
Here is the strangest story in cybersecurity this year: ransomware has never been more active, and never less profitable. Attack volumes hit record highs through 2025, with the fourth quarter alone producing over 2,287 observed victims. Yet total ransom payments fell 8 percent to about $813 million, and the share of victims who pay dropped to a historic low of 29 percent. More attacks, less money. Researchers call it the great ransomware paradox, and understanding it is the key to defending against ransomware in 2026.
This is not the ransomware of five years ago. The big-brand syndicates have shattered into dozens of smaller crews, the business models have mutated, and artificial intelligence has lowered the bar for attackers while raising it for defenders. Here is how ransomware-as-a-service works now, who it targets, and the defenses that actually work.
Key takeaways
- The paradox: ransomware payments fell 8 percent to ~$813M in 2025 while victim counts surged to record highs; only 29 percent of victims now pay, down from ~70 percent in earlier years.
- Fragmentation: the era of mega-syndicates is over. Around 85 to 95 smaller RaaS crews now compete, with white-label services and closed-shop operations replacing the old affiliate marketplaces.
- Canada is the #2 target: after the US, Canada faces the most ransomware activity, with supply chains, logistics, and critical infrastructure hit hardest.
- Entry is boring, not brilliant: nearly half of attacks start with stolen credentials or exposed remote access (RDP, VPN), not zero-day exploits.
- What works: tested offline backups, MFA everywhere, patching internet-facing systems, segmentation, and a rehearsed incident response plan.
The paradox: more attacks, fewer payments
Chainalysis's 2026 crypto-crime reporting (published September 2026) lays out the split screen. On one side: victim counts on public leak sites surged to their highest levels ever, with 2025 the most active year on record. On the other: total payments to ransomware operators fell 8 percent to roughly $813 million, and the payment rate collapsed to 29 percent.
How can both be true? Because the two sides of the market moved in opposite directions. Defenders got better: backup resilience improved, incident response matured, and regulatory scrutiny made paying harder to justify. So fewer victims pay. But attackers got more numerous: the RaaS model keeps minting new crews, and each crew needs victims, so attack volume rises even as revenue per attack falls.
There is a sting in the tail, though. While fewer victims pay, those who do pay more: the median payment jumped 368 percent, from about $12,700 in 2024 to nearly $59,600 in 2025, as gangs squeeze paying victims harder with tactics like contacting victims' employees and customers directly. (Different trackers report different medians based on methodology; Verizon's DBIR puts 2025's median near $115,000, down from $150,000. The direction of travel in total payments is down in every dataset.) Total global ransomware damage is still projected at $74 billion for 2026. The decline in payments does not mean declining harm.
How ransomware-as-a-service works in 2026
RaaS is best understood as a franchise model for crime. Core developers build the ransomware payload, the leak site, the payment portal, and the negotiation chat system. Affiliates, the franchisees, break into victims and deploy the payload, then split the ransom with the developers. It industrialized cybercrime by letting people with modest technical skills run sophisticated extortion operations.
In 2026 that model is fragmenting under pressure. International law enforcement operations, including the 2024 Operation Cronos takedown of LockBit's infrastructure and later actions against BlackSuit and 8Base, did not kill ransomware but shattered trust in the big marketplaces. Three new patterns emerged:
The cartel model. Operations like DragonForce began white-labeling: trusted affiliates use DragonForce infrastructure but deploy payloads branded under different names, complicating attribution and dodging sanctions lists.
The closed shop. Groups like SafePay and Interlock eliminated the affiliate layer entirely, running lean in-house operations that keep full profit margins and reduce the risk of operational leaks.
The churn. When RansomHub, one of the most prolific RaaS brands, went dark in 2025, its affiliates scattered to rivals like Qilin and DragonForce. Akira, Qilin, and Medusa emerged as the most active operations, together linked to more than half of observed 2025 incidents. New strains appear constantly, affiliates switch platforms quickly, and attribution gets harder every quarter.
The net effect: instead of a few mega-syndicates, defenders now face 85-plus competing crews, many small, agile, and unpredictable. Ransomware has become a repeatable business process where playbooks matter more than innovation.

Who is getting hit
Manufacturing remains the most targeted sector, accounting for roughly 14 to 22 percent of attacks, followed by healthcare and construction, with government and financial services close behind. Manufacturing's exposure makes sense: operational technology environments are hard to patch, downtime is catastrophically expensive, and the pressure to pay is intense.
Small and mid-sized organizations face disproportionate risk. They hold valuable data and run essential operations but rarely have dedicated security teams, which makes them the sweet spot for affiliate crews working at volume.
Geographically, the United States is still the primary victim region by far. Canada ranks second, which should get every Canadian executive's attention: Chainalysis specifically flags high compromise rates in Canadian supply chains, logistics, and critical infrastructure. The Ontario courts breach was a vivid domestic example of public institutions in the crosshairs. Total economic damage keeps rising even as payments fall, because recovery costs, downtime, and notification expenses do not depend on whether the ransom gets paid. IBM's Cost of a Data Breach 2025 report puts the average ransomware breach at $5.08 million, with healthcare averaging $7.42 million per incident.
How attacks actually start
Forget the Hollywood image of a hooded genius finding a zero-day. Nearly half of ransomware intrusions begin with credential compromise or exposed remote access. The typical playbook:
- Initial access through exposed RDP or VPN appliances, phishing, or credentials bought from initial-access brokers (a market running about $14 million a year).
- Privilege escalation via Active Directory and identity infrastructure, often using remote monitoring and management (RMM) tools to blend in.
- Backup destruction, disabling or deleting backups and snapshots first to remove the free recovery path.
- Double extortion: exfiltrating sensitive data before encrypting, so victims face both downtime and the threat of public data exposure.
AI has now been bolted onto this pipeline: advanced crews use large language models to craft more persuasive phishing lures, automate lateral movement, and even handle ransom negotiations, adjusting demands based on analysis of stolen financial data. The barrier to running a convincing campaign keeps dropping.
Defenses that actually work
The encouraging news: the defenses that work are well understood, unglamorous, and within reach of mid-sized organizations. They are also the reason payment rates are collapsing.
Tested, offline, immutable backups. This is the single highest-leverage defense. Follow the 3-2-1 rule (three copies, two media types, one offsite or offline), make backups immutable so attackers cannot encrypt or delete them, and actually test restores. Backups you have never tested are a hope, not a plan.
Multi-factor authentication everywhere. Especially on VPN, RDP, email, and cloud admin consoles. Credential theft is the dominant entry method; MFA defeats most of it. Use app-based or hardware MFA, not SMS. A good password manager plus MFA closes the two most abused gaps at once.
Patch internet-facing systems fast. Exposed VPN appliances, firewalls, and remote-access tools are the first things ransomware crews scan for. Know what faces the internet and patch it on a ruthless schedule.
Segment your network. Micro-segmentation limits lateral movement so one compromised workstation does not become a domain-wide event. Separate IT from operational technology.
Endpoint detection and response (EDR). Modern EDR catches the behavioral patterns of ransomware deployment, including backup-tampering, even when the specific strain is new.
A rehearsed incident response plan. Write the plan, assign roles, keep offline contact lists and runbooks, and run tabletop exercises. The organizations that recover fastest are the ones that practiced.
Do not pay. Beyond the ethics, payment is a bad bet: complete recovery after payment is rare, and paying marks you as a payer. With solid backups, most organizations can rebuild without funding the next wave of attacks.

Practical next steps
This week:
- Confirm MFA is enforced on every remote-access path: VPN, RDP, email, cloud consoles.
- Verify your backups are offline or immutable, and schedule a test restore.
- Inventory internet-facing systems and patch anything exposed.
This quarter:
- Run a tabletop ransomware exercise with leadership, IT, legal, and communications in the room.
- Segment the network between IT and operational systems.
- Review who has domain admin rights and prune aggressively.
- Confirm cyber-insurance coverage terms around ransom payments and approved response vendors.
Ongoing:
- Monitor for exposed credentials and enforce unique passwords via a password manager.
- Track backup success rates as a KPI, not an IT checkbox.
- Brief the board annually: ransomware is a business-continuity risk, not just an IT problem.
The bottom line
Ransomware in 2026 is a volume business run by fragmented crews, and the economics are finally moving against the attackers: fewer victims pay, law enforcement keeps disrupting infrastructure, and the core defenses are well mapped. But attack volume is at record highs, Canada is the second most targeted country in the world, and the victims who do pay are being squeezed harder than ever. The strategy is not mysterious. Offline backups you have tested, MFA on everything facing the internet, fast patching, segmentation, and a plan you have rehearsed will defeat the vast majority of ransomware campaigns. The gangs are counting on you not doing the boring work. Prove them wrong.
Sources
- Infosecurity Magazine, "Ransomware Payments Decline 8% as Attacks Surge 50%": https://www.infosecurity-magazine.com/news/ransomware-payments-decline-1/
- Lyrie Research, "The Great Ransomware Paradox: Payments Are Collapsing While Attacks Are Exploding": https://lyrie.ai/research/research/ransomware-economics-paradox-payments-decline-attacks-surge-raas-fragmentation
- BitsFromBytes, "Ransomware Statistics 2026: Attacks, Costs and Trends": https://bitsfrombytes.com/ransomware-statistics-2026-complete-guide/
- Encryption Consulting, "Understanding RaaS And Preventing Ransomware Attacks": https://www.encryptionconsulting.com/understanding-raas-and-preventing-ransomware-attacks/
- IndiaMoneyWise, "Ransomware-as-a-Service Trends and Prevention Tactics": https://indiamoneywise.com/ransomware-as-a-service-trends-prevention-tactics/
Quick answers
Frequently asked questions
01
What is ransomware-as-a-service (RaaS)?
RaaS is a criminal business model where developers build ransomware tooling and infrastructure, then rent it to affiliate attackers who carry out intrusions and share the profits. It lets low-skilled criminals run sophisticated attacks, which is why around 95 ransomware gangs are now tracked, up 40 percent year over year.
02
Are ransomware attacks increasing in 2026?
Yes. The fourth quarter of 2025 was the most active quarter on record with over 2,287 observed victims, and 2025 was the most active year ever for public leak-site postings. Attack volume keeps rising even as ransom payments fall.
03
Are victims still paying ransoms?
Far fewer than before. Chainalysis found only 29 percent of victims paid in 2025, a historic low, and total payments fell 8 percent to about $813 million. Only 25 to 35 percent of victims pay today, down from around 70 percent in earlier years.
04
Which industries do ransomware gangs target most?
Manufacturing is the most targeted sector, followed by healthcare, construction, government, and financial services. Healthcare incidents are the most expensive, averaging $7.42 million per breach according to IBM.
05
How do ransomware attacks actually start?
Most begin with stolen credentials or exposed remote access, not exotic hacking. Common entry points are exposed RDP and VPN appliances, remote monitoring tools, phishing, and Active Directory compromise. Credential-based intrusions account for nearly half of initial access.
06
Should you pay the ransom if you are hit?
Security experts and law enforcement say no. Payment does not guarantee recovery, it funds future attacks, and paying a sanctioned entity can be illegal. With tested offline backups, most organizations can recover without paying, which is exactly why payment rates keep falling.
07
What is the single best defense against ransomware?
Tested offline backups. If you can restore quickly from backups attackers cannot reach or delete, ransomware loses its leverage. Combine that with multi-factor authentication everywhere and prompt patching of internet-facing systems.
08
Is Canada a major ransomware target?
Yes. Chainalysis ranks Canada the second most targeted country after the United States, with notably high compromise rates in supply chains, logistics, and critical infrastructure. The [Ontario courts cyberattack](/posts/ontario-courts-cyberattack-explained) showed public institutions are firmly in the crosshairs.



