Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Leaked Database Sheds Light on Iranian Crypto Sanctions Evasion

March 4, 2026

AI and Deepfakes Supercharge Sophisticated Cyber-Attacks: Cloudflare

March 3, 2026

Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb

March 3, 2026
Facebook X (Twitter) Instagram
Wednesday, March 4
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Ransomware Payments Decline 8% as Attacks Surge 50%
News

Ransomware Payments Decline 8% as Attacks Surge 50%

Team-CWDBy Team-CWDMarch 3, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Ransomware actors are extorting bigger payments from a smaller number of victims, as the number of those victims surges but overall revenues fall, according to Chainalysis.

The blockchain analytics firm revealed in its analysis of cryptocurrency payments to threat actors that the overall figure tumbled 8% year-on-year (YoY) to $820m in 2025.

Although the figure is likely to “approach or exceed” $900m as new events and payments are attributed over the coming months, it still represents the second consecutive year of overall decline, and sits somewhat below ransomware revenues for 2020 and 2021.

It also came as victim numbers surged by 50% YoY in 2025, making 2025 the most active year on record.

It reflects the fact that payment rates plummeted from 63% in 2024 to just 29% last year – the lowest on record.

Read more on ransomware: Record Number of Ransomware Victims and Groups in 2025.

“This overall trend is a major win against the ransomware ecosystem,” said Chainalysis in its report. “Fewer victim payments mean more work for less for attackers, an important step in shifting the economic incentives.”

The analytics firm pointed to four trends reflected in the data:

  • Fewer victims are paying, thanks to improved incident response and increased regulatory scrutiny
  • Global action against ransomware operators, infrastructure and laundering networks has helped to limit some revenue flows
  • Some strains like VolkLocker contain cryptographic weaknesses that allow free decryption in some cases
  • Marked fragmentation of ransomware-as-a-service (RaaS) operations means a surge in smaller, independent groups, which may number as many as 85 today

Turning Up the Heat

However, organizations that do give in to extortion in this new landscape may find that it’s costing them more. The median payment increased 368%, from $12,738 in 2024 to $59,556 in 2025.

Tactics such as contacting employees and customers of victimized organizations, and analyzing exfiltrated data to make more targeted threats may be helping to ramp up media payment further, Chainalysis said.

“Ransomware actors remain highly opportunistic,” the report warned. “They do not consistently favor a specific sector at a given time of year. Instead, they exploit exposed services and misconfigurations as they arise, and capitalize on newly disclosed vulnerabilities.”

The US was the most heavily targeted country last year, followed by Canada, Germany, the UK, and other parts of Europe. Manufacturing and finance/professional services were the most heavily hit in most of these countries, although Canada and Germany had a high compromise rate in supply chains, logistics and critical infrastructure.

Payments to initial access brokers (IABs) remained relatively flat from 2024, at $14m, but historically high.

The report also claimed that infrastructure such as bulletproof hosting, residential proxy networks, and malware loaders is now used by financially motivated cybercrime groups as well as state-linked threat actors conducting espionage and influence operations.

“As a result, dismantling or sanctioning infrastructure nodes can generate cascading effects across ransomware affiliates, scammers and state-aligned operators simultaneously,” the report noted.

“This convergence reinforces a core dynamic of the modern cyber-threat landscape: infrastructure is the strategic center of gravity. Disrupting it raises costs across the entire ecosystem – from extortion-driven syndicates to geopolitically motivated threat actors.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMalicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens
Next Article How Exposed Endpoints Increase Risk Across LLM Infrastructure
Team-CWD
  • Website

Related Posts

News

AI and Deepfakes Supercharge Sophisticated Cyber-Attacks: Cloudflare

March 3, 2026
News

Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb

March 3, 2026
News

RedAlert Spyware Campaign Exploits Wartime Panic With Trojanized App

March 3, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

Your information is on the dark web. What happens next?

January 13, 2026

What parents should know to protect their children from doxxing

November 28, 2025

Watch out for SVG files booby-trapped with malware

September 22, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.