Nearly half of organizations experiencing ransomware encryption have paid their attackers, according to a new report by cybersecurity provider Sophos. The "State of Ransomware 2026" report, which surveyed 2,158 IT professionals and executives, indicates a complex landscape where ransom demands are decreasing, but the success rate of encryption and subsequent recovery costs are rising.
The median ransom payment has fallen to $769,000 from $1 million in the previous year, with median demands also dropping to $698,000. Notably, over half of organizations that paid a ransom were successful in negotiating a lower amount than originally demanded. However, the overall success rate of ransomware attacks in encrypting data has increased by 11% year-over-year, with 56% of attacks now achieving this goal.
Identity-based attacks, often leveraging stolen or user-provided access credentials, were the starting point for 79% of recorded attacks. Conversely, attacks initiated by exploiting firewall vulnerabilities, while less common, resulted in higher ransom demands, with 59% of these demanding $1 million or more. Malicious emails and phishing remain significant threats, accounting for half of all reported incidents.
Varying Sector Impacts and Recovery Costs
The impact of these attacks varies by sector. Retail organizations reported the lowest payment rate at 32%, while local and state government organizations saw a higher rate, with 72% paying at least some of the ransom. The average cost to recover from a ransomware incident has surged by 11% to $1.7 million. Smaller organizations appear to be more vulnerable, with only 34% managing to prevent attacks before encryption or extortion, compared to 46% of larger organizations.
Despite these challenges, there are some positive trends. Backup-based recovery rates have improved, with 66% of encrypted data being recovered, an increase of 12% from the previous year. However, the report stresses that patching vulnerabilities alone is insufficient to combat the threat. Sophos recommends increased investment in advanced email protection, user awareness training, and other preventative measures to mitigate future attacks.