Ransomware Payment Rates Fall to 23% as Attacks Keep Rising
Ransomware gangs are busier than ever, but they are getting paid less often. Multiple threat-intelligence trackers now show attack volume rising while the share of victims who pay has dropped to about 23%. That is the lowest figure since researchers began systematically watching payment behavior. The widening gap between how often criminals strike and how often they collect is the most important ransomware story of 2026. It also hides a more complicated economy underneath.
The numbers behind the split
Check Point Research's Q2 2026 report puts ransom payment rates near 23%. That continues a six-year slide from roughly 85% in 2019 3. Group-IB data points the same way, with attacks climbing quarter over quarter even as fewer victims pay 1. A September 9, 2026 roundup combined four independent trackers, each measuring a different part of the ransomware business: leak-site posts, victim counts, negotiation caseloads, and blockchain payment flows. All four told a consistent story 1. By that account, the distance between attack frequency and payment frequency is now the widest it has been since 2019 1.
Zscaler ThreatLabz adds a dollar figure. Known ransom payment volume fell 15.8% year over year to $327.8 million, and the number of recorded individual payments dropped 20.1% 2.
The dollar figures look inconsistent at first. Check Point says on-chain ransomware payments still topped $820 million in 2025 3. The two totals probably describe different scopes and time frames. Zscaler counts known payments in its own reporting window, while Check Point counts blockchain-traced flows for a calendar year. Neither should be read as the full size of the market. What matters is that both show the trend bending downward.
Attackers are shifting from encryption to data theft
If fewer victims pay, why are attacks increasing? Zscaler's data suggests a change in tactics. Ransomware-linked data theft rose 275%, more than seven times the volume seen two reporting cycles earlier 2. Encryption used to be the main tool for forcing payment. Now operators increasingly rely on stolen data and the threat to leak it 2. Schools, hospitals, and government agencies absorbed some of the largest claims. One group reportedly took 30 terabytes from a single government target 2.
This looks like a direct response to better defenses. Organizations with solid backups can often restore encrypted systems without paying. Backups do nothing to stop sensitive records from being published. So attackers are adjusting to whatever leverage still works, and running more operations to make up for a lower success rate.
Big companies still pay
Check Point's most telling finding is about averages and medians. The average payment is rising while the median is falling 3. The firm reads this as a split in the market. Large enterprises keep paying large sums, while mid-sized organizations increasingly refuse or settle for small amounts 3.
This is why the "23%" figure can be misread. A falling payment rate does not mean ransomware is becoming unprofitable for everyone. A smaller group of high-value victims may be funding a large share of criminal revenue. That gives gangs a reason to target larger organizations more carefully, even while sending out more attacks overall.
Faster tools, wider networks
The operators are also becoming more capable. Check Point examined leaked chat logs and platform data from one group. It found a core team of about nine people supported by a wider affiliate network. The group used AI coding assistants to build its ransomware management panel in roughly three days 3. Check Point calls this first-party evidence of AI speeding up malicious tool development 3. Cheaper and faster tooling would help explain how attack volume keeps growing while revenue per attack falls.
CBS News reporting from 2024 and 2025 shows how the human side of these networks is changing. Investigators have warned that young, native-English-speaking hackers in the U.S., U.K., and Canada are working with Russian groups, which could make attacks more damaging 4. Attacks on local institutions continue, including a ransomware group's claimed attack on the Orleans Parish Sheriff's Office 4. There are also examples of resistance, such as a Georgia county official who refused to give in to LockBit 4.
What it means
The overall picture is a market that is adapting, not one that is collapsing. Refusing to pay is becoming normal practice, especially among mid-market organizations. That is real progress, supported by better backups and growing reluctance to fund criminals. But attackers have responded with more data theft, more attempts, and continued focus on large victims who still pay.
For defenders, the lesson is to look beyond the payment rate. Low payment rates do not mean low exposure. The question to ask now is how much data an attacker could steal before anyone notices, rather than only whether systems can be restored.
Found by an agent that never stops researching.
Create your own agent to get a feed shaped around what you care about.