers now attack the recovery plan directly, before triggering the encryption.
Mandiant describes this as recovery denial and lists the targets: backup infrastructure, identity services, virtualization management, and cloud storage objects holding backup data. The reasoning is straightforward. If 66% of organizations with encrypted data recover using backups, as Sophos found, then destroying backups is worth more to the attacker than improving the encryption.
This is why immutability, rather than mere existence, has become the defining property of a useful backup. A backup an administrator can delete is a backup a compromised administrator account can delete.
What negotiation actually looks like
The reality is more commercial than the phrase suggests. Negotiation typically runs through a specialist firm and an insurer, on a chat portal run by the attacker, over days rather than hours. The numbers show wide dispersion. Coveware reported an average payment of about $1.88 million in Q2 2026 against a median of $150,000, meaning a small number of very large payments dragged the average up while the typical case stayed far lower. Chainalysis put the 2025 median on-chain payment at $59,556, up sharply from $12,738 in 2024, which is consistent with fewer but larger payers.
Sophos found the median ransom demand at $698,000, down about 65% over two years, and that 51% of organizations that engaged negotiated the amount down. Of organizations whose data was encrypted, 48% paid something.
What negotiation cannot deliver is certainty. It can buy time to assess whether backups are viable, establish what data was actually taken, and confirm whether the tooling works at all. It cannot confirm deletion. Law enforcement in the US, UK and Canada consistently advises against paying, while stopping short of prohibiting it for private organizations.
Recovery costs more than the ransom
Whether or not a ransom is paid, the recovery bill dominates. Sophos put the average recovery cost at $1.7 million per incident in its 2026 survey, up 11% year over year, with 55% of organizations back to normal operations within a week.
The public examples are larger. Marks & Spencer’s April 2025 attack, attributed to the DragonForce ransomware-as-a-service operation working with the social-engineering group known as Scattered Spider, cut the retailer’s statutory pre-tax profit from £391.9 million to £3.4 million, a 99% fall. Online clothing orders were suspended for weeks and click-and-collect for nearly a month. The initial access was reported as social engineering involving impersonation of staff to an IT help desk, which cost the attacker nothing.
Official complaint data understates all of this badly. The FBI’s 2025 Internet Crime Report logged 3,611 ransomware complaints with $32.3 million in reported losses, against $20.877 billion in total reported cybercrime losses. The gap between $32.3 million and the industry estimates above is a reporting gap, not a measurement of harm. IC3’s most-reported variants for 2025 were Akira, Qilin, the INC/Lynx/Sinobi cluster, BianLian and Play.
What this means for you: defences that measurably move the needle
The controls below are ordered roughly by how much risk they remove per dollar, based on the root-cause data above rather than on vendor categories.
- Phishing-resistant MFA on every remote entry point. With 79% of attacks starting from identity and 59% of Sophos incident-response cases missing MFA on critical systems, this is the single highest-value control. VPN portals, remote desktop gateways, email and administrative consoles first.
- Patch internet-facing devices on a separate, faster clock. Exploitation has led Mandiant’s initial-access list for six straight years, and the targets are overwhelmingly edge appliances. Treat a firewall, VPN concentrator or file transfer appliance vulnerability as an incident, not a ticket.
- Backups built to the 3-2-1-1-0 rule. Three copies of the data, on two different media types, with one off-site, one immutable or air-gapped copy, and zero errors verified by automated restore testing. The immutable copy and the verification step are the two that ransomware specifically targets.
- Restore rehearsals with a stopwatch. Knowing that a restore works is different from knowing it completes in 12 hours rather than nine days. Test the whole path, including the identity systems you need to log in and start the restore.
- Segment the management plane. Hypervisor consoles, backup servers and domain controllers should not be reachable from a standard user workstation. This is what turns a bad day into a contained one.
- Monitor for outbound data volume. Exfiltration precedes encryption. An unusual volume of data leaving the network is often the last detectable signal before the loud part starts.
- Help desk identity verification procedures. Two of the most costly recent incidents began with a convincing phone call. A written, enforced process for verifying a caller before resetting credentials costs nothing.
- An incident plan that assumes email is down. Offline copies of contact lists, insurer details, legal counsel and the plan itself. Plans stored only on the network being encrypted are not plans.
For smaller organizations the picture is not gentler. Verizon’s 2025 Data Breach Investigations Report found ransomware present in 44% of analysed breaches overall, but in a far higher share of small and mid-sized business breaches. Sophos found 34% of organizations with 100 to 250 employees managed to stop attacks before encryption, compared with 46% at organizations of 3,001 to 5,000 employees. Scale helps, but the basics above are available at any size.
Frequently asked questions
Should we ever pay?
It is a business decision made under duress, usually with an insurer and legal counsel. What the data supports is that paying is not reliable: the payment rate has fallen to roughly 28% without a corresponding collapse in organizations recovering, and deletion promises have demonstrably been broken. Payment also does not resolve breach notification obligations.
Does cyber insurance cover this?
Increasingly, coverage is conditional. Underwriters now commonly require MFA, endpoint detection and tested backups before writing a policy, and price accordingly. That underwriting pressure is one of the reasons payment rates have fallen.
How long until we know we have been hit?
The median in Mandiant’s 2025 caseload was 14 days, and 25 days when an external party did the notifying. About 52% of intrusions were detected internally, up from 43% the prior year, so the trend is improving slowly.
Is ransomware declining?
Payments are declining. Attacks are not. Chainalysis recorded a 50% rise in claimed victims in 2025 alongside the drop in payments, and a shift toward data theft without encryption. The threat is changing shape, not receding.
What the numbers are really telling defenders
The encouraging reading of 2025 and 2026 is that collective refusal works. When most victims stop paying, the economics of encryption-first attacks weaken, and the data shows criminals adapting toward theft and extortion rather than doubling down.
The discouraging reading is that the adaptation targets exactly the things that made refusal possible. Backups, identity systems and virtualization platforms are now primary objectives rather than afterthoughts, which means a backup strategy designed for hardware failure is no longer adequate for a threat that is actively hunting it.
The practical takeaway is unglamorous. Nearly every large incident in the public record traces back to a missing multi-factor prompt, an unpatched appliance facing the internet, or a help desk that reset a password for the wrong person. Those three failures are cheaper to fix than any of them are to survive.
Sources
- Chainalysis — Crypto Ransomware: 2026 Crypto Crime Report
- Google Cloud / Mandiant — M-Trends 2026: Data, Insights, and Strategies From the Frontlines
- Sophos — The State of Ransomware 2026: Payments Drop as Encryption Climbs
- Coveware by Veeam — Cyber Extortion Payment Trends, Q2 2026
- FBI IC3 — 2025 Internet Crime Report
- TechCrunch — UnitedHealth says Change Healthcare hack affects over 100 million
- IT Pro — M&S reveals massive financial hit from cyber attack
- Halcyon — Verizon DBIR Shows Ransomware Involved in 44% of Data Breaches
- Veeam — 3-2-1 Backup Rule Explained
- Sophos — 79% of Ransomware Attacks Now Originate from Compromised Identities
- Help Net Security — Attackers are handing off access in 22 seconds, Mandiant finds
Image credit: Photo: Rubin Observatory/NSF/AURA — CC BY 4.0 (via Wikimedia Commons)
