Why 90 Percent of Ransomware Victims Pay the Ransom – and Why That’s a Mistake
The numbers are clear: Most ransomware victims pay up. Yet studies show just as clearly that those who pay are more likely to be attacked again, less likely to recover all their data, and face higher long-term costs. The economics of extortion only work as long as victims cooperate.
TL;DR
- Sophos study: 46 percent of those who paid did not recover all their data
- Repeat attacks on payers: 80 percent are attacked again (Cybereason)
- Average ransom demand in 2022: $812,000 (Sophos)
- BSI and FBI unanimously advise against paying
The Psychology of Payment
When the screen goes black and the countdown clock ticks, rational decision-making collapses. CEOs face triple pressure: operational disruption, reputational damage, and potential liability. In that moment, transferring Bitcoin feels like the fastest solution.
That’s exactly what attackers count on. Ransomware groups like LockBit or BlackCat run professional marketing operations: “customer support,” discounts for quick cooperation, and even warranty promises. This is a business model.
Why Paying Makes the Problem Worse
Cybereason data confirms it: 80 percent of companies that pay are attacked again – often by the same group. The logic is simple: Anyone who pays once signals both willingness to pay and inadequate defenses.
Then there’s the data problem. Sophos found that, even after payment, only an average of 61 percent of encrypted data could be restored. Corrupted databases, damaged backups, and tampered timestamps make full recovery the exception – not the rule.
The Alternative: Resilience Over Reaction
Companies with tested backup strategies and incident-response plans pay significantly less often. Success rests on three pillars: immutable backups (stored in write-protected form), regular restore testing, and a documented playbook for the first 60 minutes.
Investing in prevention and resilience is measurably cheaper than a single ransom payment – and it shuts the door on repeat offenders.
Regulation Is Tightening
In the U.S., OFAC is considering sanctions against ransom payments to certain groups. The EU is weighing similar measures under NIS2. Companies that pay may soon face criminal liability – an added incentive to prioritize prevention.
Key Facts
Payment rate: Over 50 percent of affected companies pay (Sophos 2022)
Recovery rate: Only 61 percent of data restored after payment
Costs without payment: Average $1.4 million – but with better recovery outcomes
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
Should you never pay – under any circumstances?
The BSI and FBI recommend never paying. Exceptions may apply in life-threatening situations (e.g., hospitals) – but even then, law enforcement involvement is mandatory.
Does cyber insurance cover ransom payments?
Many policies used to include ransom coverage. The trend, however, is moving toward explicit exclusions. AXA became the first major insurer to eliminate ransom coverage in France – in 2021.
What should you do instead of paying?
Immediately: Isolate affected systems, engage forensic experts, file a police report. Medium-term: Verify backups, activate your communication plan, and – if required – report to the BSI under § 8b BSIG.
Related Articles
- Cybersecurity Trends 2026: The 7 Developments Every Security Leader Must Know
- Ransomware 2026: Incident Response in the First 60 Minutes
- Why Your Cyber Insurance Won’t Pay Out When It Matters Most – The Industry’s Toxic Exclusion Clauses
More from the MBF Media Network