Ransomware: the economics behind the incident
Most ransomware coverage reports the demand. The demand is the least informative number in the whole incident, and it is the only one the attacker chooses.
At a glance
- Share of breaches
- Ransomware appeared in 48% of breaches in the 2026 Verizon DBIR, up from 44%
- Victims who pay
- 69% paid nothing (Verizon DBIR 2026); Coveware measured a 20% payment rate in Q4 2025
- Median payment
- About 139,875 USD (Verizon DBIR 2026)
- Total incident cost
- Around 5.13m USD on average, whether or not a ransom was paid (IBM)
What the word actually covers
Ransomware started as encryption: files locked, key sold. That model is now the minority of the business. The dominant pattern is extortion built on exfiltration - the data is copied out, and the threat is publication rather than denial of access. Many incidents involve no encryption at all, which matters because a company with perfect backups is fully protected against the old model and not at all against the new one.
The economics changed with it. Encryption-only extortion is a bet that restoring from backup is more expensive than paying. Exfiltration extortion is a bet on regulatory exposure, customer contracts and reputation, none of which a backup addresses. That is why payment rates have fallen for years while individual demands have risen: the population that pays has narrowed to those with something specific to lose.
The structure behind it is industrial rather than artisanal. Access brokers sell entry, affiliates run the intrusion using tooling licensed from an operator, and the operator takes a cut and runs the leak site. Nobody in that chain needs to be able to write the malware, which is why the supply of incidents is far more elastic than the supply of skilled attackers.
A backup defeats encryption and does nothing against publication. Most modern extortion is aimed at the second, which is why 'we have backups' stopped being an answer.
Who pays, and who does not
The headline finding of recent years is that most victims do not pay. Verizon's 2026 report found that 69 per cent of ransomware victims paid nothing at all, and Coveware measured a payment rate of around 20 per cent by the end of 2025 - the lowest levels either series has recorded. Two decades of advice not to pay finally shows up in the numbers, helped considerably by better backups, better insurance discipline and the accumulating evidence that paying does not reliably prevent publication.
The victims who still pay are not a random sample. They cluster where downtime is measured in revenue per hour, where the exfiltrated data carries regulatory weight, and where a contractual obligation to a larger customer makes silence worth buying. That selection is why the average payment keeps rising even as the payment rate falls: the marginal payer has left the population, and the remaining payers are the ones with the most at stake.
The aggregate flow has fallen with the rate. Chainalysis, tracking payments on-chain, put total ransomware receipts at roughly 820 million dollars in 2025, down about 8 per cent on the prior year and well below the peak. That is one of the few numbers in cyber security measured by observation rather than by survey, which makes it unusually reliable - and it is a floor rather than a total, since it counts only what moves through identified addresses.
- Paid nothingThe clear majority, and a share that has risen for several years
- 69%
- Paid a ransomConcentrated where downtime or data sensitivity makes silence worth buying
- 31%
Source: Verizon Data Breach Investigations Report 2026
How an incident is actually assembled
The chain is standardised enough to describe generically. Someone sells access - a credential from an infostealer log, an unpatched edge device, a session token. An affiliate uses it to move through the network, finds the data worth taking, and copies it out. Encryption, if it happens, comes last, because it is the step that announces the intrusion and ends the quiet part.
Then the negotiation begins, and it follows a script. An initial demand is set high, deliberately: it anchors the conversation and costs the attacker nothing. A leak site posting adds a deadline. Partial publication demonstrates that the data is real. Every step is designed to move the victim's estimate of publication risk, which is the only variable that determines whether a payment happens.
Verizon's 2026 report recorded a structural change at the front of this chain: exploitation of vulnerabilities overtook stolen credentials as the leading initial entry point for the first time in the report's history. That shifts where defence has to sit - patching cadence on internet-facing systems rather than password hygiene alone - and it shifts which companies are exposed, since edge devices are concentrated in exactly the mid-sized organisations least likely to patch quickly.
1Initial access
An exploited vulnerability or a stolen credential, frequently bought rather than obtained
Vulnerability exploitation now leads
2Movement and discovery
Finding the data whose publication would actually cost something
3Exfiltration
The step that creates the leverage; encryption is optional
4Demand
Anchored high, because a high anchor is free
5Leak site and deadline
Manufactured urgency plus proof the data is real
6Negotiation
Where most of the demand disappears
7Payment, or not
Roughly seven in ten victims stop here
Behind the subscription
The rest of this entry is the part that changes a decision: what moves the price, which contract sets it, who ships it and where that can be cut off.
What decides whether an incident becomes expensive
Six variables set the cost of a ransomware incident. The size of the demand is not one of them.
Where a ransomware incident carries a price
Four places this trades, including the one that prices it before it happens - and reprices it every renewal.
The negotiation arithmetic
Payments land at a fraction of what was demanded. The fraction is measured, and it is far smaller than the headlines imply.
How this shows up in prediction markets
Which ransomware questions are answerable, which are unanswerable, and how to tell before you take a side.
Included with a subscription
Create an account to unlock the full entry — price drivers, trading venues, trade flows and the live markets attached to it.
Frequently asked questions
- Do most companies pay the ransom?
- No, and the share that does keeps falling. Verizon's 2026 report found 69 per cent of victims paid nothing, and Coveware's incident data showed a payment rate near 20 per cent by the end of 2025 - the lowest in either series. Better backups, insurer discipline and the accumulating evidence that paying does not reliably stop publication all contributed.
- How much is a typical ransom payment?
- The 2026 Verizon report put the median at about 139,875 dollars, and Coveware measured a median near 150,000 dollars in the second quarter of 2026. Use the median rather than the average: a handful of very large payments from organisations with extreme downtime exposure pulls the mean far above any typical case.
- How much of the demand actually gets paid?
- Roughly 8.7 per cent on average, according to Coveware's negotiated-outcome data. The demand is an opening anchor that costs the attacker nothing to set high, so a reported demand is a poor estimate of anything. Combine the discount with the payment rate and the expected payment against a headline demand is small.
- Does having backups solve ransomware?
- It solves the encryption half. Modern extortion is built on exfiltration and the threat of publication, against which a backup does nothing at all. Backups moved the attack rather than stopping it, which is exactly why payment rates fell while individual demands rose.
- What does a ransomware incident cost in total?
- IBM's benchmarking puts the average total at around 5.13 million dollars whether or not a ransom is paid, with business interruption as the largest component. Geography matters more than most people expect: IBM's 2025 figures showed a global average breach cost of 4.44 million dollars against a US average of 10.22 million.
Primary sources
Related entries
Prediction markets carry real risk of loss. Nothing on Market Guy is financial advice — it is research tooling to help you think, not a signal to trade.