{"id":8414,"date":"2022-04-12T10:00:00","date_gmt":"2022-04-12T10:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-5026\/"},"modified":"2026-07-04T12:25:30","modified_gmt":"2026-07-04T12:25:30","slug":"why-90-percent-of-ransomware-victims-pay-the-ransom-and-why-thats-a-mistake","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2022\/04\/12\/why-90-percent-of-ransomware-victims-pay-the-ransom-and-why-thats-a-mistake\/","title":{"rendered":"Why 90 Percent of Ransomware Victims Pay the Ransom  &#8211;  and Why That\u2019s a Mistake"},"content":{"rendered":"<p><strong>The numbers are clear: Most ransomware victims pay up. Yet studies show just as clearly that those who pay are more likely to be attacked again, less likely to recover all their data, and face higher long-term costs. The economics of extortion only work as long as victims cooperate.<\/strong><\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li>Sophos study: 46 percent of those who paid did <em>not<\/em> recover all their data<\/li>\n<li>Repeat attacks on payers: 80 percent are attacked again (Cybereason)<\/li>\n<li>Average ransom demand in 2022: $812,000 (Sophos)<\/li>\n<li>BSI and FBI unanimously advise <em>against<\/em> paying<\/li>\n<\/ul>\n<h2>The Psychology of Payment<\/h2>\n<p>When the screen goes black and the countdown clock ticks, rational decision-making collapses. CEOs face triple pressure: operational disruption, reputational damage, and potential liability. In that moment, transferring Bitcoin feels like the fastest solution.<\/p>\n<p>That\u2019s exactly what attackers count on. Ransomware groups like LockBit or BlackCat run professional marketing operations: \u201ccustomer support,\u201d discounts for quick cooperation, and even warranty promises. This is a business model.<\/p>\n<h2>Why Paying Makes the Problem Worse<\/h2>\n<p>Cybereason data confirms it: 80 percent of companies that pay are attacked again  &#8211;  often by the same group. The logic is simple: Anyone who pays once signals both willingness to pay <em>and<\/em> inadequate defenses.<\/p>\n<p>Then there\u2019s the data problem. Sophos found that, even after payment, only an average of 61 percent of encrypted data could be restored. Corrupted databases, damaged backups, and tampered timestamps make full recovery the exception  &#8211;  not the rule.<\/p>\n<h2>The Alternative: Resilience Over Reaction<\/h2>\n<p>Companies with tested backup strategies and incident-response plans pay significantly less often. Success rests on three pillars: immutable backups (stored in write-protected form), regular restore testing, and a documented playbook for the first 60 minutes.<\/p>\n<p>Investing in prevention and resilience is measurably cheaper than a single ransom payment  &#8211;  and it shuts the door on repeat offenders.<\/p>\n<h2>Regulation Is Tightening<\/h2>\n<p>In the U.S., OFAC is considering sanctions against ransom payments to certain groups. The EU is weighing similar measures under NIS2. Companies that pay may soon face criminal liability  &#8211;  an added incentive to prioritize prevention.<\/p>\n<h2>Key Facts<\/h2>\n<p><strong>Payment rate:<\/strong> Over 50 percent of affected companies pay (Sophos 2022)<\/p>\n<p><strong>Recovery rate:<\/strong> Only 61 percent of data restored after payment<\/p>\n<p><strong>Costs without payment:<\/strong> Average $1.4 million  &#8211;  but with better recovery outcomes<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Should you <em>never<\/em> pay  &#8211;  under any circumstances?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The BSI and FBI recommend <em>never<\/em> paying. Exceptions <em>may<\/em> apply in life-threatening situations (e.g., hospitals)  &#8211;  but even then, law enforcement involvement is mandatory.<\/p>\n<\/details>\n<details>\n<summary><strong>Does cyber insurance cover ransom payments?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Many policies used to include ransom coverage. The trend, however, is moving toward explicit exclusions. AXA became the first major insurer to eliminate ransom coverage in France  &#8211;  in 2021.<\/p>\n<\/details>\n<details>\n<summary><strong>What should you do <em>instead<\/em> of paying?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Immediately: Isolate affected systems, engage forensic experts, file a police report. Medium-term: Verify backups, activate your communication plan, and  &#8211;  if required  &#8211;  report to the BSI under \u00a7 8b BSIG.<\/p>\n<\/details>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/06\/post_id-3837\/\">Cybersecurity Trends 2026: The 7 Developments Every Security Leader Must Know<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/18\/post_id-3523\/\">Ransomware 2026: Incident Response in the First 60 Minutes<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2025\/05\/15\/post_id-4958\/\">Why Your Cyber Insurance Won\u2019t Pay Out When It Matters Most  &#8211;  The Industry\u2019s Toxic Exclusion Clauses<\/a><\/li>\n<\/ul>\n<p style=\"font-weight:700;color:#e6e3da;font-size:1.05em;margin:48px 0 16px;\">More from the MBF Media Network<\/p>\n<div style=\"display:flex;flex-direction:column;gap:14px;margin-bottom:40px;\"><a href=\"https:\/\/www.cloudmagazin.com\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#0bb7fd;\">cloudmagazin<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Cloud Magazin<\/span><\/a><a href=\"https:\/\/www.mybusinessfuture.com\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#aa8ac2;\">MyBusinessFuture<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">MyBusinessFuture<\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#d65663;\">Digital Chiefs<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Digital Chiefs<\/span><\/a><\/div>\n","protected":false},"excerpt":{"rendered":"The numbers are clear: Most ransomware victims pay up. Yet studies show just as clearly that those who pay are more likely to be attacked again, less likely to recover all their data, and face higher long-term costs. The economics of extortion only work as long as victims cooperate. TL;DR Sophos study: 46 percent of [&hellip;]","protected":false},"author":55,"featured_media":5025,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"ransomware victims","_yoast_wpseo_title":"Why 90 Percent of Ransomware Victims Pay the Ransom - and Why That\u2019s a Mistake","_yoast_wpseo_metadesc":"Ransomware victims pay\u2014don\u2019t be one. Paying increases repeat attacks, lowers data recovery, and raises costs. Learn safer, smarter recovery strategies now.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-5026"],"footnotes":""},"categories":[259],"tags":[233],"class_list":["post-8414","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-strategie-governance-en","tag-ransomware"],"evm_reading_time_minutes":3,"wpml_language":"en","wpml_translation_of":5026,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8414","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=8414"}],"version-history":[{"count":5,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8414\/revisions"}],"predecessor-version":[{"id":19840,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8414\/revisions\/19840"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/5025"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=8414"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=8414"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=8414"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}