At-Bay
All Statistics
The single largest fraud loss in 2025 hit $9.7M.
Claim frequency rose 7% year-over-year to the highest rate At-Bay has recorded since 2021.
Akira, a Ransomware-as-a-Service operation that has run since 2023, drove a 53% increase in ransomware frequency in the second half of 2025.
The average ransom demand was $957K, and the average ransom paid was $317K. This means the price was often negotiated down by more than half.
Ransomware attacks increased by nearly 20% in 2024.
4 of 5 (83%) financial fraud claims began with email.
Akira accounted for more than 40% of all ransomware claims in At-Bay’s portfolio for the full year.
Average claim severity climbed to an all-time high of $221K.
The average amount stolen reached $285K, up 16% from the prior year and up significantly from $199K in 2023.
86% of Akira attacks occurred in environments where a SonicWall device was present.
The largest single business interruption claim hit $5M, the policy limit.
Roughly one in 10 ransomware incidents caused downtime exceeding 30 days.
Companies with under $25M in revenue saw a 26% increase in average claim severity, the steepest jump of any segment and part of a three-year upward trend.
Akira ransom demands averaged $1.2M, which is 50% higher than the non-Akira average.
Two-thirds of Akira attacks in 2025 occurred on nights or weekends.
In 2025, one in three ransomware claims triggered business interruption coverage.
Ransomware claims that triggered business interruption coverage averaged $510K in severity, compared to $168K for ransomware claims without business interruption.
Financial fraud was the most common incident type for the third consecutive year, accounting for 30% of all claims.
Third-party liability claims jumped 70% in 2025.
The blast radius of ransomware continues to grow as businesses impacted by attacks on vendors and partners increased 43%.
The average cost of third-party ransomware incidents jumped by 72% to $241K.
VPNs alone accounted for two-thirds (66%) of all ransomware attacks.
Close to 50 ransomware groups were implicated in attacks in 2024, a 3X increase from 2021.
The vast majority of ransomware started with an attack on a remote access tool, contributing to 80% of attacks.
Mid-sized companies generating $25-100M in revenue saw a 46% increase in ransomware attacks.
Severity of ransomware attacks was up 13% in 2024.
Only 31% of ransoms were paid by At-Bay customers in 2024. This totaled $146M in unpaid ransoms.
Financial fraud remained the most common incident type, accounting for 32% of all claims.
Overall claims frequency increased by 16% in 2024.
Remote access tools like VPNs and RDP were correlated with 80% of ransomware attacks in 2024, up from 63% the year prior.
Supply chain-driven cyber claims were up 43%.
The frequency of ransomware attacks in 2024 increased by 19% vs. 2023.
Email was the preferred entry vector for cybercriminals, driving 43% of claims.