惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
N
Netflix TechBlog - Medium
宝玉的分享
宝玉的分享
Google DeepMind News
Google DeepMind News
腾讯CDC
G
Google Developers Blog
Martin Fowler
Martin Fowler
Microsoft Security Blog
Microsoft Security Blog
Recent Announcements
Recent Announcements
爱范儿
爱范儿
Engineering at Meta
Engineering at Meta
Microsoft Azure Blog
Microsoft Azure Blog
A
About on SuperTechFans
aimingoo的专栏
aimingoo的专栏
有赞技术团队
有赞技术团队
Jina AI
Jina AI
人人都是产品经理
人人都是产品经理
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
M
MIT News - Artificial intelligence
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
美团技术团队
WordPress大学
WordPress大学
阮一峰的网络日志
阮一峰的网络日志

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Ransomware Payments Decline 8% as Attacks Surge 50%
Phil Muncaster · 2026-03-02 · via www.infosecurity-magazine.com

Ransomware actors are extorting bigger payments from a smaller number of victims, as the number of those victims surges but overall revenues fall, according to Chainalysis.

The blockchain analytics firm revealed in its analysis of cryptocurrency payments to threat actors that the overall figure tumbled 8% year-on-year (YoY) to $820m in 2025.

Although the figure is likely to “approach or exceed” $900m as new events and payments are attributed over the coming months, it still represents the second consecutive year of overall decline, and sits somewhat below ransomware revenues for 2020 and 2021.

It also came as victim numbers surged by 50% YoY in 2025, making 2025 the most active year on record.

It reflects the fact that payment rates plummeted from 63% in 2024 to just 29% last year – the lowest on record.

Read more on ransomware: Record Number of Ransomware Victims and Groups in 2025.

“This overall trend is a major win against the ransomware ecosystem,” said Chainalysis in its report. “Fewer victim payments mean more work for less for attackers, an important step in shifting the economic incentives.”

The analytics firm pointed to four trends reflected in the data:

  • Fewer victims are paying, thanks to improved incident response and increased regulatory scrutiny
  • Global action against ransomware operators, infrastructure and laundering networks has helped to limit some revenue flows
  • Some strains like VolkLocker contain cryptographic weaknesses that allow free decryption in some cases
  • Marked fragmentation of ransomware-as-a-service (RaaS) operations means a surge in smaller, independent groups, which may number as many as 85 today

Turning Up the Heat

However, organizations that do give in to extortion in this new landscape may find that it’s costing them more. The median payment increased 368%, from $12,738 in 2024 to $59,556 in 2025.

Tactics such as contacting employees and customers of victimized organizations, and analyzing exfiltrated data to make more targeted threats may be helping to ramp up media payment further, Chainalysis said.

“Ransomware actors remain highly opportunistic,” the report warned. “They do not consistently favor a specific sector at a given time of year. Instead, they exploit exposed services and misconfigurations as they arise, and capitalize on newly disclosed vulnerabilities.”

The US was the most heavily targeted country last year, followed by Canada, Germany, the UK, and other parts of Europe. Manufacturing and finance/professional services were the most heavily hit in most of these countries, although Canada and Germany had a high compromise rate in supply chains, logistics and critical infrastructure.

Payments to initial access brokers (IABs) remained relatively flat from 2024, at $14m, but historically high.

The report also claimed that infrastructure such as bulletproof hosting, residential proxy networks, and malware loaders is now used by financially motivated cybercrime groups as well as state-linked threat actors conducting espionage and influence operations.

“As a result, dismantling or sanctioning infrastructure nodes can generate cascading effects across ransomware affiliates, scammers and state-aligned operators simultaneously,” the report noted.

“This convergence reinforces a core dynamic of the modern cyber-threat landscape: infrastructure is the strategic center of gravity. Disrupting it raises costs across the entire ecosystem – from extortion-driven syndicates to geopolitically motivated threat actors.”