THREAT BRIEFING · 13.07.2026 DEENFRES

Strategy & Governance

Why 90 Percent of Ransomware Victims Pay the Ransom – and Why That’s a Mistake

By Tobias Massow · April 12, 2022 · 3 min read

The numbers are clear: Most ransomware victims pay up. Yet studies show just as clearly that those who pay are more likely to be attacked again, less likely to recover all their data, and face higher long-term costs. The economics of extortion only work as long as victims cooperate.

TL;DR

The Psychology of Payment

When the screen goes black and the countdown clock ticks, rational decision-making collapses. CEOs face triple pressure: operational disruption, reputational damage, and potential liability. In that moment, transferring Bitcoin feels like the fastest solution.

That’s exactly what attackers count on. Ransomware groups like LockBit or BlackCat run professional marketing operations: “customer support,” discounts for quick cooperation, and even warranty promises. This is a business model.

Why Paying Makes the Problem Worse

Cybereason data confirms it: 80 percent of companies that pay are attacked again – often by the same group. The logic is simple: Anyone who pays once signals both willingness to pay and inadequate defenses.

Then there’s the data problem. Sophos found that, even after payment, only an average of 61 percent of encrypted data could be restored. Corrupted databases, damaged backups, and tampered timestamps make full recovery the exception – not the rule.

The Alternative: Resilience Over Reaction

Companies with tested backup strategies and incident-response plans pay significantly less often. Success rests on three pillars: immutable backups (stored in write-protected form), regular restore testing, and a documented playbook for the first 60 minutes.

Investing in prevention and resilience is measurably cheaper than a single ransom payment – and it shuts the door on repeat offenders.

Regulation Is Tightening

In the U.S., OFAC is considering sanctions against ransom payments to certain groups. The EU is weighing similar measures under NIS2. Companies that pay may soon face criminal liability – an added incentive to prioritize prevention.

Key Facts

Payment rate: Over 50 percent of affected companies pay (Sophos 2022)

Recovery rate: Only 61 percent of data restored after payment

Costs without payment: Average $1.4 million – but with better recovery outcomes

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Should you never pay – under any circumstances?

The BSI and FBI recommend never paying. Exceptions may apply in life-threatening situations (e.g., hospitals) – but even then, law enforcement involvement is mandatory.

Does cyber insurance cover ransom payments?

Many policies used to include ransom coverage. The trend, however, is moving toward explicit exclusions. AXA became the first major insurer to eliminate ransom coverage in France – in 2021.

What should you do instead of paying?

Immediately: Isolate affected systems, engage forensic experts, file a police report. Medium-term: Verify backups, activate your communication plan, and – if required – report to the BSI under § 8b BSIG.

Related Articles

More from the MBF Media Network

cloudmagazinCloud MagazinMyBusinessFutureMyBusinessFutureDigital ChiefsDigital Chiefs

Further reading

News · July 2, 2026

When Attackers Are Faster Than the Patch

Between disclosure and exploitation of a vulnerability, only days often pass today. The State of Vulnerabilities Report 2026 reveals what matters now.

A magazine by Evernine Media GmbH