Ransomware is malicious software that encrypts an organization's files and holds them hostage, usually paired with the theft of the same data so attackers can threaten to publish it. In 2026 it affects almost every sector — healthcare, schools, local government, finance, manufacturing and nonprofits — and the evidence now points the same way in three independent data sets: more incidents, fewer victims paying, and initial access most often bought with an unpatched internet-facing system rather than a stolen password. That combination changes what a reader should actually do. Refusing to pay has become the majority response rather than the brave exception, which makes recovery capability — offline backups, a patch process, and a rehearsed reporting path — the thing worth spending money on before an incident rather than during one.
Table of Contents
- What the 2026 numbers actually show
- How attackers are getting in
- Who is being targeted
- Should you pay? What the evidence says
- What to do in the first hours
- Frequently Asked Questions
What the 2026 numbers actually show
Ransomware was present in 48% of confirmed data breaches in Verizon's 2026 Data Breach Investigations Report, up from 44% the year before. The same report found 69% of ransomware victims refused to pay, and the median ransom that was actually paid fell to $139,875 from $150,000. Verizon's data window ran from November 1, 2024 to October 31, 2025. Blockchain tracing tells a compatible story from a different angle.
Chainalysis reported in its 2026 Crypto Crime Report that on-chain ransomware payments fell roughly 8% to about $820 million in 2025, even as the number of publicly claimed victims rose about 50%. The share of victims paying dropped to an estimated all-time low near 28%. One figure moves against the trend and is worth understanding. Chainalysis found the median payment rose 368% year over year to nearly $60,000. Fewer organizations are paying, but the ones that do are writing larger cheques — consistent with attackers concentrating on victims who cannot recover without a decryptor.
How attackers are getting in
For the first time in 19 years of DBIR data, vulnerability exploitation overtook stolen credentials as the leading way breaches start, accounting for 31% of them. Verizon also reports that attackers are using AI tooling to compress the gap between a vulnerability being disclosed and being exploited from months down to hours. A quarterly patch cycle no longer covers an internet-facing appliance. The advisories name specific doors.
CISA, the FBI and partners issued a joint #StopRansomware advisory on Gunra ransomware on August 11, 2026, reporting that affiliates gain initial access by exploiting CVE-2024-55591 and CVE-2025-24472 in internet-facing firewall and VPN appliances. Those are the boxes that sit at the network edge and are easy to forget precisely because they are working. Older methods have not gone away. The FBI, CISA and HHS report that Medusa affiliates rely on phishing and unpatched software, and CISA's #StopRansomware Guide lists three defences as the core of any programme: offline immutable backups, patching internet-facing systems, and network segmentation that stops one compromised machine from reaching everything.
Who is being targeted
The sector lists in the 2026 advisories are broad by design. Gunra affiliates have hit healthcare, financial services, government and nonprofit organizations across five regions. The FBI, CISA and HHS said in their Medusa advisory updated on August 18, 2026 that Medusa developers and affiliates had struck more than 500 victims as of April 2026, across medical, education, legal, insurance, technology and manufacturing. Reported volume understates the problem badly.
The FBI's Internet Crime Complaint Center logged more than 3,600 ransomware complaints in 2025 with reported losses above $32 million, and identified 63 new ransomware variants — but IC3 counts only reported ransom losses. Downtime, remediation and lost business are excluded, so the real cost sits far above that figure. The practical read for a smaller organization: 63 new variants in a single year means there is no short list of gangs to defend against. A school district or a regional clinic is not too small to appear on a leak site, and the entry points named in the advisories are ones almost every organization has.
Should you pay? What the evidence says
CISA, the FBI, the NSA and MS-ISAC advise victims not to pay, on two grounds: payment does not guarantee file recovery, and the money funds the next round of attacks. The Medusa case files give that abstract warning a concrete shape. FBI investigations documented a victim who paid, then was contacted by a second Medusa actor claiming the negotiator had stolen the payment — and demanding half the amount again for the "true decryptor." Paying also carries legal exposure that many organizations discover too late. The US Treasury's Office of Foreign Assets Control warns that paying or facilitating a ransom can violate sanctions law if the recipient is on the SDN list or in an embargoed jurisdiction.
That exposure extends beyond the victim to cyber insurers, incident-response firms and payment processors. Victims who report to Treasury's OCCIP and contact OFAC receive significant enforcement mitigation. The rules may tighten further. The UK Home Office's government response confirmed plans to ban ransom payments by public sector bodies and critical national infrastructure operators — including the NHS, councils and schools — with 72% of respondents in favour, and to require other businesses to notify government before paying. These are legislative proposals, not enacted law, so a UK organization today is making a judgement call, not following a statute.
What to do in the first hours
Speed matters less than sequence. Reporting early preserves options that disappear later: decryptors, sanctions mitigation, and the ability to trace payments.
The preparation that makes any of this survivable happens months earlier. Backups have to be offline and immutable, because attackers look for backup servers first; patching has to cover the firewall and VPN appliances named in the Gunra advisory; and segmentation has to be tested, not assumed.
- Isolate affected systems from the network without powering them down, so volatile evidence survives.
- Report promptly to a local FBI field office, ic3.gov, or CISA's 24/7 Operations Center, as the #StopRansomware Guide directs.
- If payment is being considered at all, contact OFAC and Treasury's OCCIP before any funds move, not after.
- Check whether a free decryptor exists for the variant before treating payment as the only recovery route.
- Assume data was stolen as well as encrypted — Medusa operates a double-extortion model, where files are exfiltrated first and publication is threatened separately from the encryption.
Frequently Asked Questions
Does refusing to pay mean losing the data permanently?
Not necessarily. Recovery depends on whether backups are offline and intact, and whether a free decryptor exists for the variant. Paying carries its own failure risk — the FBI documented a Medusa victim who paid and was then asked for half again by a second actor.
Why are total payments falling while attacks rise?
Chainalysis attributes it to a falling share of victims paying — near 28% in 2025, an estimated all-time low — even as publicly claimed victims rose about 50%. More organizations can now recover without a decryptor.
Is a small organization safe from these groups?
Medusa alone passed 500 victims as of April 2026 across medical, education, legal, insurance, technology and manufacturing. IC3 identified 63 new variants in 2025, so targeting is opportunistic rather than curated.
You Might Also Like
- Healthcare Data Breach News Explained for 2026: Who It Affects, Key Evidence, and What to Do Next
- Financial Sector Data Breach News Explained for 2026: Who It Affects, Key Evidence, and What to Do Next
- How to Verify Ransomware Attacks Claims in 2026: breach notices and security advisories, Evidence, and Red Flags