Ransomware Payout: The Reality Check

Sophos says 29 percent of victims paid in 2024, down from 46 percent in 2022. Coveware says the average payment in early 2026 is around 200,000 dollars. The story is not the headline number, it is what is sitting underneath…

A single brass briefcase with a brass price tag on dark wood, dim warm amber side light, deep navy shadows, no people, no logos.

The ransom payment in 2026 is a smaller number than it was two years ago, and a smaller number than the press releases would have you believe; the story, as usual, is in the second paragraph. Sophos put the proportion of victims who actually paid at 29 percent in its 2024 State of Ransomware report, down from 46 percent in 2022, and Coveware’s quarterly figures have the average payment hovering around 200,000 dollars in early 2026, well off the 2021 peak. The number you should care about is not the ransom. It stands as the recovery cost, the negotiation length, and the regulatory question that comes with the act of paying at all.

Editorial chart showing global ransomware payment rate trend from 2022 to 2026 projected, with negotiation outcomes broken down by year: 2022 high at 80 to 90 percent payment rate, 2024 low at 30 to 40 percent, 2026 mid projected at 50 to 60 percent. Dark navy background with cyan and red bars.
Payment rate stands as the headline; the breakdown stands as the actual story. Source: Sophos State of Ransomware 2024, Coveware quarterly research, Arete incident data.

What the payment rate actually looks like

There is a useful distinction between “paid the ransom” and “paid the full demand,” and most of the noise in the press comes from conflating the two. The Sophos 2024 figure of 29 percent runs as the share of victims who paid anything at all, including partial payments negotiated down; the older 2022 figure of 46 percent becomes the same measurement taken two years earlier, and the gap between the two is mostly explained by better backups, worse decryptors, and a sharp drop in confidence that the threat actor will actually hand over a working key. Coveware’s quarterly data, which tracks individual incident outcomes rather than survey responses, puts the average payment in the low to mid six figures for most of 2024 and the first half of 2025, with a modest uptick in late 2025 driven by a handful of large game hunting operations against mid market manufacturing and legal targets. The chart above captures the shape: the headline number has come down, the share of victims who refuse entirely has gone up, and the share who pay something reduced has quietly become the largest single category.

What has not changed becomes the median ransom demand. Threat actors are still opening with seven figure asks on most enterprise incidents, and a non trivial number of those asks are calibrated to the victim’s cyber insurance coverage limit, which is a problem we will get to in a moment. The thing that has changed is how many of those opening asks actually get met, and the answer is fewer, slower, and usually for less money than the threat actor wanted.

What the negotiation actually looks like

Anyone who has been through a real ransomware negotiation will tell you the same thing: it is dull. The threat actor opens high, the firm (Coveware, Arete, Unit 42, or one of a dozen regional boutiques) replies low, and the back and forth runs for somewhere between three and fourteen days with most of the work happening in shared chat windows at strange hours. Coveware’s published averages put the typical reduction from initial demand at around 70 to 80 percent, which lines up with Arete’s incident data and what the larger incident response firms describe off the record. The “you have 72 hours before we leak” countdown is theatre; the actual deadline is usually when the negotiator runs out of useful pretexts to keep talking.

Three things matter during negotiation that are not obvious from the outside. First, proof of life: the threat actor has to demonstrate that they can actually decrypt a sample of the data, and the firm will push for that early because everything else depends on it. Second, the legal review: any payment above the OFAC threshold requires a sanctions check before the wire goes out, and the check itself is not optional, no matter how urgent the situation feels at 2am. Third, the insurance carrier: if there is a policy in play, the carrier has to consent to the payment in writing, the consent is conditional on the OFAC check clearing, and the consent usually takes longer than the negotiation does. Anyone who tells you the negotiation serves as the bottleneck is selling you something.

What recovery actually costs

This counts as the part nobody puts in the press release. Sophos 2024 puts the median recovery cost (excluding any ransom) at 2.73 million dollars, with the upper quartile north of 5 million; IBM’s Cost of a Data Breach 2024 lands the broader average at 4.88 million across all incident types. The reason these numbers dwarf the ransom is that the actual cost is in the restoration time, the forensic work, the legal fees, the regulator notification, the customer notification, the credit monitoring, and the lost margin while the business is running on paper for three to six weeks. When Beazley talks about “ransomware as the leading driver of cyber claims by count and severity,” this runs as the figure they are talking about, not the ransom itself.

The “we have backups, we will not pay” line is true for a shrinking set of organisations, and it is more expensive than it looks. Restoration from clean backups assumes the backups themselves were not touched, that the test restore was recent, that the segment that was encrypted was actually segmentable, and that nobody clicked the second time the threat actor came back. Coveware reports that somewhere between a third and a half of victims who thought they had a clean recovery path ended up paying something, because the second variable to fail was usually the test restore, not the backup itself. Treat the recovery claim as a probability, not a binary; budget accordingly.

What the prohibition landscape looks like

Paying a sanctioned threat actor is a federal offence in the United States under OFAC’s 2020 and subsequent advisories, and the Treasury has been notably willing to enforce it. In the United Kingdom, the Office of Financial Sanctions Implementation takes a similar line under the Russia and Belarus regimes, and a payment to a designated group can trigger a control notice even when the payer had no way of knowing the designation was in force. The CISA #StopRansomware guidance, last refreshed in 2024, is explicit: do not pay, contact CISA, contact the FBI, contact the relevant sector coordinator, and treat the payment as a last resort that may not be legal. The “may not be legal” part stands as the bit the insurance brokers tend to skip over in the renewal conversation.

The practical effect of all of this is that the OFAC check is no longer a compliance nicety. It becomes the gate. Any negotiation firm worth using will run the check before the first counter offer; any insurance carrier worth using will refuse to consent to payment without the check; and any general counsel worth their salary will not let the wire leave the building without a paper trail showing the check was done. If your incident response runbook does not list who runs the OFAC check and how long it takes, fix that before you fix anything else.

What the right way to think about it looks like

The honest framework for a board or a leadership team is roughly this, in order. Verify the backups, with a real test restore, not a screenshot. Get the threat intel: who stands as the actor, what is their pattern, have they actually decrypted for anyone recently. Loop in counsel before you loop in the carrier, because the legal privilege on the negotiation is more useful if it is set up early. Run the OFAC check, even if the answer is obviously clear, because “we ran the check” sits as the only sentence that will hold up later. Then, and only then, decide whether to negotiate at all, and treat that decision as a governance event with a paper trail, not an operations call taken by the IT director at 3am.

The threat actor saying the decryptor works does not make it work. A polished demo is not the same thing as a working system. Sometimes the honest answer is that the only path serves as the slow one, and the only thing worth measuring is how long the slow one actually takes.

The bottom line

The ransom payment amounts to the smallest number on the incident spreadsheet, and the only one with a federal enforcement regime attached. The recovery cost, the negotiation length, the OFAC check, and the insurance carrier’s consent are the four numbers that actually move the outcome. Sophos says 29 percent of victims paid in 2024; Coveware says the average payment is around 200,000 dollars; IBM says the average total incident cost is 4.88 million; OFAC says you cannot pay a designated actor no matter what your insurance carrier says. The right way to read those four sentences together is: the headline number sits as the least interesting one.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading