Key Findings
51% of organizations that pay the ransom negotiate a lower amount than the initial demand.
Brute-force attacks accounted for 6% of ransomware incidents.
Compromised credentials accounted for 23% of ransomware incidents.
Across ransomware attacks that begin with exploited vulnerabilities, compromised credentials, or brute force, 38% of initial compromises occur in exposed applications and systems.
Across those attacks, 21% of initial compromises occur in firewalls.
Across those attacks, 3% of initial compromises occur in IoT devices.
56% of ransomware attacks succeed in encrypting data, up from 50% the previous year.
48% of victims whose data was encrypted pay the ransom, roughly in line with a four-year average of about 50%.
79% of ransomware attacks start with an identity-based approach.
Median ransom demand is $698,000, down 65% over two years.
Malicious email (26%) and phishing (24%) together account for 50% of ransomware incidents.
Exploited vulnerabilities accounted for 18% of ransomware incidents, down 14 percentage points year-over-year.
67% of ransomware victims confirmed their ransomware incident was the same event as their most significant identity attack.
Multi-factor authentication (MFA) is missing where it matters in 59% of IR and MDR cases.
97% of victims where compromised credentials are identified as the root cause have MFA enabled in some form at the time of the attack.
Across those attacks, 30% of initial compromises occur on user devices.
Across all ransomware attacks, 48% of ransom demands are for $1 million or more.
Median ransom payment is $769,000, down from $1,000,000 the previous year.
32% of retail organizations paid the ransom, the lowest payment rate of any sector.
Backup-based recovery accounts for 66% of encrypted-data cases, up 12 percentage points from 2025.
Average recovery cost is $1.7 million per incident, up 11% year-over-year.
72% of local and state government organizations paid the ransom, the highest payment rate among sectors.
The UK records the highest median ransom demand for any country at $2.5 million.
Only 34% of small organizations (100–250 employees) stop attacks before encryption or extortion, compared with 46% of organizations with 3,001–5,000 employees.
67% of root causes across 661 incident response and managed detection and response (MDR) cases are identity-related.
Across those attacks, 8% of initial compromises occur in VPNs.
When ransomware attacks start with exploitation of a vulnerability in the firewall, 59% of those ransom demands are for $1 million or more.