Home News Nearly half of organisations falling victim to ransomware encryption pay up, says report—although half of those often negotiate the payment down first
gaming Jul 22, 2026 · 👁 1 views · Syndicated from PC Gamer

Nearly half of organisations falling victim to ransomware encryption pay up, says report—although half of those often negotiate the payment down first

Cybersecurity provider Sophos has released a report entitled "The State of Ransomware 2026," pulling together responses from 2,158 survey participants, ranging from IT directors to company executives, in regards to ransomware incidents. Comparing the results to previous reports indicates that ransom demands themselves...

Nearly half of organisations falling victim to ransomware encryption pay up, says report—although half of those often negotiate the payment down first

Cybersecurity provider Sophos has released a report entitled "The State of Ransomware 2026," pulling together responses from 2,158 survey participants, ranging from IT directors to company executives, in regards to ransomware incidents.

Comparing the results to previous reports indicates that ransom demands themselves are actually decreasing—although 48% of organisations whose data was encrypted paid their attackers.

The median ransom payment is now said to be $769,000, down from a neat $1 million from the previous year's study, with the median demand dropping to $698,000. Interestingly, 51% of organisations that paid a ransom coughed up less than the demanded amount, which the report says is due to victims "often [being] successful in negotiating a lower amount than originally demanded."

Together, malicious emails and phishing are said to account for half of all reported incidents, with exploited vulnerabilities dropping 14% year-over-year. Sophos notes that "patching alone will not close the gap," and recommends that businesses invest in advanced email protection, user awareness training, and similar methods to prevent future attacks.

79% of recorded attacks started with an identity-based approach, essentially relying on stolen (or user-provided) access credentials to initiate a breach. However, Sophos notes that when ransomware attacks start with a firewall vulnerability, 59% of those demands are for $1 million or more.

(Image credit: Westend61)

In terms of which sectors paid up, the lowest category was retail, with a 32% payment rate. However, according to Sophos' data, 72% of local and state government organisations surveyed bit the bullet after falling victim to ransomware, and duly paid at least some of the demands.

It's a bit of a rollercoaster of a report. On the one hand, median ransom demands and payments going down is definitely a good thing, along with backup-based recovery rates jumping to 66% in terms of encrypted data cases, up 12% from the previous year.

On the other, 56% of attacks succeeded in encrypting data, up 11% YOY. The average recovery cost has jumped to $1.7 million, another 11% increase. And a mere 34% of small organisations managed to stop attacks before encryption or extortion, compared to 46% of large organisations with between 3,001 and 5,000 employees.

In essence, a ransomware incident is often pretty devastating for organisations large and small, and it's your user credentials where attackers are gaining ground. Keep an eye on those emails, folks. Who exactly is HackerMan69, anyway?

Read full story at PC Gamer →

Original reporting appears on the publisher’s site.

Open original article →
Related Articles
mobile

Devolver has rereleased former Netflix exclusive Poinpy for free

gaming

Ocarina of Time on Switch 2 May Be the One Game GTA 6 Can't Touch

gaming

Nvidia says DLSS 5 is a "new level of realism" and not "AI replacing graphics"