Ransomware Cost: What a Ransomware Attack Costs in 2026
Ransomware attacks encrypt or exfiltrate an organisation's data, then demand payment for decryption or data suppression. The average cost to recover from a ransomware attack was $1.53M in 2025 excluding any ransom payment, down from $2.73M in 2024 (Sophos State of Ransomware 2025). The full cost of an event runs higher once the ransom (a median $300,750 to $1M where paid), downtime revenue loss, legal counsel, and breach-notification are added. Few victims pay: the Q1 2026 payment rate was roughly 23%, up slightly from Q4 2025's ~20% record low (Coveware).
What the 2025-2026 Reports Found
No single report captures the entire cost of a ransomware event end-to-end, because each measures a different slice. The figures below are taken verbatim from each primary source so they can be cited directly.
| Source | Figure | What it measures |
|---|---|---|
| Sophos State of Ransomware 2025 | $1.53M | Average recovery cost, excluding ransom (down from $2.73M in 2024) |
| Sophos State of Ransomware 2025 | $1.0M median | Median ransom payment (down ~50% from $2M in 2024) |
| Coveware Q1 2026 | $680,081 avg / $300,750 median | Ransom payments actually made |
| Coveware Q1 2026 | 23% | Share of victims who paid (up from Q4 2025 low) |
| Resilience Cyber Risk Report 2025 | $1.18M | Average insured ransomware loss (+17% YoY) |
| IBM Cost of a Data Breach 2025 | 63% refuse | Ransomware victims declining to pay (up from 59%) |
Sources: Sophos State of Ransomware 2025 (3,400 organisations), Coveware Q1 2026 Ransomware Marketplace Report, Resilience Cyber Risk Report 2025, IBM Cost of a Data Breach Report 2025.
The Cost Components of a Ransomware Event
A ransomware incident triggers several cost categories at once. Only the recovery and ransom figures below are anchored to a primary source; the remaining ranges are illustrative and vary enormously with revenue, downtime duration, and the volume of regulated data exposed.
| Cost Category | Typical Amount | Notes |
|---|---|---|
| Recovery and rebuild | $1.53M avg (Sophos 2025) | Restoration, rebuild, and remediation, excluding ransom |
| Ransom payment (where paid) | $301K-$1M median | Coveware Q1 2026 median $301K; Sophos 2025 median $1M |
| Downtime revenue loss | Highly variable | Scales with revenue and outage duration |
| Legal and regulatory | Variable | Counsel, GDPR/HIPAA notification where data was exfiltrated |
| Forensics and IR | Variable | External DFIR firm, evidence preservation |
| PR and reputation | Variable | Crisis communications, customer-trust rebuilding |
Sources: Sophos State of Ransomware 2025, Coveware Q1 2026.
To Pay or Not to Pay: The Real Cost Comparison
- Median ransom paid: $300,750 (Coveware Q1 2026) to $1M (Sophos 2025)
- Paid on top of recovery costs, not instead of them
- 53% paid less than the original demand after negotiation (Sophos)
- OFAC sanctions exposure if the group is a designated entity
- A decryptor can be slow or incomplete; data may still be leaked
- Only 23% of victims now choose to pay (Coveware Q1 2026)
- Average recovery cost: $1.53M (Sophos 2025), down 44% YoY
- 63% of ransomware victims refused to pay in 2025 (IBM), up from 59%
- Slower restoration if backups are not immutable and tested
- Must still address data exfiltration (notification if data was taken)
- No funding of a sanctioned or repeat-offending threat actor
Bottom line: Paying the ransom adds cost rather than reducing it, because the ransom sits on top of the same recovery bill. The primary argument for paying is speed of restoration, not total cost. Tested immutable backups and an IR retainer are the only reliable cost-reducers.
Extortion Variants and Their Cost Profiles
| Variant | Tactic | Cost vs Basic Ransomware |
|---|---|---|
| Basic encryption only | Files encrypted, demand for decryption key | Baseline |
| Double extortion | Encrypt + exfiltrate; pay or data published | Higher (adds notification, legal, brand cost) |
| Triple extortion | Double + DDoS attack on victim during negotiations | Higher still (adds DDoS mitigation + payment pressure) |
| Ransom DDoS (RDDoS) | No encryption; DDoS threatened unless crypto paid | Mitigation cost only, typically lower |
Notable Ransomware Incidents 2021-2025
| Organisation | Year | Est. Total Cost | Details |
|---|---|---|---|
| Change Healthcare | 2024 | $2.87B+ | AlphV/BlackCat affiliate; UHG subsidiary |
| CDK Global | 2024 | $1B+ (est.) | BlackSuit ransomware; auto dealer disruption |
| MGM Resorts | 2023 | $100M+ | Scattered Spider vishing attack |
| Caesars Entertainment | 2023 | $15M ransom (paid) | Same group as MGM; chose to pay |
| Clorox | 2023 | $356M total impact | Manufacturing disruption, supply chain impact |
| Colonial Pipeline | 2021 | $4.4M ransom + weeks downtime | DarkSide; critical infrastructure |
Cost Reducers
The single most effective control against ransom leverage. Organisations restoring from tested immutable backups avoid the ransom entirely and recover faster. Backups must be tested regularly to be reliable.
Emergency hourly rates without a retainer run $800-$1,500/hr. Retained IR firms respond in 2-4 hours vs 24-48 hours cold. Retainer cost: $25K-$100K/yr.
Covers ransom negotiation, IR costs, legal, and notification. Insurers increasingly require MFA and EDR as conditions of cover, and claims volumes fell in 2025 even as per-event losses rose (Resilience).
Endpoint Detection and Response reduces ransomware deployment success. MFA closes credential-based entry, which remains a leading ransomware access vector (Verizon DBIR 2026).