Ransomware 2026 Trends: Attacks Up, Payments at 23% Low | #ransomware | #cybercrime


Ransomware in 2026 has split into two contradictory storylines, and both are backed by hard numbers. Attack volume keeps climbing: Group-IB counted 2,393 attacks published on ransomware data leak sites across 79 active groups in the first quarter of 2026 alone, a 4.5% jump from the previous quarter, according to the firm’s “Ransomware in 2026: Same Business, New Rules” report. Yet fewer victims are opening their wallets. The result is a market where gangs are working harder for less overall cash, but squeezing far bigger checks out of the organizations that do cave.

That divergence is the story security teams, CISOs, and boards need to understand heading into the back half of 2026. Attack counts are up. Payment rates are down. And the ransom demands that do get paid have exploded in size, turning ransomware from a volume business into something closer to a targeted extraction racket aimed at the organizations least able to say no.

Google · Preferred Sources

Don’t miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

The headline numbers: more attacks, fewer payers, bigger checks

Group-IB’s data shows the leak-site ecosystem accelerating through 2026. By the second quarter, the firm recorded 2,202 victim organizations listed on leak sites, operated by 92 active ransomware groups — a 16.46% jump in active groups compared to Q1. Check Point Research, tracking a similar window, found that more than 70 active data leak sites collectively listed 2,122 new victims during Q1 2026, a figure it published in its State of Ransomware Q1 2026 report. The two firms count slightly differently, but the direction is the same: the number of gangs operating leak sites and publishing victims is growing, not shrinking.

What’s shrinking is the willingness to pay. Check Point’s Q2 2026 research found ransom payment rates falling to “a multi-year low near 23%, continuing a six-year decline from 85% in 2019,” a striking collapse in a metric that once looked unshakeable. That tracks with separate data compiled from Coveware’s incident-response caseload, which put the paid-victim rate at roughly 23% in Q3 2025 and around 20% in Q4 2025 — levels described as unprecedented lows.

Sophos tells a slightly different story from its own annual survey. Its 2026 State of Ransomware report found a median ransom payment of $769,000, with 48% of encrypted victims choosing to pay. That figure sits well above the Check Point and Coveware-derived numbers because Sophos surveys organizations that were already hit by ransomware and had data encrypted, a narrower and more severely affected slice of the market than the full universe of leak-site victims. GuidePoint Security’s GRIT team, in its 2026 Ransomware and Cyber Threat Report, pegged the average ransom payment across the two most active groups it tracked at between $366,000 and $457,000, reinforcing that payments, when they happen, now land in six-figure territory as a baseline rather than an outlier.

Why the median payment jumped 368% in a single year

The clearest illustration of the “fewer, bigger” trend comes from blockchain-tracing firm Chainalysis. Its 2026 Crypto Crime Report found that the median ransomware payment rose from $12,738 in 2024 to roughly $59,556 in 2025 — a 368% increase in a single year. That is not a story about ransomware becoming more profitable across the board. Total on-chain ransomware revenue actually fell, from a revised $892 million in 2024 to about $820 million in 2025, an 8% year-over-year decline and the second consecutive annual drop Chainalysis has recorded.

Put those two data points together and the shape of the market becomes obvious. Attackers are casting a wider net (claimed attacks rose roughly 50% in 2025, per Chainalysis) while collecting from a shrinking share of targets. The victims who still pay tend to be the ones with the least leverage: hospitals facing life-safety risk, manufacturers with idled production lines, or municipalities with no backup infrastructure. Those organizations are absorbing demands that dwarf what a mid-size retailer might have paid in 2021.

Coveware’s own Q1 2025 Marketplace Report, cited in a later 2026 statistics compilation, put the median paid ransom at roughly $200,000 for that quarter — itself a substantial figure, and one that has clearly kept climbing through the rest of the year based on the Chainalysis median. The pattern holds across every dataset in this article: fewer payments, larger individual amounts.

2026 ransomware payment and attack data at a glance

MetricFigureSource
Leak-site attacks, Q1 20262,393 across 79 groupsGroup-IB
Leak-site victims, Q2 20262,202 across 92 groupsGroup-IB
New victims listed, Q1 20262,122 across 70+ leak sitesCheck Point Research
Ransom payment rate, Q2 2026~23% (multi-year low)Check Point Research
Median ransom payment, 2025$59,556 (up 368% YoY)Chainalysis
Median ransom payment, 2026 survey$769,000Sophos
Share of encrypted victims who paid48%Sophos
Average ransom, two top groups$366,000–$457,000GuidePoint Security GRIT
Total on-chain ransomware revenue, 2025~$820 million (down 8% YoY)Chainalysis

Which groups are driving the numbers

Group-IB’s tracking identifies Qilin as the single most active ransomware operation of Q2 2026, responsible for 298 of the 2,202 published attacks that quarter — meaning one group alone accounted for roughly 13.5% of all publicly listed victims. That concentration matters: a handful of well-resourced ransomware-as-a-service operations are now generating a disproportionate share of total attack volume, while dozens of smaller or newer groups fight for the remainder.

Regional data from Group-IB’s APAC Intelligence Insights reports shows how quickly the leaderboard can shift month to month. In February 2026, a group Group-IB calls The Gentlemen was the dominant actor in the Asia-Pacific region with 29 attacks, while Qilin’s regional activity fell 37.5% compared to January. By March, The Gentlemen had grown to 36 attacks and was named the most active and dangerous group in APAC for that month, with Qilin down to just 12 incidents in the region and groups called Gunra and Payload Ransom logging eight each. The swings illustrate how ransomware-as-a-service affiliates migrate between platforms, chasing better tooling, higher payout splits, or law enforcement pressure on rival operations.

Group-IB’s broader APAC monthly tracking also shows raw incident counts can spike hard. February 2026 logged 58 incidents in the region, a 7.4% rise over January. March then jumped to 120 incidents, a 107% month-over-month surge. Numbers like that don’t move gradually; they lurch, often tied to a single group’s affiliate recruitment drive or a fresh exploited vulnerability giving multiple crews simultaneous initial access.

Who’s getting hit: sectors and countries in the crosshairs

Manufacturing remains the sector taking the heaviest and most consistent damage. Group-IB’s February 2026 APAC report found manufacturing accounted for nearly 27% of all regional incidents, the largest share of any industry. The March 2026 report confirmed the pattern, again naming manufacturing as the hardest-hit sector while noting rising pressure on energy, government, and healthcare organizations as well. Manufacturing’s appeal to attackers is structural: production lines can’t tolerate downtime, backup and segmentation practices often lag behind those of finance or tech, and many industrial control environments still run on unpatched, legacy software that’s difficult to take offline for updates.

Geographically, Group-IB’s February 2026 data lists India as the most targeted country in APAC, followed by Thailand, Australia, and Taiwan. By March, Australia and Thailand had moved into a joint top spot, followed by India, Malaysia, Taiwan, and Japan. The consistent presence of the same six or seven countries across both months suggests attackers are working from established playbooks in the region rather than opportunistically hitting whoever’s exposed that week.

Initial access: the market feeding ransomware crews

Ransomware doesn’t start with encryption. It starts with a foothold, and that foothold increasingly gets bought rather than found. Group-IB’s High-Tech Crime Trends Report 2026 documented more than 200 instances of corporate access tied to organizations in the Middle East, Turkey, and Africa (META) region being publicly advertised for sale during 2025 alone — a market that exists purely to hand ransomware affiliates a door into a target network without the reconnaissance work.

That access-broker economy shows up in the payment data too. A 2026 analysis built on Coveware and blockchain-tracing data found that initial access brokers received at least $14 million in on-chain payments during 2025, about 1.7% of total tracked ransomware payments. It’s a small slice of the overall revenue pool, but a critical one: it’s the plumbing that lets ransomware operators skip weeks of intrusion work and go straight to deployment, compressing the time between first compromise and encryption.

Supply chains and identity: the new attack surface

Group-IB’s High-Tech Crime Trends Report 2026 flags supply chain attacks as an emerging top global cyber threat, arguing that the industrialization of cybercrime has exposed the limits of perimeter-based defenses and elevated identity and trust as the primary attack surface for 2026. That framing matches what’s visible in the leak-site data: attackers are no longer just hunting for an unpatched VPN appliance. They’re going after software vendors, managed service providers, and identity infrastructure, because a single supply-chain compromise can hand them simultaneous initial access to dozens or hundreds of downstream customers.

This shift also explains why ransomware crews increasingly skip encryption altogether in favor of pure data-theft extortion. If the goal is to threaten a public leak rather than lock up file systems, an attacker doesn’t need to survive inside a network long enough to deploy encryption software across every endpoint — they just need to exfiltrate data and disappear. That’s faster, quieter, and harder for endpoint detection tools to catch in the act.

Historical context: how we got from 85% to 23%

The collapse in payment rates didn’t happen overnight. Check Point’s own historical framing puts the 2019 payment rate at roughly 85%, meaning the overwhelming majority of ransomware victims paid up at the start of the last decade’s ransomware boom. Six years of decline later, that number sits near 23%. The drivers are well understood in the industry: cyber insurers have tightened underwriting requirements and pushed clients toward better backup hygiene, law enforcement takedowns (including sanctions actions against ransomware-linked cryptocurrency exchanges) have made paying legally riskier, and public breach-disclosure rules have made it harder for companies to quietly settle and move on.

Chainalysis’s multi-year revenue tracking tells the same story from the money side. Its 2025 Crypto Crime Report preview estimated 2024 ransomware payments at roughly $813.55 million, itself a 35% decrease from 2023’s $1.25 billion. That figure was later revised upward to $892 million for 2024, and the 2025 total came in around $820 million — still a decline, just a smaller one than initially estimated. Three straight years of falling revenue, even as attack counts climb, is the clearest signal yet that the ransomware business model is under real strain.

Competitive comparison: how the major trackers differ

Anyone trying to make sense of ransomware statistics quickly runs into a problem: Group-IB, Check Point, Chainalysis, Sophos, Coveware, and GuidePoint Security all measure different things. Group-IB and Check Point track public leak-site postings, which capture attacks where a victim refused to pay (prompting the gang to publish their name) but miss quiet, unreported incidents entirely. Chainalysis tracks actual cryptocurrency flows to known ransomware wallets, giving a revenue-side view but one that can’t see off-chain or unconventional payment arrangements. Sophos and Coveware survey organizations or review incident-response caseloads directly, which captures the victim experience but skews toward customers who already engaged a security vendor.

None of these methodologies is wrong, but they answer different questions. If you want to know how many organizations got hit, look at Group-IB or Check Point’s leak-site counts. If you want to know how much money is actually moving, Chainalysis is the closest thing to ground truth. If you want to know what a real incident-response engagement costs a specific company, Sophos and Coveware’s survey data is more useful than aggregate attack counts. Treating any single number as “the” ransomware statistic for 2026 misses the point — the real picture only emerges from combining all of them.

Data source methodology comparison

SourceWhat it measuresKey 2026 metric
Group-IBPublic data leak-site postings2,393 attacks, 79 groups (Q1)
Check Point ResearchLeak-site victim counts, payment rate surveys~23% payment rate (Q2)
ChainalysisOn-chain cryptocurrency payment tracing$820M total revenue, 2025
SophosDirect victim organization surveys$769,000 median payment
CovewareIncident-response caseload analysis~20-23% victims paid (Q3-Q4 2025)
GuidePoint Security GRITThreat intelligence on active groups$366K-$457K average payment

What this means for security budgets in 2026

For CISOs and security leaders, the data points toward a specific budget conversation rather than a generic “spend more on security” message. Falling payment rates suggest that backup and recovery investment is paying off at the macro level — organizations that can restore from backups without paying are driving down the industry-wide payment rate. But rising median payments mean the organizations that still lack solid recovery capability are facing catastrophically higher bills than they would have three years ago. There’s no longer a comfortable middle ground; recovery readiness has become a binary that determines whether an incident costs a company nothing or costs it hundreds of thousands of dollars.

The manufacturing sector’s persistent overrepresentation in the incident data also points to a specific gap: operational technology (OT) and industrial control system security still lags well behind IT security maturity at most manufacturers. Group-IB’s repeated finding that manufacturing accounts for roughly a quarter of regional incidents, month after month, isn’t a coincidence — it reflects real, unaddressed exposure in production environments that boards have been slow to fund.

Predictions for the rest of 2026 and into 2027

Based on the trajectory in this data, several trends look likely to continue through the rest of 2026 and into 2027.

  • Payment rates keep falling, but slower. The drop from 85% to roughly 23% over six years has been dramatic, but it’s approaching a floor — some share of victims (those without any viable recovery option) will likely always pay, keeping the rate from collapsing to near-zero.
  • Median payments continue rising. As the pool of paying victims narrows to the most desperate and least-prepared organizations, expect the median payment figure to keep climbing well past the $59,556 Chainalysis recorded for 2025.
  • Leak-site group churn accelerates. The swings seen in Group-IB’s APAC data, where a group like The Gentlemen can jump from a minor player to the region’s top threat within a month, suggest affiliate migration between ransomware-as-a-service platforms will keep intensifying as law enforcement disrupts individual brands.
  • Supply-chain and identity-focused attacks grow as a share of total incidents. Group-IB’s framing of identity and trust as the new primary attack surface points toward more incidents that start with a compromised vendor, SaaS platform, or credential broker rather than a direct network intrusion.
  • Manufacturing and critical infrastructure remain the top targets. Without a broad, funded push to modernize OT security, expect manufacturing to keep showing up as the most-targeted sector in quarterly reports through 2027.

Market impact: insurance, disclosure, and the cost of a breach

The shift toward fewer but larger payments is already reshaping the cyber insurance market. Insurers that once treated ransomware as a broad, predictable risk pool now underwrite much more selectively, often requiring proof of offline backups, multi-factor authentication, and endpoint detection tooling before issuing or renewing a policy. That underwriting pressure is itself a contributor to the falling payment rate documented by Check Point and Coveware: insurers are effectively forcing their policyholders into the recovery readiness that lets them refuse to pay.

At the same time, the size of payments among victims who do pay is pushing up the ceiling on cyber insurance claims. A median payment of $769,000 in Sophos’s survey, or an average of $366,000 to $457,000 per GuidePoint’s tracking of top groups, represents a real jump in claim severity even if claim frequency (measured by payment rate) is falling. Insurers and reinsurers price for both frequency and severity, and a market where severity is climbing while frequency falls is a genuinely difficult one to model — which is part of why cyber insurance premiums have remained stubbornly high industry-wide even as headline attack-prevention metrics improve.

What defenders should actually do with this data

The practical takeaway from six separate 2026 datasets converging on the same conclusion is straightforward, even if executing on it isn’t. Offline, tested backups remain the single highest-leverage investment against ransomware, because they’re the mechanism directly responsible for driving the payment rate down from 85% to 23% over six years. Segmentation matters more than ever given the concentration of attacks in manufacturing and OT environments, where a compromised office network shouldn’t be able to reach production systems. And given that initial access brokers are actively selling footholds into corporate networks — Group-IB documented over 200 such listings for the META region alone in 2025 — credential hygiene and monitoring for compromised-access sales on criminal marketplaces both belong on a 2026 security roadmap, not just traditional perimeter defense.

Organizations should also treat the manufacturing and critical-infrastructure targeting pattern as a planning input rather than background noise. If a company sits in one of the sectors Group-IB has repeatedly flagged as overrepresented in its incident data, board-level risk conversations should reflect that elevated baseline probability rather than treating ransomware as a generic, sector-agnostic threat.

Frequently asked questions

How many ransomware attacks happened in 2026 so far?
Group-IB recorded 2,393 attacks published on leak sites across 79 active groups in Q1 2026, rising to 2,202 victims across 92 groups by Q2 2026, according to the firm’s research.

What is the average ransomware payment in 2026?
Figures vary by methodology. Sophos found a median payment of $769,000 among surveyed victims who paid, while GuidePoint Security’s GRIT team put the average at $366,000 to $457,000 across the two most active groups it tracked. Chainalysis found the broader median payment across all on-chain ransomware transactions was $59,556 in 2025.

Is ransomware getting worse or better in 2026?
Both, depending on the metric. Attack and leak-site posting volume is rising, per Group-IB and Check Point Research. But total on-chain ransomware revenue fell to roughly $820 million in 2025, an 8% year-over-year decline, according to Chainalysis, and the share of victims who pay has fallen to a multi-year low near 23%, per Check Point.

Which ransomware group is most active in 2026?
Group-IB named Qilin the most active ransomware group globally in Q2 2026, responsible for 298 of 2,202 total published attacks that quarter. Regionally in Asia-Pacific, a group Group-IB calls The Gentlemen took the top spot in February and March 2026.

Which industries are most targeted by ransomware in 2026?
Manufacturing is the most consistently targeted sector, accounting for nearly 27% of regional incidents in Group-IB’s February 2026 APAC report and remaining the top sector in its March 2026 report. Energy, government, and healthcare also show rising incident counts.

Why did the median ransom payment jump 368% in one year?
Chainalysis attributes the rise from $12,738 in 2024 to about $59,556 in 2025 to a shrinking pool of paying victims. As more organizations refuse to pay thanks to better backups and insurance requirements, the remaining payers tend to be those with the least leverage, facing larger demands.

What role do initial access brokers play in ransomware attacks?
Initial access brokers sell compromised corporate network access to ransomware affiliates, letting them skip the reconnaissance and intrusion phase. Group-IB documented more than 200 such access listings tied to the META region in 2025, and a 2026 analysis found brokers received at least $14 million in on-chain payments that year.

Should companies pay a ransomware demand?
Industry data doesn’t answer this in absolute terms, but the trend is clear: payment rates have fallen from roughly 85% in 2019 to about 23% in Q2 2026, per Check Point Research, largely because organizations with tested offline backups have a viable alternative to paying.

Related Coverage

Marcus Chen

Gaming & Consumer Tech Editor

Marcus Chen is a senior editor at Tech Insider, where he leads coverage of the US online gaming market, including sweepstakes and social casinos, alongside consumer technology. He evaluates operators on their published terms, licensing and RNG certifications, stated redemption policies, and corroborating independent reporting, and writes plainly about what the evidence supports. Tech Insider does not run first-party money tests and does not gamble with reader funds. Marcus has reported on the technology and online-gaming industries for more than a decade.

View all articles



Click Here For The Original Source.

——————————————————–

..........

.

.