Ransomware payment rate drops to record low as attacks surge
嗯,用户让我帮忙总结一篇文章,控制在一百个字以内,而且不需要用“文章内容总结”之类的开头。首先,我需要仔细阅读这篇文章,理解其主要内容和关键数据。 文章主要讲的是勒索软件的情况。去年支付赎金的受害者比例下降到28%,是历史新低。尽管声称的攻击数量显著增加。Chainalysis连续四年观察到支付趋势下降。2025年的链上赎金支付总额为8.2亿美元,可能接近或超过9亿美元。 尽管勒索软件攻击增加了50%,但总支付数量相对稳定。2024年的支付率是62.8%,2022年是78.9%。数据泄露事件和支付率有相关性。Chainalysis指出影响勒索经济的因素包括更好的事件响应、监管审查、国际执法行动和市场碎片化。 虽然总收入下降,但中位数赎金增加了368%。这可能是因为受害者希望删除数据。活跃的勒索集团数量增加到85个,美国是主要目标国家。初始访问代理赚了1400万美元,占总收入的1.7%。 总的来说,勒索软件在适应变化,影响越来越大。 现在我需要把这些信息浓缩到100字以内,确保涵盖主要点:受害者支付比例下降、攻击增加、Chainalysis的数据、中位数赎金上升、活跃勒索集团数量增加、美国为目标国家以及影响因素。 </think> 去年勒索软件受害者支付比例降至28%,创历史新低,尽管攻击数量显著增加。Chainalysis数据显示,链上赎金支付总额达8.2亿美元,中位数赎金上涨368%至5.9万美元。活跃勒索团伙增至85个,美国为主要目标国家。 2026-2-26 15:30:29 Author: www.bleepingcomputer.com(查看原文) 阅读量:5 收藏

Ransomware payment rate drops to record low despite attack surge

The number of ransomware victims paying threat actors has dropped to 28% last year, an all-time low, despite a significant increase in the number of claimed attacks.

A downward payment trend has been observed for the past four consecutive years by the blockchain intelligence platform Chainalysis.

At the moment, the total of on-chain ransomware payments in 2025 stands at $820 million, but the company notes that "the 2025 total is likely to approach or exceed $900 million as we attribute more events and payments."

Wiz

Chainalysis reports a relative stability in the total number of payments, despite a 50% increase of ransomware attacks year-over-year.

In 2024, the payment rate recorded by Chainalysis was more than double, at 62.8%, while in 2022, it was at 78.9%.

Data leak events (bars) and payment rate (line)
Data leak events (bars) and payment rate (line)
Source: Chainalysis

Data from Chainalysis also aligns with previous reports by Coveware, which showed a steady decline in victim payment rates throughout 2025.

According to the blockchain company, some of the factors that influenced the ransomware economy include improved incident response, regulatory scrutiny, international law enforcement actions, and market fragmentation.

Current Chainalysis data shows that while aggregate revenue from ransomware activity declined, the median ransom payment rose significantly, up 368% from $12,738 in 2024 to $59,556 in 2025.

This indicates that ransomware victims pay larger amounts for the hope that cybercriminals will delete the stolen data and not sell it to other threat actors or trade it.

Payment amounts graph
Payment amounts graph
Source: Chainalysis

In 2025, the analysts observed 85 active extortion groups, far higher compared to previous years, when the ransomware space was dominated by a small number of threat groups and RaaS platforms.

A few high-impact incidents Chainalysis highlights in its report include the attack at Jaguar Land Rover, which inflicted an estimated $2.5 billion in damages, the Marks & Spencer breach by the Scattered Spider threat group, and the DaVita Inc. ransomware breach that exposed 2.7 million patient records.

For another year, the most targeted country was the United States, followed by Canada, Germany, and the U.K., showing threat actors’ preference for concentrating their efforts in developed economies.

Targeted countries and industries
Targeted countries and industries
Source: Chainalysis

Initial access brokers (IABs), hackers who sell access to compromised endpoints to ransomware operators, reportedly made $14 million in 2025, roughly the same as last year. This is only 1.7% of the total ransomware revenue last year, though initial access is a key enabler.

Analysis shows that spikes in IAB payment inflows are followed by increases in ransomware payments and victim leak posts roughly 30 days later, suggesting IAB activity can act as a leading indicator.

The average price for network access declined from approximately $1,427 in Q1 2023 to just $439 in Q1 2026, indicating that automation, AI-assisted tooling, and oversupply from info-stealer logs have shaped the industry.

Chainalysis says that although ransom payments declined last year, the scale, sophistication, and real-world impact of ransomware attacks continued to grow, impacting organizations of all sizes and backgrounds globally.

The researchers believe ransomware is going through a phase of adaptation, rather than losing the fight, evolving tactics to extract more value from an ever-decreasing number of consenting victims.

tines

The future of IT infrastructure is here

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.


文章来源: https://www.bleepingcomputer.com/news/security/ransomware-payment-rate-drops-to-record-low-as-attacks-surge/
如有侵权请联系:admin#unsafe.sh