Skip to content
The Cyber Security Place

Threats

Ransomware in 2026: how attacks start, what they cost, and what reduces the damage

The name has outlived the mechanism. What began as a business built on encryption is now a business built on copying data and threatening to publish it, and the defences that answered the first problem do not answer the second.

Last reviewed August 25, 2026

Ransomware in 2026 is extortion built on stolen data rather than locked files. Roughly four in five intrusions now begin with a working login rather than a software flaw, and exploiting a known vulnerability has fallen to under a fifth of cases. Around a third of incidents involve no encryption at all — theft and a publication threat — up from under a fifth a year earlier. Median payments sit near six figures while averages are pulled past$2m by large targets, and 64% of victims now refuse to pay. Total incident costs average about $5m. Just over half recover inside aweek; the mean stretches to roughly three weeks, and recovery spending excluding any ransom has fallen from about $2.5m to a little over$1.5m in a year.

What counts as ransomware in 2026?

The working definition has drifted a long way from the one most policies were written against. For a decade the word described a specific mechanism: software encrypts files, a note demands payment, a key is sold back. Everything defenders built — the backup regime, the recovery runbook, the tabletop exercise — answered that mechanism.

What organisations face now is a negotiation about publication. Attackers copy the data out first. Encryption, if it happens at all, is added pressure rather than the source of it. The share of incidents with no encryption whatsoever has roughly doubled in a year, and the share involving data theft in some form covers more than three-quarters of intrusions.

That distinction is not academic, and it decides where money should go. An organisation that has rehearsed restoring from backup has solved the older problem completely and the newer one not at all. Restoring in four hours instead of four days is a genuine achievement that changes nothing about a threat to publish payroll records next Tuesday.

A useful test for any control you are about to fund: does it reduce the time the business is down, or does it reduce the chance that data leaves? Both are worth buying. Confusing one for the other is how budgets get spent on the problem that was already handled.

Where the pressure comes from

Three years of incidents, split by how the extortion is applied. The bars are not showing volume — they show what proportion of attacks used each approach, and the direction of travel is the whole story.

202362%20%18%202523%59%18%202612%53%35%Encryption onlyEncryption + theftTheft onlyshare of incidents by extortion method
Proportions rounded from published incident-response research. Categories overlap in the source data, so the bars describe the dominant method rather than a strict partition.

How does the attacker actually get in?

With a login that works. Roughly four intrusions in five now trace back to valid credentials rather than to an exploited flaw, and the share starting with a known vulnerability has fallen by nearly half in a single year. The shift matters because the two routes call for entirely different defences, and most programmes are still weighted toward the one that is shrinking.

Remote access is where those credentials get used. Where responders could establish an entry point, VPN compromise accounted for the clear majority — a share that has roughly doubled since 2023. Exposed applications, remote device logins and firewall management interfaces make up most of the rest. None of that requires a novel technique. It requires a password that someone else also has.

The uncomfortable finding sits with multi-factor authentication. It was deployed in some capacity in almost every incident where stolen credentials were the root cause. Read carelessly that suggests the control does not work. Read properly it says something narrower and more useful: partial coverage provides very little protection, because an attacker only needs the one service that was left out.

The service left out is almost always the same kind of thing. A legacy VPN concentrator kept for a supplier. A management interface reachable from the internet because a firewall rule was added during an outage in 2022 and never removed. An emergency account with a memorable password. The exercise worth running is not another phishing simulation; it is listing every way into the network and checking each one against the identity policy you believe you have.

What would an incident cost you?

Published averages hover around five million dollars an incident, which is a true number and a useless one for planning: it describes a distribution, not your organisation. Move the four inputs below to something that resembles your business and the arithmetic becomes specific enough to argue about — which is the point of putting a figure on a slide at all.

Estimated cost of the incident$3,969,000

Revenue not earned
$2,520,000
Staff time lost
$1,134,000
Response and restoration
$315,000
How this is worked out

Revenue not earned takes annual revenue across 250 working days, multiplied by the days of disruption and the share of operations affected. Staff time lost assumes an eight-hour day at $45 an hour fully loaded, for the same period and the same share. Response and restoration starts at $90,000 and adds $900 per employee, because specialist help is priced by the size of the estate rather than by how long the outage runs.

The ransom itself is deliberately absent. Whether one is demanded, and whether it is paid, are separate decisions with their own arithmetic — and in the incidents where no payment is made, every figure above still applies.

Two things this deliberately leaves out. The ransom itself is absent, because whether one is demanded and whether it is paid are separate decisions — and in the majority of incidents where nothing is paid, every figure above still lands. The cost of publication is also absent, because it resists this kind of arithmetic: regulatory exposure, contract penalties and lost deals arrive over quarters rather than days, and they vary far more by sector than downtime does.

Used honestly, a figure like this changes a conversation. A board that has heard "ransomware is a serious risk" for six years responds differently to a number derived from its own revenue and headcount, especially when the assumptions are on screen and open to challenge. The argument that follows about whether twenty-one days is the right assumption is the valuable part.

Should you pay?

Most organisations now say no, and that majority has grown as recovery has become faster and better rehearsed. Around two-thirds of victims decline. That is a reversal from the middle of the last decade, when paying was frequently the pragmatic route back and was quietly treated as a cost of doing business.

What payment buys has also shrunk. A decryption key of variable quality, which in severe cases restores more slowly than a rebuild. A promise that stolen data has been deleted, which cannot be verified by anyone and has been broken often enough to be worthless as an assurance. Neither addresses publication, which is the part that now does the lasting damage.

There are still situations where paying is the least bad option, and pretending otherwise helps nobody. A hospital with degraded clinical systems and a healthcare provider facing weeks of manual working are not solving the same problem as a software firm with tested infrastructure-as-code. The decision belongs to the people accountable for the consequences, informed by counsel — and it should be taken against criteria written down in advance, not invented at two in the morning with a countdown on screen.

One legal point deserves attention before the incident rather than during it. Payments to sanctioned entities are prohibited in several jurisdictions, and the affiliation of the group demanding money is rarely clear while the negotiation is live. Any organisation that considers payment a possible outcome needs to know in advance who signs that off and on what advice.

What actually reduces the damage

Four things, in rough order of how much they change the outcome per unit of effort. None is novel and all of them are unglamorous, which is part of why they get deferred in favour of a product.

Remove standing administrative privilege. This does not stop an intrusion, and it is not meant to. It stops one compromised account from becoming access to everything, which is the step that separates a contained incident from a company- wide outage. Most organisations that have done it describe the migration as painful for a quarter and invisible afterwards.

Make identity coverage complete rather than broad. Given that multi-factor was present in nearly every credential-driven incident, the work is not more deployment — it is enumeration. Every remote entry point, every service account, every path a supplier uses. The gap is the whole risk.

Know where regulated data sits. When the threat is publication rather than encryption, the first question in the incident is which data left. An organisation that can answer in hours negotiates from a position of fact. One that cannot spends the first week discovering its own estate while a clock runs.

Rehearse the restore, with the network isolated. Backup success rates measure whether jobs completed, not whether the business can come back. The exercise that matters is a full restore of a critical system under the conditions of a live incident, including the awkward discovery that the recovery documentation lives on the file server that is currently encrypted.

What unites the four is that none of them is a purchase. Each is a decision somebody has to make and then defend against the colleagues it inconveniences: the developer who loses permanent domain rights, the supplier asked to authenticate differently, the finance team whose quarterly close now happens on a segmented network. Vendors sell tools that assist with all four and none that substitutes for the argument. Programmes stall at precisely that point, which is why the organisations that have done this work describe it as political rather than technical, and budget it accordingly, with time for the arguments deliberately built in.

How long does recovery actually take?

Just over half of organisations are fully operational within a week. That share has roughly doubled in two years, which is one of the few genuinely encouraging measurements in this subject and reflects real investment in rehearsed recovery rather than better luck.

The mean tells a different story and both are worth carrying. Averaged across all incidents, disruption runs to about three weeks, dragged out by a tail of severe cases where recovery takes months. Planning to the median produces a runbook that works for the ordinary incident and collapses in the one that matters. Planning to the tail alone produces a programme nobody funds.

Recovery cost, excluding any ransom, has also fallen — from roughly two and a half million to something over a million and a half in a year. The improvement is real and it is concentrated among organisations that had rehearsed. Nothing about that trend is automatic, and it does not arrive with a product.

Insurance, disclosure and the regulator

Cyber cover still pays, and it pays less freely than it did. Underwriters spent the early part of the decade absorbing losses they had priced against a different threat, and the correction arrived as questionnaires with teeth: evidence of specific controls before a policy is bound, and exclusions that bite where the evidence and the estate disagree.

That gap is where claims go wrong. An organisation declares that privileged access requires a second factor, and it does — except on the four service accounts that run overnight batch jobs, which is precisely where the attacker went. The declaration was made in good faith by someone who believed it. It was still wrong, and the policy was priced on it.

Disclosure runs on a separate and much shorter clock. Personal data triggers notification duties within days in most jurisdictions, several sectors carry an independent obligation to report the incident itself, and listed companies face materiality tests that do not wait for a complete technical picture. Those timers start when the incident is discovered, not when it is understood.

The practical consequence is that legal counsel belongs in the first hour of the response rather than the second day. Organisations that handle disclosure badly are almost always the ones that treated it as something to sort out once the engineering was under control, by which point the window for doing it well has closed on its own.

How did the model change so completely?

In three steps, each visible in the reporting at the time. The first was scale without selection: campaigns that encrypted whatever they reached and asked for modest sums from everybody. WannaCry, in May 2017, was the high-water mark of that approach and also the end of it — enormously disruptive, commercially unimpressive.

The second step was selection. Groups began choosing organisations that could pay and pricing accordingly, moving through networks by hand before triggering anything. Ryuk, which the trade press was tracking by late 2019, worked this way, and the arithmetic changed: fewer victims, much larger demands.

The third step is the one still unfolding. Maze added the leak site — copy the data first, publish it if the invoice goes unpaid — and by April 2020 the technique was being used against household names. Once that worked, encryption became optional. Everything since has been refinement: pressure applied to customers and regulators directly, and increasingly no encryption at all.

The intervening years added reach rather than novelty. The Kaseya incident showed what happens when the target is the tool that manages a thousand other estates, and DarkSide demonstrated that disrupting physical supply gets a response no amount of stolen data does. Neither changed the extortion model. Both showed how far its blast radius reaches.

When the target is your supplier

A growing share of incidents reach an organisation through something it does not operate. Managed service providers, remote monitoring tools, backup platforms and payroll processors all hold privileged access to many estates at once, which makes each of them a route to hundreds of victims from a single intrusion.

The defensive problem is that the usual controls stop at the boundary. An organisation can enumerate its own remote access, remove its own standing privilege and rehearse its own restore, and still be reached through an agent installed on every endpoint by a supplier whose security posture it has seen only as a completed questionnaire.

Three questions get further than a questionnaire does. What can this supplier's tooling do on our systems without asking us first? How would we know if it did something unexpected? And if we terminated the relationship this afternoon, how long would their access actually persist? The third one produces uncomfortable answers more often than the other two.

Contractual language is worth having and is not a control. A clause obliging notification within twenty-four hours does not shorten the intrusion, and it will not be the reason anyone finds out. Detection that does not depend on the supplier telling you is the part that changes outcomes.

Building a response you can run at three in the morning

Most incident response plans fail on the same detail: they assume the people reading them can reach them. A plan stored on the network that has just been encrypted, describing a call tree in a directory that is currently unavailable, is an artefact of compliance rather than a working document.

Four properties separate a plan that survives contact. It exists on paper and somewhere outside the estate. It names people rather than roles, with numbers that have been dialled in the last six months. It states who can authorise disconnecting production without waiting for consensus. And it says, in advance, what the criteria for considering payment are and who owns that decision.

The legal and communications work belongs in the first hour, not the second day. Notification duties for personal data run on short clocks in most jurisdictions, several sectors carry a separate obligation to report the incident itself, and the organisations that handle disclosure worst are almost always the ones that started thinking about it once the technical picture was clear. By then the window has usually closed on doing it well.

Rehearsal is what converts any of this from a document into a capability. Run it with the technical lead unavailable, since that is a realistic Tuesday. The gaps that surface are rarely the exotic ones anybody war-gamed.

The days before anything is encrypted

Encryption is the last step, and by the time it fires the attacker has usually been present for days. That interval is the whole opportunity. Organisations that contain an incident cheaply almost always caught something during it, and what they caught was rarely subtle.

The recurring signals are mundane. A domain administrator account signing in from a country where nobody works. Bulk enumeration of file shares by an account that has never opened one. A remote access tool appearing on a handful of servers, installed legitimately, by nobody who will admit to it. Backup jobs failing quietly for three nights in a row, or backup retention being shortened by someone with credentials to do it.

Data leaving is the signal most worth instrumenting now that theft has overtaken encryption as the mechanism. A sustained outbound transfer to a file-sharing service at four in the morning is not hard to detect. It is hard to notice, which is a different problem, and it is solved by alerting on volume rather than by adding another dashboard nobody watches.

None of this requires a new product for most organisations. It requires deciding which handful of events warrant waking somebody, and then actually waking them. Detection that produces a ticket for review on Monday is indistinguishable from no detection at all when the timeline runs in hours.

Common questions

What is ransomware?

An extortion attack against an organisation's data. Historically it meant encrypting files and selling the key back. In 2026 it more often means copying the data out and threatening to publish it, with encryption as an optional extra rather than the point.

Do backups still protect you?

Against downtime, yes, and that remains most of the cost. Against publication, no. A clean restore brings the business back and does nothing about a copy of the customer database sitting on someone else's server, which is why the two problems now need separate answers.

How do attackers usually get in?

Through a valid login far more often than through a software flaw. Roughly four incidents in five now begin with credentials that work, and remote access services are the favourite door. Exploiting a known vulnerability has fallen to under a fifth of cases.

We have multi-factor authentication. Are we covered?

Not by itself. Multi-factor was present in some form in nearly every incident where stolen credentials were the root cause. What matters is whether it covers every route in, including the legacy VPN nobody has looked at since it was installed.

Should we pay the ransom?

Most organisations now decline, and the share refusing has grown as recovery has improved. Payment buys a decryption key of uncertain quality and a promise about deleted data that cannot be verified. It does not buy back publication, and it marks you as a payer.

How much does an incident cost?

Published averages land near five million dollars, but averages hide the shape of the distribution. The calculator above gives a figure specific to your revenue, headcount and expected downtime, which is a more useful number to argue about.

How long until we are running again?

Just over half of organisations are fully back within a week, a share that has roughly doubled in two years. The mean is dragged out to about three weeks by a long tail of severe cases, so plan for both the median and the tail.

Does cyber insurance cover this?

Usually in part, and with conditions that have tightened considerably. Insurers now ask for evidence of specific controls before binding, and a gap between what was declared and what was deployed is the most common reason a claim goes badly.

Do we have to tell anyone?

Almost certainly. Personal data triggers notification duties in most jurisdictions on short timers, and in several sectors there is a separate obligation to report the incident itself. The time to find out which apply is before, not during.

Is paying illegal?

It depends on who is paid. Payments to sanctioned entities are prohibited in several jurisdictions and the group's affiliation is rarely clear during the incident, which is one reason legal counsel belongs in the response from the first hour.

What single control helps most?

Removing standing administrative privilege. It does not stop the intrusion, and that is not what it is for: it stops one compromised login from becoming access to everything, which is the step that turns an incident into a catastrophe.

Are small organisations actually targets?

Yes, and disproportionately so relative to their defences. Access is bought and sold rather than earned, so a small firm with an exposed remote desktop is reached by the same route as a large one — it simply has fewer people to notice.

Ransomware coverage

930 reports on ransomware, newest first.