The ransomware economy is shrinking at the top and thickening in the middle. On-chain payments to ransomware operators fell to roughly $820 million in 2025, down about 8% from $892 million in 2024, according to Chainalysis. Over the same period the number of attacks claimed on leak sites rose by about 50% — meaning far more victims, and a far smaller share of them paying.
That divergence is the defining feature of the 2026 picture. Extortion volume is up, the proportion of victims who hand over money is at or near record lows, and the payments that do happen have become larger and more erratic.
The money: down in total, up per victim
Chainalysis’s 2026 Crypto Crime Report puts the 2025 median ransom payment at $59,556, against $12,738 in 2024 — a 368% increase. The firm estimates the share of claimed attacks that ended in a payment may have reached an all-time low of about 28%, derived by setting the $820 million in traced payments against the sharp rise in claimed victims. Chainalysis cautions that the 2025 total will likely climb as further wallet attributions are made.
Corsin Camichel, founder of the threat-tracking service eCrime.ch, told Chainalysis that the shift is structural: “We’re seeing a structural shift in targeting: fewer large, headline-grabbing intrusions and more volume focused on small and medium enterprises.”
Incident response firm Arete added a caveat that anyone reading leak-site counts should hold onto — that some groups inflate their numbers. “This year, we saw several groups reposting old victims or posting victims from other groups’ data leak sites, which skewed data leak site posting rates,” the firm said.
Coveware’s second quarter: a record low payment rate
Coveware, now part of Veeam, publishes quarterly figures drawn from its own negotiation caseload. Its Q2 2026 report recorded an average payment of $1,880,612 — a 176% jump on the first quarter — alongside a median of $150,000, down 50%. The firm attributes the gap between the two to a handful of unusually large, “lumpy” payments concentrated in data-theft cases rather than encryption events.
The headline finding is the payment rate. Coveware said the share of victims choosing to pay fell to a new record low during the quarter, with the rate for exfiltration-only extortion — no encryption, just a threat to publish — dropping to 15%. Its explanation is that buyers have stopped believing the product works: “Victims of cyber extortion are becoming increasingly sensitive to the potential volatility of outcomes that may occur post-payment,” the firm wrote, citing cases where actors kept stolen data after being paid, or where a second criminal group turned up with the same files.
The caseload skews mid-market. Organizations with 11 to 10,000 employees made up 75.8% of cases, with the 101–1,000 band the largest single segment at 35.4%. Median victim size was 750 employees. By attack vector, phishing and social engineering led the quarter, followed by remote access compromise, with compromised credentials rising as a standalone route in and vulnerability exploitation declining.
The most active groups Coveware handled in Q2 2026 were, by share of cases: unaffiliated “lone wolf” actors at 17%, ShinyHunters at 12%, Akira at 9%, The Gentlemen at 8%, and DragonForce at 4%.
Indictments and infrastructure takedowns
Law enforcement has largely stopped chasing brands and started chasing the plumbing. On July 14, 2026, the Justice Department indicted three Russian nationals — Alexander Alexandrovich Volosovik, 43, Kirill Andreevich Zatolokin, 34, and Yulia Vladimirovna Pankova, 29, all of St. Petersburg — along with two companies, Medialand LLC and ML.Cloud LLC, over a “bulletproof hosting” operation prosecutors say underpinned ransomware, malware distribution and phishing campaigns. The indictment cites more than $62 million in victim losses across 21 states.
“Their actions put the American public at risk. We will continue to dismantle these networks,” Assistant Attorney General A. Tysen Duva said. FBI Cyber Division Assistant Director Brett Leatherman said Media Land had “enabled malicious activity causing tens of millions in losses and impacting victims across 21 states.”
Other recent actions follow the same logic. In December 2025 prosecutors in the Eastern District of Michigan moved against E-Note, a money-laundering platform alleged to have washed more than $70 million in ransomware and account-takeover proceeds since 2017, indicting Russian national Mykhalio Petrovich Chudnovets. Chainalysis also notes 2025 OFAC sanctions against the bulletproof hosting provider AEZA Group and against Zservers, a provider linked to LockBit.
Prosecutions of individuals continue in parallel. In May 2026, TechCrunch reported that Latvian national Deniss Zolotarjovs was sentenced to more than eight years for his role in the Karakurt extortion group, which the Justice Department said targeted more than 54 companies and collected at least $15 million.
The regulatory turn: making payment the harder option
The most consequential policy development is British. On February 12, 2026, the UK government published its response to the ransomware consultation, setting out three measures, summarized by law firm Goodwin:
- A targeted payment ban covering public sector bodies and critical national infrastructure operators. 72% of consultation respondents supported it.
- A payment prevention regime requiring victims outside the ban’s scope to notify authorities before paying, so government can assess the proposed payment and discuss alternatives. 47% backed economy-wide mandatory reporting.
- Mandatory incident reporting regardless of whether a payment is contemplated, backed by 63% of respondents, with a 72-hour initial reporting window under consideration.
None of the three is law yet; the government said scope, thresholds and penalties need further work. But the direction of travel is clear enough that cyber insurers have begun modeling it, since a ban would remove ransom reimbursement as an option for a defined class of insureds while leaving recovery, business interruption and incident response costs — the larger part of most claims — untouched.
What this means operationally
Verizon’s 2026 Data Breach Investigations Report, published May 19, 2026, found 48% of breaches now involve ransomware even as payouts shrink — a reminder that a falling payment rate is not a falling attack rate.
The practical reading of the 2026 data is that the mid-market is the target set, social engineering and stolen credentials are the way in, and the negotiating leverage of exfiltration-only extortion is eroding because victims have watched enough post-payment outcomes go badly. That argues for spending on identity controls, tested offline backups, and a rehearsed decision process for whether to pay — one that anticipates a legal regime in which the answer may not be the company’s alone.
Sources
- Crypto Ransomware: 2026 Crypto Crime Report — Chainalysis
- Cyber Extortion Payment Trends Q2 2026 — Coveware by Veeam
- Three Russian Nationals and Two Companies Indicted — U.S. Department of Justice
- The UK’s Ransomware Strategy — Goodwin
- DOJ says ransomware gang tapped into Russian government databases — TechCrunch
- 2026 Data Breach Investigations Report — Verizon Business

