Opinion

Why Rising Ransomware Payments Mean Fewer Victims Are Paying

By Joe Manning 8 min read
Why Rising Ransomware Payments Mean Fewer Victims Are Paying

Key takeaways

  • The average ransom payment jumped 176% quarter over quarter to $1,880,612 in Q2 2026, according to Coveware by Veeam, but the overall share of victims who paid anything fell to a record low.
  • The payment rate for data-theft-only attacks (no encryption at all) also dropped, to a historic low of 15%, meaning even the "leak your data" threat is losing its bite for most victims.
  • A handful of huge payouts, mostly law firms hit by the social-engineering group Silent Ransom (also known as Luna Moth), are dragging the average up while the median payment fell 50% to $150,000.
  • Identity abuse, such as fake help-desk calls and MFA reset requests, is now a bigger initial-access route than malware, which changes what defenders should actually spend their budget on.

The headline number from the latest ransomware payment data looks alarming: average payouts up 176% in a single quarter. But the number hiding underneath it is more important, and more encouraging. According to Coveware by Veeam's Q2 2026 cyber extortion report, the share of victims who ultimately pay a ransom at all fell to a new record low during the same three months. Ransomware payment trends are not telling one story this quarter, they are telling two contradictory ones at once, and the gap between them is the real news.

The $1.88 Million Average Is Doing a Lot of Hiding

Coveware by Veeam reports that the average ransom payment reached $1,880,612 in the second quarter of 2026, a 176% jump from the first quarter. Read alone, that figure suggests ransomware crews are having a banner year. But the median payment, the number that better reflects what a typical victim actually pays, fell by half in the same period to $150,000. When an average rises sharply while the median falls, it almost always means a small number of extreme outliers are pulling the mean upward while most cases are getting cheaper or rarer.

That is exactly what happened here. Coveware attributes the spike in average payments primarily to an ongoing campaign against high-profile law firms, run by a group called Silent Ransom, also tracked as Luna Moth. A related security incident covered in our look at autonomous ransomware tooling showed a similar pattern: a small set of high-value targets can distort an entire quarter's statistics even as the broader trend moves in the opposite direction.

Advertisement

Encryption Stopped Paying Once Backups Started Working

The other number buried in the report is arguably more important than the average payment: the payment rate for data-exfiltration-only attacks, meaning the attacker steals data but never encrypts anything, dropped to a historic low of 15%, per Coveware. That is a strange result if you assume ransomware is only getting scarier. It makes more sense once you consider why encryption-based extortion has been losing its grip for several years: organizations that can restore from backups without paying simply do not need to pay, and a growing number now can.

Encryption-only ransomware works on a simple threat: pay us or lose your data forever. Once that threat stops being credible, because a company can rebuild from backups in days rather than weeks, the economics of encryption-first attacks collapse. Attackers responded by shifting emphasis toward exfiltration and the threat of public leaks instead. But Q2's numbers show that threat is also wearing thin for most victims: record-low payment rates suggest that many organizations are now willing to accept a leak rather than negotiate, particularly when the stolen data is not immediately damaging.

Rows of server racks lit by blue indicator lights

Why Attackers Moved From Malware to Your Help Desk

If encryption is losing leverage and exfiltration threats are getting less effective too, attackers need a cheaper way in to make the economics work at all. Coveware's report describes this shift plainly: initial access in Q2 was dominated by identity abuse rather than malware. Attackers are exploiting "trusted identity workflows including MFA and password resets, help desk manipulation, account recovery processes, OAuth grants, delegated applications, and remote access portals," in the report's own words.

This is a cheaper, quieter version of the same crime. Instead of writing malware that has to evade endpoint detection, an attacker calls a help desk, impersonates an employee, and asks for a password reset or an MFA re-enrollment. Coveware's data shows this is working: lateral movement and data exfiltration each appeared in 76% of cases in Q2, tied for the most common tactics observed, while command-and-control activity showed up in 69% of cases, up 11 percentage points from the prior quarter. Discovery activity, attackers mapping out a network after gaining access, rose to 52% of cases, up 10 points. None of that requires a single line of custom malware.

Advertisement

Who Actually Pays $1.88 Million? Mostly Law Firms, Not Typical Businesses

Silent Ransom's law firm campaign is the clearest illustration of why the average payment jumped so far out of line with the median. Coveware describes the group's method as "targeted social engineering" combined with "physical infiltration" of law offices, using vishing (voice phishing) calls and impersonation rather than exploits or malware. Law firms hold exactly the kind of sensitive, reputationally explosive material, client records, privileged communications, litigation strategy, that makes a leak threat unusually credible and expensive to ignore.

✦ Free Newsletter ✦

Never miss a story

Tools, tutorials and AI deep-dives - straight to your inbox, every week.

No spam, unsubscribe any time.
Office phone handset resting on a desk

That is a narrow, specific vulnerability, not a general one. Coveware's broader industry breakdown for Q2 puts software services at 17.2% of cases, healthcare at 14.1%, and professional services (which includes law firms) at 13.1%. Mid-market organizations, defined as 11 to 10,000 employees, accounted for 75.8% of all cases, and the median victim organization grew to 750 employees, up 50% from the first quarter. Ransomware crews are not chasing the biggest possible targets; they are chasing organizations large enough to have something worth stealing but not always mature enough to have hardened identity processes.

Is Ransomware Actually Getting Worse, or Just More Selective?

Both, depending on which number you look at. Aggregate dollar figures and the size of the largest single payouts are trending up, driven by a small number of highly targeted, highly profitable campaigns like Silent Ransom's law firm operation. At the same time, the broad base of ransomware victims is paying less often and less money than before, because backups, incident response planning, and a general refusal to negotiate have made the average attack less profitable. Ransomware is not disappearing, it is concentrating.

Bookshelf of legal binders in a law office

The Honest Counterpoint: A Record-Low Payment Rate Does Not Mean a Record-Low Attack Rate

It would be easy to read all this as reassuring, and it partly is, but the strongest objection deserves airtime. A falling payment rate does not mean fewer attacks, fewer breaches, or less total damage. Coveware's own report shows attack sophistication rising across nearly every measured tactic: command-and-control activity up 11 points, discovery up 10 points, and identity-based initial access becoming the dominant pattern. Organizations that refuse to pay still absorb downtime, incident response costs, regulatory exposure, and reputational harm, whether or not a ransom check gets written.

Advertisement

There is also a selection effect worth naming: Coveware's data reflects cases where the firm was retained to negotiate or advise, which skews toward organizations sophisticated enough to call in professional incident responders in the first place. Smaller, less prepared victims that pay quietly through an intermediary, or that never report an incident at all, are underrepresented in any single vendor's dataset. Treat the specific percentages as directionally reliable rather than a census of every ransomware case in the world.

What This Means for Security Teams Right Now

The practical shift from malware-driven to identity-driven attacks changes where a defense budget should go. A short checklist based on what Coveware's Q2 data actually shows working against organizations:

Person typing on a laptop at an office desk
  • Require phishing-resistant, hardware-based MFA (FIDO2 security keys) rather than SMS or app-based codes that can be socially engineered through a help desk.
  • Add a callback or secondary verification step for any password reset, MFA re-enrollment, or account recovery request that originates from a phone call, not just from a support ticket.
  • Monitor and alert on new OAuth grants and delegated application permissions, since attackers are using these as a quiet, malware-free persistence method.
  • Treat law firms, professional services firms, and mid-market companies (roughly 11 to 10,000 employees) as high-priority targets for identity hardening specifically, since Q2's data shows attackers concentrating there.
  • Maintain and regularly test offline or immutable backups, since organizations that can restore without negotiating are the reason encryption-only extortion is losing leverage.

Security leaders at mid-market companies, law firms, and anyone managing help-desk or account-recovery workflows should read Coveware's identity-abuse findings closely; this quarter's data is describing their threat model. Consumers and very small businesses without a dedicated help desk are a much lower priority for this specific set of changes, since fake help-desk calls need a real help desk to target. Teams already running phishing-resistant MFA and tested immutable backups, similar to the approach behind reducing dependence on third-party SaaS access paths, are already ahead of most of what this report describes.

Advertisement

The Takeaway: Watch the Payment Rate, Not the Average Payment

The average ransom payment is the number that makes headlines, but it is also the number most distorted by a handful of extreme cases. The payment rate, the percentage of victims who actually decide to pay, is the more honest measure of whether ransomware is working as a business model, and in Q2 2026 it fell to a record low across both encryption and data-theft-only attacks. That is the number worth tracking next quarter, alongside whether identity-based attacks like help-desk impersonation keep climbing. If both trends continue, expect ransomware crews to keep narrowing their focus toward a smaller number of high-value, high-leverage targets rather than spraying attacks broadly, echoing the shift in defensive priorities discussed in our analysis of how vulnerability discovery is reshaping patch cycles.

Sources

Joe Manning
Written by
Joe Manning, Senior Editor
Share this article:
Advertisement