Ransomware Statistics
Ransomware by Industry
Latest Statistics
Cloud-related threats (40%), third-party breaches (34%), and ransomware (33%) rank after AI as major preparedness gaps.
49% of organizations that experienced or suspected a deepfake attack also experience follow-on cyberattacks such as ransomware.
Ransomware attacks on manufacturers have more than doubled since 2023.
The average manufacturing or distribution ransomware victim scores 0.552 on the RSI.
In the first half of 2026, ransomware attacks on manufacturers increased nearly 40% year over year.
83% of organizations fell victim to a successful ransomware attack in the last 24 months, up from 66% in 2024.
Of organizations hit by ransomware, 75% experience multiple service interruptions.
83% of technology leaders view backup storage as the last line of defense against ransomware.
Twelve vulnerabilities carry confirmed "multi-nexus" attribution, being independently exploited across five distinct threat categories (China, Russia, DPRK, Iran-nexus, and criminal actors).
More than half of mid-market ransomware victims generate less than $50M in annual revenue.
Mid-market organizations accounted for approximately 72–75% of ransomware victims each year.
Compromised credentials accounted for 67% of ransomware intrusions investigated by Beazley Security, down from 74% in Q1.
Public ransomware leak-site postings totaled 2,268, remaining nearly 60% above Q2 2025.
73% of ransomware attacks in North America and Europe hit companies with $10M to $1B in annual revenue from 2023 through the first half of 2026.
27% of healthcare organizations cite cybersecurity threats and ransomware as the #1 network challenge, 23% cite staffing shortages and lack of expertise, 20% cite rising operational and compliance costs, 16% cite network reliability impacting clinical systems, and 15% cite aging or fragmented infrastructure.
Professional services recorded 69.9 million ransomware hits in the first half of 2026, more than any other vertical.
Ten active ransomware families operated simultaneously against the professional services sector in the first half of 2026, including Filecoder (19.1 million hits across 113 organizations), Gandcrab (11.9 million) and Ryuk (10.5 million).
460 organizations in the professional services sector are actively detecting ransomware campaigns, representing the broadest exposure of any vertical.
Ransomware remained the most persistent and disruptive cyber threat to industrial organizations in Q2 2026
Manufacturing was the most affected sector by ransomware incidents affecting industrial organizations worldwide, with 747 incidents (65%) across all subsectors in Q2 2026.
Transportation and logistics was the third-most-impacted sector by ransomware incidents affecting industrial organizations worldwide, with 95 incidents in Q2 2026.
7% of reported cybercrime cases in Africa in 2025 involved ransomware or Banking Trojan stealers.
57 ransomware variants were associated with disclosed attacks in Q2 2026, a 21% increase from Q1 2026.
Healthcare accounted for 81 disclosed ransomware attacks (26%) in Q2 2026, making it the most targeted sector.
The average volume of data stolen per undisclosed ransomware incident reached 508 GB in Q2 2026.
41% of ransomware attacks exploited brand reputation.
35% of ransomware attacks exploited employee data.
31% of ransomware attacks exploited intellectual property.
Ransomware incidents made up over 20% of Cisco Talos Incident Response engagements this quarter, similar to just under 20% last quarter.
Threat actors maintained undetected access for approximately three days before ransomware deployment in the observed Sinobi engagement.
PEAR was responsible for 35 claims in H2 2026, nearly triple the 13 posted the quarter before.
Q2 2026 recorded 1,988 ransomware attack claims from 89 groups across 101 countries.
The US accounted for 42.5% of ransomware claims, Canada for 5% and Germany for 4.8%.
Brazil recorded 8 ransomware attacks (a 33% increase) and Thailand recorded 5 attacks (a 150% increase) on the education sector in H1 2026.
34 of 104 attacks (33%) in H1 2026 targeted educational institutions in the US, a 44% decline from 61 attacks in H2 2025.
Attacks on K-12 decreased 26% from H2 2025 to H1 2026.
48% of organizations in Singapore report user interaction as the reason ransomware bypassed controls.
65% of global organizations affected by ransomware say AI increased the effectiveness of the attack.
Ten ransomware families were active against manufacturing networks in H1 2026.
28% of global organizations that experienced a ransomware attack report that AI significantly increases the attack's effectiveness.