Report by Sophos

State of Ransomware in Retail

8 FINDINGSPublished Nov 4, 2025
View Original Report →

Key Findings

62% of retailers who experienced attacks restored their data using backups in 2025, the lowest rate in four years

SophosState of Ransomware in Retail·Nov 4, 2025
RansomwareEncrypted dataBackupData restorationRetail

47% of retail IT/cybersecurity teams reported increased pressure after experiencing data encryption in 2025

SophosState of Ransomware in Retail·Nov 4, 2025
RansomwareData encryptionRetail

The median ransom demand for retail ransomware attacks doubled to $2 million in 2025 compared to 2024

SophosState of Ransomware in Retail·Nov 4, 2025
RansomwareRansom Retail

The average cost of recovering from a ransomware attack in retail, excluding any ransom payment, dropped by 40% to $1.65 million in 2025, the lowest point in three years

SophosState of Ransomware in Retail·Nov 4, 2025
RansomwareRansom Retail

The proportion of retailers hit by extortion-only attacks tripled from 2% in 2023 to 6% in 2025

SophosState of Ransomware in Retail·Nov 4, 2025
RansomwareExtortion-only attackRetail

58% of retail organizations with encrypted data paid the ransom in 2025, marking the second highest payment rate in five years

SophosState of Ransomware in Retail·Nov 4, 2025
RansomwareEncrypted dataRansomRetail

26% of cases in retail saw leadership teams replaced as a result of data encryption in 2025

SophosState of Ransomware in Retail·Nov 4, 2025
RansomwareLeadershipRetail

46% of retail ransomware incidents were traced to an unknown security gap in 2025

SophosState of Ransomware in Retail·Nov 4, 2025
RansomwareSecurity gapRetail