Ransomware—malware used to encrypt data, steal it, or pressure victims with publication threats—remains a major disclosure and recovery risk in 2026. Organizations need to prepare for operational response, regulatory decisions, and law-enforcement coordination at the same time. The evidence also exposes unresolved issues. Reported losses omit much of ransomware's real cost, while a major federal reporting rule remained delayed as of July 2026.
Table of Contents
- What the 2025 complaint data shows
- Why data theft changes the response
- What organizations should do during an attack
- When public companies must disclose
- Which questions remain open
What the 2025 complaint data shows
The FBI's Internet Crime Complaint Center received more than 3,600 ransomware complaints in 2025, with reported losses above $32 million. The FBI cautions that this total excludes disruption, remediation, and some unreported losses, making it an incomplete measure of harm. Akira, Qilin, and INC./Lynx/Sinobi led the ten most-reported variants.
Critical manufacturing, healthcare and public health, and government facilities were the most affected sectors, according to the FBI's 2025 IC3 Annual Report. These figures help identify recurring targets, but they cannot establish ransomware's full economic impact. Boards and risk teams should include downtime, investigation, restoration, legal work, and business interruption when assessing exposure.
Why data theft changes the response
The Gunra advisory issued by U.S. agencies in August 2026 describes an active ransomware-as-a-service operation. In this model, operators provide ransomware capabilities to affiliates who conduct attacks.
Gunra encrypts and exfiltrates data, then threatens to publish or sell the stolen information. Reported victims span government, critical infrastructure, healthcare, finance, manufacturing, transportation, utilities, and other sectors worldwide. That combination creates two separate problems. Restoring systems may resolve encryption, but it does not retrieve stolen files or end possible disclosure obligations.
What organizations should do during an attack
Response teams must first contain the intrusion while preserving evidence and essential operations. They should also assess what systems and information were affected before assuming recovery is complete.
CISA and the FBI recommend several measures against Gunra-style attacks: These controls can improve recovery without paying an attacker, according to the CISA and FBI guidance. NIST's final 2026 ransomware-risk profile also maps practical prevention and mitigation actions to the cybersecurity Framework 2.0 for organizations of any size or sector.
- Patch known-exploited vulnerabilities on internet-facing systems.
- Keep offline, immutable backups separate from production networks.
- Test backups so restoration works under pressure.
- Segment networks to restrict lateral movement.
- Preserve evidence and contact law enforcement promptly.
When public companies must disclose
SEC registrants must determine whether a cyber incident is material to investors. If it is, the company generally must report its nature, scope, timing, and material impact on Form 8-K within four business days after making that determination. A delay is available only through a written U.S. Attorney General determination that disclosure would create a substantial national-security or public-safety risk, as explained in the SEC's cyber-disclosure rule announcement.
Paying a ransom, restoring data, or ending visible disruption does not eliminate the materiality analysis. SEC staff guidance says a public company must still determine materiality and file the required disclosure if the incident qualifies. The practical lesson is to involve security, legal, finance, and disclosure teams early. Waiting until technical recovery ends can leave too little time for an accurate filing.
Which questions remain open
CIRCIA—the Cyber Incident Reporting for Critical Infrastructure Act—remains the central unresolved federal reporting issue. GAO reported in July 2026 that CISA's final incident and ransom-payment reporting rule had been delayed and was then planned for September 2026. GAO also found that federal reporting-harmonization efforts remained incomplete.
Until implementation settles the requirements, potentially covered organizations should track the rule's status and maintain records that can support overlapping reports, including incident timing, affected systems, material effects, payments, and response actions. See the GAO's July 2026 assessment. Law-enforcement reporting can also create recovery opportunities beyond investigation. DOJ says the 2023 ALPHV/BlackCat disruption gave hundreds of victims decryption capability and prevented an estimated $99 million in ransom payments.
