Ransomware is malicious software that locks an organization's files or systems, often after stealing the data, and demands payment to restore access. In 2026 the main facts to know are these: attacks still hit critical services hardest, recovery costs more than the ransom, and offline backups plus a fast, planned response decide how badly an attack hurts. This guide covers who is most exposed, which criminal groups lead, what to do in the first hours, how recovery and payment decisions work, and what to ask your IT team or vendor before an attack happens.
Table of Contents
- How Big Is the Ransomware Problem Right Now?
- Who Is Most Exposed, and Which Groups Lead?
- What Should Happen in the First Hours of an Attack?
- Can You Recover Without Paying?
- What Are the Risks of Paying a Ransom?
- Questions to Ask Before an Attack
- Frequently Asked Questions
How Big Is the Ransomware Problem Right Now?
The FBI's 2025 Internet Crime Report from IC3 recorded 3,611 ransomware complaints and more than $32 million in reported losses. That total leaves out downtime, business disruption and cleanup. Those costs often exceed the ransom itself, so the real damage is much higher. Survey data shows the scale for larger organizations. Sophos surveyed 2,158 IT and security leaders in 17 countries for its State of Ransomware 2026 report.
The median ransom payment fell to $769,000, down from $1 million the year before. Average recovery cost, not counting any ransom, rose 11% to about $1.70 million. The two sources measure different things. FBI figures count only complaints filed with IC3, while Sophos figures come from a vendor's own survey. Both likely undercount, and they shouldn't be added together or compared directly.
Who Is Most Exposed, and Which Groups Lead?
IC3 counted more than 2,100 ransomware attacks on U.S. critical infrastructure in 2025. healthcare and public health led with 460 ransomware attacks and 182 data breaches. Critical manufacturing, financial services, information technology and government followed. IC3 named Akira, Qilin and Lynx as the three most-reported strains of 2025.
All three are rented out to other criminals as a service. That means the people who break in are often not the people who wrote the malware. All three also use double extortion. They steal data and lock it, then charge for both. Restoring from backup fixes the lockout but not the theft, so a well-prepared victim can still face a data breach. IC3 also logged 63 new strains in 2025, more than five a month.
What Should Happen in the First Hours of an Attack?
Speed and containment matter most. CISA's #StopRansomware Guide tells organizations to find the affected systems and isolate them right away. Start with systems critical to daily operations.
CISA advises calling law enforcement even when you can recover on your own. Researchers sometimes find flaws in a strain's encryption and release free decryption tools. Reporting also helps other organizations defend against the same group.
- Identify which machines, servers and accounts show encryption or strange activity.
- Disconnect those systems from the network immediately.
- If several systems or subnets are hit, take the network offline at the switch level.
- Contact federal law enforcement, such as the FBI, and report to CISA.
- Share signs of the attack with CISA or your sector's information-sharing group (ISAC).
Can You Recover Without Paying?
Backups are the difference between restoring and negotiating. CISA recommends keeping encrypted backups of critical data offline, on a separate device the network can't reach. It also says to test them regularly. Offline matters because attackers look for backups first.
Many strains search for backups they can reach and delete or encrypt them. That leaves the victim with no way to restore except by paying. A backup stored on a connected network drive can fail you in exactly this way. So can a backup that has never been test-restored. Even a clean restore does not undo the data theft in a double-extortion attack.
What Are the Risks of Paying a Ransom?
Paying brings legal risk as well as financial cost. The U.S. Treasury's Office of Foreign Assets Control advisory warns that anyone who helps pay a ransom may violate U.S. sanctions. That includes victims, banks, cyber insurers and incident-response firms.
The same advisory counts quick reporting and cooperation with U.S. agencies as mitigating factors if OFAC takes enforcement action. An organization that is even weighing payment should report early rather than after deciding. Ransoms can also be negotiated. In the Sophos survey, 51% of organizations that paid got the amount reduced. Paying still leaves the recovery bill, which averaged about $1.70 million in that survey without the ransom.
Questions to Ask Before an Attack
Put these questions to your IT team, managed service provider or insurer now, while there's time to fix the answers: A plan that can't answer the backup questions is the most urgent gap, because it is the one attackers are built to exploit.
- Are our critical backups encrypted, offline and unreachable from the network?
- When did we last restore from them, and how long did it take?
- Who has authority to isolate systems or shut the network down at the switch level?
- Who calls the FBI and CISA, and do we have those contacts written down?
- Which ISAC serves our sector, and are we members?
Frequently Asked Questions
Does restoring from backup end a double-extortion attack?
No. Backups restore locked systems, but attackers who use double extortion have already stolen the data and may still demand payment to keep it private.
Should a small business report an attack it recovered from?
Yes. CISA advises contacting federal law enforcement even after a self-recovery, because reports can lead to free decryption tools and help others defend.
Can an insurer or response firm pay the ransom for us to avoid legal risk?
No. OFAC's advisory says insurers, banks and incident-response firms that help with a payment may also violate sanctions.
You Might Also Like
- Financial Sector Data Breach News 2026 Guide: exposure, response, and recovery; Key Facts and Questions to Ask
- What Is New With Ransomware Attacks in August 2026? Latest breach notices and security advisories and Key Takeaways
- Ransomware Attacks August 2026 Update: What Changed, Why It Matters, and What to Watch Next