Sophos
Reports
All Statistics
51% of organizations that pay the ransom negotiate a lower amount than the initial demand.
Brute-force attacks accounted for 6% of ransomware incidents.
Compromised credentials accounted for 23% of ransomware incidents.
67% of ransomware victims confirmed their ransomware incident stemmed from an identity attack.
Human error (employees tricked into providing credentials) was cited in nearly 43% of identity incidents.
Organizations with weak NHI management pay approximately $150,000 more to recover from incidents than average.
62% of retailers who experienced attacks restored their data using backups in 2025, the lowest rate in four years
47% of retail IT/cybersecurity teams reported increased pressure after experiencing data encryption in 2025
The proportion of retailers hit by extortion-only attacks tripled from 2% in 2023 to 6% in 2025
Healthcare reported the lowest median ransom payment at $150,000.
Only 18% took more than a month to recover from a ransomware attack, down from 34% in 2024
Over half (53%) of organisations fully recovered from a ransomware attack in a week, up from 35% last year.
Compromised network edge devices account for a quarter of the initial compromises of businesses in cases that could be confirmed from telemetry.
Use of remote ransomware increased 50 percent in 2024 over last year.
Most active STAC campaigns tracked by Sophos MDR in 2024 were ransomware-related.
Ransomware cases accounted for 70 percent of Sophos Incident Response cases for small business customers in 2024.
Across ransomware attacks that begin with exploited vulnerabilities, compromised credentials, or brute force, 38% of initial compromises occur in exposed applications and systems.
Across those attacks, 21% of initial compromises occur in firewalls.
Across those attacks, 3% of initial compromises occur in IoT devices.
56% of ransomware attacks succeed in encrypting data, up from 50% the previous year.
48% of victims whose data was encrypted pay the ransom, roughly in line with a four-year average of about 50%.
79% of ransomware attacks start with an identity-based approach.
Median ransom demand is $698,000, down 65% over two years.
Malicious email (26%) and phishing (24%) together account for 50% of ransomware incidents.
Exploited vulnerabilities accounted for 18% of ransomware incidents, down 14 percentage points year-over-year.
67% of ransomware victims confirmed their ransomware incident was the same event as their most significant identity attack.
Multi-factor authentication (MFA) is missing where it matters in 59% of IR and MDR cases.
97% of victims where compromised credentials are identified as the root cause have MFA enabled in some form at the time of the attack.
Across those attacks, 30% of initial compromises occur on user devices.
Across all ransomware attacks, 48% of ransom demands are for $1 million or more.
Median ransom payment is $769,000, down from $1,000,000 the previous year.
32% of retail organizations paid the ransom, the lowest payment rate of any sector.
Backup-based recovery accounts for 66% of encrypted-data cases, up 12 percentage points from 2025.
Average recovery cost is $1.7 million per incident, up 11% year-over-year.
72% of local and state government organizations paid the ransom, the highest payment rate among sectors.
The UK records the highest median ransom demand for any country at $2.5 million.
Only 34% of small organizations (100–250 employees) stop attacks before encryption or extortion, compared with 46% of organizations with 3,001–5,000 employees.
67% of root causes across 661 incident response and managed detection and response (MDR) cases are identity-related.
Across those attacks, 8% of initial compromises occur in VPNs.
When ransomware attacks start with exploitation of a vulnerability in the firewall, 59% of those ransom demands are for $1 million or more.
Organizations with weak NHI management are 22% more likely to experience financial theft.
71% of organizations suffered at least one identity-related breach in the past year.
Organizations reported an average of three separate identity-related incidents.
10% of organizations reported an identity breach that impacted their business in the last year.
Weak non-human identity (NHI) management was cited in 41% of identity incidents.
One-third of organizations regularly rotate or audit service accounts and non-human identities, while just 11% do so continuously.
Mean recovery cost for identity-related incidents reached $1.64 million, with a median of $750,000, and 73% of affected organizations facing costs of $250,000 or more.
When identity breaches impact business, the primary consequences are data theft (49%), ransomware (48%), and financial theft (47%).
Only 24% of organizations continually monitor for unusual login attempts.
14% of breached organizations cannot detect and stop their most significant identity attack before damage is done.