Ransomware crews launched more attacks than ever in the first half of 2026, but fewer victims are cutting checks. New data from Group-IB and Check Point Research, both published this year, show attack volume climbing quarter over quarter while the share of victims who actually pay has fallen to roughly 23%, a level neither firm has recorded before. The split marks one of the clearest breaks yet between how often ransomware gangs strike and how often that aggression actually converts into cash.

The numbers, first packaged together in a September 9, 2026 report from Tech Insider, pull from four independent trackers that each measure a different slice of the ransomware economy: leak-site posts, victim counts, negotiation caseloads, and blockchain payment flows. They tell a consistent story. Attacks are up. Payments are down. And the gap between those two lines is now the widest it has been since researchers started tracking ransomware payment behavior in 2019.

Ransomware Attacks Climb to 2,393 Incidents in Q1 2026

Group-IB’s “Ransomware in 2026: Same Business, New Rules” report counted 2,393 attacks posted to ransomware data leak sites in the first quarter of 2026, spread across 79 active groups. That figure is up 4.5% from the previous quarter, a modest but steady increase that Group-IB frames as evidence the ransomware-as-a-service model keeps recruiting new affiliates even as headline groups get disrupted or rebrand.

Seventy-nine active groups is a lot of competition for a criminal market. It means no single operator controls enough share to set terms the way LockBit or Conti once did at their peaks. Instead, smaller crews post victim names to leak sites, apply pressure through name-and-shame tactics, and hope enough targets fold before law enforcement or a rival gang takes their infrastructure down. The fragmentation shows up directly in the attack count: more groups posting more victims, even without any single group dominating headlines the way past leaders did.

That volume increase matters because it undercuts a common assumption that falling payment rates would eventually discourage attackers from bothering at all. So far in 2026, that has not happened. Attackers are running the same playbook more often, not less, even as their odds of getting paid drop.

Payment Rates Crash to a Six-Year Low of 23%

The payment side of the ledger is where the ransomware trends 2026 story gets sharper. Check Point Research puts the ransom payment rate at roughly 23% in the second quarter of 2026, calling it a multi-year low. Coveware’s own Q1 2026 report, “Inside the Economics of Cyber Extortion,” lands on the same 23% figure for that quarter, describing it as the end point of a decline that stretches back to 2019.

The two firms differ slightly on where that decline started. Coveware’s own report puts its 2019 baseline payment rate at 77%. Check Point, citing the same Coveware caseload data, states the 2019 figure at 85%. Both readings describe the same underlying trend, a six-year slide toward victims refusing to pay, but the discrepancy is worth flagging rather than smoothing over: even the firms tracking this space closely do not fully agree on where the curve began, only on where it has ended up.

Either starting point tells the same underlying story. Whether the drop ran from 77% to 23% or from 85% to 23%, victims have grown dramatically less willing to pay ransomware operators over a six-year stretch, and 2026 is where that decline has hit its floor so far.

Check Point’s Q2 Numbers: 2,139 Victims, Up 33% Year Over Year

Check Point Research’s own victim count, separate from Group-IB’s attack tally, recorded 2,139 victims posted to data leak sites in Q2 2026. Quarter over quarter, that is essentially flat, up just 0.8% from Q1. Year over year against 2025, though, it is up 33%, a much steeper climb that puts the current pace well above where the market sat a year earlier.

Reading Group-IB’s Q1 attack count against Check Point’s Q2 victim count side by side shows two trackers, measuring similar but not identical things, arriving at a similar conclusion from different angles: leak-site activity has plateaued quarter to quarter after a period of sharp growth, but it remains far above 2025 levels. The plateau is not a retreat. It is a market that has already ramped up and is now holding at an elevated baseline.

On-Chain Revenue Falls to $820 Million Despite More Attacks

Blockchain analytics firm Chainalysis offers the clearest evidence that attack volume and attacker revenue have decoupled. Chainalysis data cited in the original Tech Insider report puts total on-chain ransomware revenue at roughly $820 million for 2025, an 8% year-over-year decline. That is a smaller haul collected from a larger number of victims, which is exactly what a falling payment rate would predict.

The mismatch between rising attack counts and falling total revenue is the single most useful number in this entire dataset for understanding where the ransomware economy actually stands in 2026. It suggests the business model itself, not just enforcement pressure or victim resistance in isolation, is under strain. Gangs are working harder for less money, and the wallets receiving ransom payments are seeing thinner deposits even as the volume of attacks feeding into that pipeline grows.

Ransomware Data Snapshot: Q1 vs Q2 2026

Pulling the quarter-over-quarter figures into one table makes the divergence between attack volume and payment behavior easier to follow.

MetricQ1 2026Q2 2026Source
Leak-site attacks / victims2,393 attacks2,139 victimsGroup-IB (Q1), Check Point Research (Q2)
Active ransomware groups tracked79 groupsNot separately disclosedGroup-IB
Quarter-over-quarter change+4.5%+0.8%Group-IB (Q1), Check Point Research (Q2)
Year-over-year change (vs. 2025)Not separately disclosed+33%Check Point Research
Ransom payment rate~23%~23% (multi-year low)Coveware (Q1), Check Point Research (Q2)

Part of why ransomware statistics can look contradictory at first glance is that no two firms measure the same thing. Group-IB counts posts to leak sites. Check Point tracks victims listed on those same sites but runs its own independent count. Coveware works from its incident-response negotiation caseload, meaning real client engagements rather than public leak-site scraping. Chainalysis follows money movement on public blockchains. Sophos surveys IT and security teams directly about what happened to them. Each lens catches something the others miss, which is why cross-referencing all four, as this article does, gives a fuller picture than relying on any single tracker.

TrackerWhat It MeasuresKey 2026 FigureReport
Group-IBLeak-site posts across active RaaS groups2,393 attacks, 79 groups, Q1 2026, +4.5% QoQ“Ransomware in 2026: Same Business, New Rules”
Check Point ResearchVictims listed on data leak sites2,139 victims, Q2 2026, +33% YoYState of Ransomware Q2 2026
CovewareIncident-response negotiation caseload23% payment rate, Q1 2026“Inside the Economics of Cyber Extortion”
ChainalysisOn-chain wallet flows to known ransomware addresses~$820M total 2025 revenue, -8% YoYChainalysis blog
SophosDirect survey of IT and security teams$698K median demand (-65% over two years), $769K median paymentState of Ransomware 2026

Why Fewer Victims Are Paying Ransomware Gangs

A payment rate falling from the high-70s or mid-80s down to 23% over six years does not happen for one reason. Backup and recovery practices have matured across enterprise IT, cutting the leverage a working decryption key holds when a company can restore from an untouched backup instead. Cyber insurance underwriters have tightened terms and, in many cases, now push clients toward no-pay negotiation strategies rather than fast settlement. Law enforcement and government guidance in multiple jurisdictions has leaned harder against payment, and public sector victims in several countries now face legal or policy barriers to paying at all.

There is also a sanctions dimension. The U.S. Treasury’s Office of Foreign Assets Control has continued to designate ransomware operators and their infrastructure, which raises real legal exposure for any company that pays a sanctioned entity, knowingly or not. That risk alone has pushed some victims to walk away from negotiations they might otherwise have settled. Treasury keeps a running record of these sanctions actions publicly available, and it has become a standard reference point for incident-response counsel deciding whether a payment is even legally viable.

None of this means ransomware has stopped working as a business model. It means the model has gotten less reliable, and attackers are compensating by casting a wider net rather than extracting more from each individual victim.

What the Ransom Numbers Actually Look Like

Sophos’ 2026 State of Ransomware report adds texture to the payment-rate story with figures on the size of demands and payments themselves. According to the report, “The good news: Median ransom demand: $698,000, down 65% over two years.” That is a steep drop, and it lines up with the broader pattern of attackers extracting less value per victim even as they hit more targets.

The report also states, “The good news: Median ransom payment: $769,000, down from $1 million last year,” and adds that “51% of paying organizations negotiated a lower amount than the demand.” (Sophos, State of Ransomware 2026) Put together, victims who do pay are paying less, negotiating harder, and more often walking away with a discount than accepting the initial demand outright.

What Check Point and Sophos Are Saying

Check Point Research frames the decline in blunt terms, stating that “ransom payment rates fell to a multi year low near 23%, continuing a six year decline from 85% in 2019.” (Check Point Research, State of Ransomware Q2 2026) That framing matters because it treats 2026’s number not as an anomaly but as the latest data point in a trend that has been running consistently since before the pandemic-era ransomware boom.

Sophos’ report reinforces the same direction of travel from a victim-survey angle rather than a leak-site or negotiation-caseload angle, which is part of why the two datasets are useful read together. One tracks what attackers post publicly and how often victims fold in negotiation rooms. The other asks IT teams directly what they experienced. Both point toward the same conclusion: less money is changing hands per incident, and a shrinking minority of victims are willing to pay at all.

Historical Context: From an 85% Payment Rate to 23%

To understand how unusual a 23% payment rate is, it helps to look at where this market started. In 2019, ransomware was arguably at its most straightforwardly profitable point: backups were less consistently tested, cyber insurance was cheaper and less prescriptive about response strategy, and most victims defaulted to paying because it was, in the short term, the fastest way back online. Coveware’s caseload data from that period put the payment rate at either 77% or 85% depending on which citation of the figure you use, but both numbers describe a market where paying was the norm, not the exception.

Six years later, that norm has flipped. A rate below a quarter of victims paying means the majority of companies hit by ransomware in 2026 are choosing, or are being advised, to rebuild rather than negotiate. That is a fundamentally different calculation than the one victims were making in 2019, and it has forced ransomware operators to change strategy in response, leaning harder on double extortion (stealing data before encrypting it, then threatening to leak it regardless of whether the victim restores from backup) to preserve some leverage even when the encryption itself no longer guarantees a payout.

Ransomware Payment Rate Trend, 2019 to 2026

PeriodPayment RateSource
2019 (Coveware’s own baseline)77%Coveware, “Inside the Economics of Cyber Extortion”
2019 (as cited by Check Point)85%Check Point Research, citing Coveware data
Q1 202623%Coveware
Q2 2026~23% (multi-year low)Check Point Research
2025 on-chain revenue trend-8% YoY (~$820M total)Chainalysis, cited in Tech Insider’s report

Market Impact: Insurers, Vendors, and Enterprise Budgets

A falling payment rate reshapes incentives across the entire cyber-defense industry, not just for victims. Cyber insurance carriers benefit directly: fewer six- and seven-figure ransom payouts mean lower claims exposure, even as the number of incidents they have to respond to and investigate keeps climbing. That has already started showing up in how insurers underwrite policies, with more carriers requiring proof of tested backups, endpoint detection tooling, and incident-response retainers as a condition of coverage rather than optional add-ons.

For security vendors, the picture is more mixed. Backup and recovery vendors, along with incident-response and negotiation firms like Coveware, have a growing caseload to work through given rising attack counts, which supports demand for their services. But vendors whose pitch centers on preventing payment in the first place, rather than detecting or recovering from an attack, may find it harder to differentiate in a market where payment refusal has become the default behavior rather than a specialized capability.

Enterprise security budgets are likely to keep shifting toward recovery speed and data exfiltration prevention rather than pure ransomware negotiation, because the leverage attackers retain now runs almost entirely through stolen data and its threatened publication, not through withheld decryption keys.

Competitive Landscape: How Ransomware Groups Are Adapting

With 79 active groups competing for a shrinking pool of paying victims, per Group-IB’s Q1 2026 tally, ransomware-as-a-service operators are under pressure to differentiate. Some groups lean into faster encryption and shorter dwell time to reduce the odds of detection before damage is done. Others have shifted emphasis toward pure data theft and extortion without encryption at all, since exfiltrated data retains leak-site leverage even against a victim with perfect backups.

That fragmentation also makes takedown efforts harder to land cleanly. When one group’s infrastructure gets seized or its leaders indicted, affiliates scatter to competing platforms rather than the market model collapsing entirely, a pattern security researchers have observed repeatedly since the LockBit takedown efforts in prior years. The net effect is a market structure that looks less like a handful of dominant brands and more like a diffuse, resilient franchise system, which is consistent with what Group-IB describes when it frames 2026 as “same business, new rules.”

What Enterprises Should Take From This Going Into Q4 2026

For security teams building budgets and incident-response plans heading into the final quarter of 2026, the practical read of this data is straightforward. Attack volume is not going to fall on its own, so detection and response capacity should be sized for continued high frequency rather than a hoped-for decline. At the same time, a 23% payment rate confirms that refusing to pay is now a mainstream, defensible response rather than an outlier decision, provided the organization has backups solid enough to make refusal survivable.

The other practical takeaway is legal exposure around payment itself. With Treasury continuing to sanction ransomware infrastructure and operators, any organization still considering payment as a fallback option needs sanctions screening built into its incident-response plan before a crisis hits, not during one.

  • Payment rates will likely stay in the low-to-mid 20s through the rest of 2026 rather than rebounding, since the structural drivers behind the decline (mature backups, insurer requirements, sanctions risk) are not reversing.
  • Attack volume growth will probably keep outpacing payment growth, widening the gap between leak-site activity and actual ransomware revenue that Chainalysis has already documented for 2025.
  • Expect continued fragmentation among ransomware groups rather than consolidation, since no single operator has emerged with a market share large enough to dominate the 79-group field Group-IB tracked in Q1.
  • Data-theft-only extortion, without encryption, is likely to keep gaining ground as a tactic since it preserves leverage even against victims with strong backup practices.
  • Cyber insurers will likely keep tightening backup and detection requirements as a condition of coverage, reinforcing the very defensive practices that are driving payment rates down in the first place.

None of this means ransomware is a fading threat. Attack counts from Group-IB and Check Point both point the other direction, toward a market that is more active in 2026 than a year earlier. What has changed is the payoff. A criminal enterprise that once converted the vast majority of successful intrusions into six- or seven-figure payments now converts roughly one in four. That is still enough revenue, an estimated $820 million on-chain in 2025 per Chainalysis, to sustain 79 active groups. But it is a meaningfully worse business than the one that existed in 2019, and every data point in this year’s reporting suggests that trend is continuing rather than reversing.

For organizations building defenses, the resources available for staying current on this fast-moving threat include the No More Ransom project, which maintains free decryption tools for numerous ransomware families, and the FBI’s Internet Crime Complaint Center, which tracks and investigates reported incidents in the United States.

Frequently Asked Questions

What is the current ransomware payment rate in 2026?
Check Point Research and Coveware both report the ransom payment rate at roughly 23% in 2026, described as a multi-year low. Coveware’s Q1 2026 figure and Check Point’s Q2 2026 figure both land at approximately the same level.

How many ransomware attacks happened in 2026?
Group-IB counted 2,393 attacks posted to ransomware data leak sites in Q1 2026 across 79 active groups, a 4.5% increase from the prior quarter. Check Point Research separately counted 2,139 victims in Q2 2026, up 33% year over year.

Why are fewer ransomware victims paying?
Analysts point to more mature backup and recovery practices, stricter cyber insurance requirements, government guidance discouraging payment, and rising legal risk tied to paying sanctioned entities as the main drivers behind the six-year decline in payment rates.

How much money do ransomware gangs make?
Chainalysis data cited in reporting on this trend puts total on-chain ransomware revenue at roughly $820 million in 2025, an 8% decline from the prior year, despite a rise in the total number of attacks.

What was the ransomware payment rate in 2019?
Figures vary slightly by source. Coveware’s own report puts its 2019 baseline at 77%, while Check Point Research, citing the same underlying Coveware data, states the 2019 figure at 85%. Both describe the same six-year downward trend toward the current 23% rate.

How much are ransomware gangs demanding in 2026?
According to Sophos’ State of Ransomware 2026 report, the median ransom demand is $698,000, down 65% over two years, while the median amount actually paid is $769,000, down from $1 million the previous year.

Do most companies negotiate ransom demands down?
Sophos reports that 51% of organizations that did pay a ransom in 2026 negotiated a lower amount than the initial demand, suggesting negotiation has become a standard part of the response process rather than a rare tactic.

Are ransomware groups more or less organized in 2026 than in past years?
Group-IB’s tracking shows 79 distinct active groups in Q1 2026, indicating a fragmented rather than consolidated market. No single operator holds enough share to dominate the field the way earlier groups did at their peak, and reports describe this fragmentation as making full takedowns harder to sustain.