Ransomware attacks hit a record volume in 2025 while the money attackers actually collected fell. That is not a contradiction. It is the entire story, and most coverage of ransomware in 2026 is still telling last year's version of it.

This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.

The Volume Went Up. The Payout Went Down.

Chainalysis reported that claimed ransomware victims rose 50% year over year in 2025, the most active year on record by that measure. Over the same period, on-chain ransomware payments totaled roughly $820 million, an 8% decline from a revised 2024 figure of $892 million. The share of victims who actually paid fell to an all-time low of 28%. Coveware's independent tracking tells the same story from a different angle. Only 23% of victims made a ransom payment in its Q1 2026 data, down from 77% back in 2019.

Read those numbers together and the shape of the problem changes. This is not an industry where fewer criminals are attacking and collecting less. It is an industry running dramatically more attacks against a shrinking pool of victims willing to pay, and making up the difference in volume rather than in size. Attackers who used to run a smaller number of high-stakes operations against large targets are now running far more operations against a much wider set of victims, most of whom refuse.

Why the Median Victim Changed

The clearest evidence of that shift is in the median payment, not the average. Chainalysis found the median ransom payment jumped from $12,738 in 2024 to $59,556 in 2025, a 368% increase, even as the total dollar volume paid across the industry fell. Coveware's Q1 2026 data shows the median victim size rising 150%, to roughly 500 employees, with 66% of that quarter's attacks aimed at organizations with between 11 and 1,000 staff. Large enterprises still get hit and still pay large sums when they do. But the operators are increasingly optimizing for victims in the middle of the market, organizations small enough to lack a dedicated security team but large enough to have something worth paying to protect.

Coveware also found that 29% of Q1 2026 attacks targeted organizations that, in its words, cannot afford to go dark, hospitals, schools, and public services. Healthcare and consumer services combined accounted for 35% of all targeted organizations that quarter. That is a deliberate targeting strategy, not an accident of who happened to have vulnerable systems. An operator choosing between a large enterprise with a security operations center and a regional hospital system that cannot tolerate downtime is choosing the target more likely to pay quickly, even at a lower dollar amount.

The Ransomware Gang Model Is Fragmenting

The old mental model of ransomware, a handful of named groups running centralized operations, no longer matches how the ecosystem works. Chainalysis counted roughly 85 active extortion groups operating in 2025, up sharply as major ransomware-as-a-service brands fractured into smaller, more independent affiliate operations. Initial access broker pricing tells a related story. The average price for stolen network access fell from about $1,427 in early 2023 to $439 by the first quarter of 2026, a sign that automation and competition among criminal suppliers have made the raw material of a ransomware attack cheaper and easier to obtain than at any point in the tracking data.

Not every operator is fragmenting into irrelevance, though. Encryption-led groups such as Akira, Anubis, and Qilin are driving most of the payments that still happen, using operational disruption rather than data theft alone to give attackers a decisive edge in forcing a decision. Data-exfiltration-only groups, ShinyHunters among them, are struggling to generate comparable payment pressure without the operational disruption that encrypting production systems provides. At-Bay's 2026 claims data shows Akira alone responsible for more than 40% of all ransomware claims industry-wide in 2025, with 86% of those intrusions hitting organizations running SonicWall devices and two-thirds of the attacks launched at night or on weekends. Concentration and fragmentation are happening at the same time, at different layers of the ecosystem.

AI's Role Is Real but Still Small

Chainalysis documented ransomware groups experimenting with AI-driven negotiation interfaces starting in mid-2025, mirroring similar tooling already common in scam operations. The report is explicit that it could not quantify the financial impact of this experimentation. That distinction matters. AI is showing up inside ransomware operations in 2025 and 2026, but the honest current data does not support a claim that AI has meaningfully changed payment outcomes yet. The more measurable shift in the ecosystem, cheaper access brokering, fragmented affiliate structures, and volume-over-size targeting, has nothing to do with AI and everything to do with a criminal market adjusting to a shrinking pool of payers.

A Worked Scenario

A regional healthcare network with three hospitals and a dozen outpatient clinics was hit by an Akira affiliate in late 2025. The attack encrypted scheduling and pharmacy systems across two of the three hospitals. The organization had cyber insurance, a documented incident response plan, and internal pressure from clinical leadership to restore systems within hours rather than days, given the direct patient safety impact of a scheduling and pharmacy outage. The ransom demand came in at $2.1 million, well above the network's ability to justify paying under its own policy, but the operational pressure to restore quickly was severe enough that the network's board debated payment anyway before its incident response retainer restored core systems from backup within 36 hours, avoiding the need to decide. The attacker chose that target precisely because healthcare organizations face exactly this kind of pressure, and in this case the network's tested backup and restoration capability, not negotiation, is what kept the decision from being forced.

The Counterargument Worth Taking Seriously

Someone could reasonably argue the big game era is not actually over, pointing to the largest individual claims still on record, a $5 million policy-limit ransomware claim at At-Bay in 2025 and a Black Basta average demand of $4 million reported in earlier Coalition data. Large, catastrophic single events still happen, still make headlines, and still deserve genuine board attention, particularly for organizations that are plausible targets for that tier of attacker. Dismissing catastrophic risk because the aggregate trend favors volume attacks would be its own kind of misreading.

That argument is fair, and it does not actually contradict the volume story, it sits alongside it. The data shows both things happening at once. A small number of large, sophisticated operations still chase the biggest possible payout from the largest viable targets, while a much larger number of smaller, more automated operations chase reliable, faster payments from mid-market and essential-service targets. Preparing only for the catastrophic scenario while ignoring the much higher probability of the volume attack is the actual mistake, not the reverse.

Questions for Monday

Ask whether the organization's risk profile more closely resembles the catastrophic minority or the high-volume majority described in current claims data, and whether the security budget reflects that honestly. Ask how quickly production systems could realistically be restored from backup without paying, tested against a real restoration exercise rather than a written plan. Ask whether the incident response retainer accounts for after-hours attacks, given that two-thirds of Akira intrusions land at night or on weekends. These are questions leadership and the board should be asking this quarter, while the answer is still theoretical.

Ransomware did not get quieter in 2026. It got more efficient, and efficiency is a harder problem to defend against than headlines suggest.