Ransomware Cost: What a Ransomware Attack Costs in 2026
Ransomware attacks encrypt or exfiltrate an organisation's data, then demand payment for decryption or data suppression. The average cost to recover from a ransomware attack was $1.7M in 2026 excluding any ransom payment, up 11% from $1.53M in 2025 (Sophos State of Ransomware 2026). The full cost of an event runs higher once the ransom (a median $150,000 to $769,000 where paid), downtime revenue loss, legal counsel, and breach-notification are added. Few victims pay: the Q2 2026 payment rate fell to a new record low, with the data-exfiltration-only rate down to 15% (Coveware).
What the 2025-2026 Reports Found
No single report captures the entire cost of a ransomware event end-to-end, because each measures a different slice. The figures below are taken verbatim from each primary source so they can be cited directly.
| Source | Figure | What it measures |
|---|---|---|
| Sophos State of Ransomware 2026 | $1.7M | Average recovery cost, excluding ransom (up 11% from $1.53M in 2025) |
| Sophos State of Ransomware 2026 | $769K median | Median ransom payment (down from $1M in 2025) |
| Coveware Q2 2026 | $1,880,612 avg / $150,000 median | Ransom payments actually made |
| Coveware Q2 2026 | 15% | Data-exfil-only victims who paid (record low) |
| Resilience Cyber Risk Report 2025 | $1.18M | Average insured ransomware loss (+17% YoY) |
| IBM Cost of a Data Breach 2025 | 63% refuse | Ransomware victims declining to pay (up from 59%) |
Sources: Sophos State of Ransomware 2026 (2,158 organisations), Coveware Q2 2026 Ransomware Marketplace Report, Resilience Cyber Risk Report 2025, IBM Cost of a Data Breach Report 2025.
The Cost Components of a Ransomware Event
A ransomware incident triggers several cost categories at once. Only the recovery and ransom figures below are anchored to a primary source; the remaining ranges are illustrative and vary enormously with revenue, downtime duration, and the volume of regulated data exposed.
| Cost Category | Typical Amount | Notes |
|---|---|---|
| Recovery and rebuild | $1.7M avg (Sophos 2026) | Restoration, rebuild, and remediation, excluding ransom |
| Ransom payment (where paid) | $150K-$769K median | Coveware Q2 2026 median $150K; Sophos 2026 median $769K |
| Downtime revenue loss | Highly variable | Scales with revenue and outage duration |
| Legal and regulatory | Variable | Counsel, GDPR/HIPAA notification where data was exfiltrated |
| Forensics and IR | Variable | External DFIR firm, evidence preservation |
| PR and reputation | Variable | Crisis communications, customer-trust rebuilding |
Sources: Sophos State of Ransomware 2026, Coveware Q2 2026.
To Pay or Not to Pay: The Real Cost Comparison
- Median ransom paid: $150,000 (Coveware Q2 2026) to $769,000 (Sophos 2026)
- Paid on top of recovery costs, not instead of them
- 51% of paying organisations negotiated the amount below the demand (Sophos 2026)
- OFAC sanctions exposure if the group is a designated entity
- A decryptor can be slow or incomplete; data may still be leaked
- Payment rate at a record low; only 15% pay in data-exfiltration-only cases (Coveware Q2 2026)
- Average recovery cost: $1.7M (Sophos 2026), up 11% YoY
- 63% of ransomware victims refused to pay in 2025 (IBM), up from 59%
- Slower restoration if backups are not immutable and tested
- Must still address data exfiltration (notification if data was taken)
- No funding of a sanctioned or repeat-offending threat actor
Bottom line: Paying the ransom adds cost rather than reducing it, because the ransom sits on top of the same recovery bill. The primary argument for paying is speed of restoration, not total cost. Tested immutable backups and an IR retainer are the only reliable cost-reducers.
Extortion Variants and Their Cost Profiles
| Variant | Tactic | Cost vs Basic Ransomware |
|---|---|---|
| Basic encryption only | Files encrypted, demand for decryption key | Baseline |
| Double extortion | Encrypt + exfiltrate; pay or data published | Higher (adds notification, legal, brand cost) |
| Triple extortion | Double + DDoS attack on victim during negotiations | Higher still (adds DDoS mitigation + payment pressure) |
| Ransom DDoS (RDDoS) | No encryption; DDoS threatened unless crypto paid | Mitigation cost only, typically lower |
Notable Ransomware Incidents 2021-2025
| Organisation | Year | Est. Total Cost | Details |
|---|---|---|---|
| Change Healthcare | 2024 | $2.87B+ | AlphV/BlackCat affiliate; UHG subsidiary |
| CDK Global | 2024 | $1B+ (est.) | BlackSuit ransomware; auto dealer disruption |
| MGM Resorts | 2023 | $100M+ | Scattered Spider vishing attack |
| Caesars Entertainment | 2023 | $15M ransom (paid) | Same group as MGM; chose to pay |
| Clorox | 2023 | $356M total impact | Manufacturing disruption, supply chain impact |
| Colonial Pipeline | 2021 | $4.4M ransom + weeks downtime | DarkSide; critical infrastructure |
Cost Reducers
The single most effective control against ransom leverage. Organisations restoring from tested immutable backups avoid the ransom entirely and recover faster. Backups must be tested regularly to be reliable.
Emergency hourly rates without a retainer run $800-$1,500/hr. Retained IR firms respond in 2-4 hours vs 24-48 hours cold. Retainer cost: $25K-$100K/yr.
Covers ransom negotiation, IR costs, legal, and notification. Insurers increasingly require MFA and EDR as conditions of cover, and claims volumes fell in 2025 even as per-event losses rose (Resilience).
Endpoint Detection and Response reduces ransomware deployment success. MFA closes credential-based entry, which remains a leading ransomware access vector (Verizon DBIR 2026).