Logo uShield Cyber Security
Ransomware Incident Response Privacy

Nobody Pays Anymore: Ransomware's Pivot to Pure Extortion

by uShield staff August 18, 2026
Nobody Pays Anymore: Ransomware's Pivot to Pure Extortion

Ransomware payments plateaued in the low hundreds of millions even as reported attacks rose sharply. When encryption stops paying, the business model does not die — it changes shape.

Something genuinely encouraging happened to ransomware economics over the last several years, and the industry has been slow to explain what it means. Total blockchain payments to ransomware operations fell from roughly 1.25 billion dollars in 2023 to about 814 million in 2024, and stayed roughly flat near 820 million in 2025 — while the number of publicly reported attacks rose by close to half again over the same period. More attacks, less revenue. The share of victims paying has fallen to record lows, with quarterly reporting at times putting it near or below forty percent. Median demands sit around 1.3 million dollars, average recovery costs around 1.5 million, and roughly two thirds of organizations now refuse to pay.

Why Extortion Stopped Working

The decline has several causes and they reinforce each other. Backup and recovery discipline improved enough that restoring became a credible alternative to paying, which is exactly what a decade of immutable-backup advice was meant to achieve. Insurers tightened which incidents they would fund a payment for. Law enforcement disruption campaigns raised the operational cost of running a criminal enterprise, and sanctions exposure made facilitating payments legally hazardous for the advisers involved. Underneath all of it sits a lesson chief financial officers learned the hard way: paying does not buy a clean recovery. It buys a promise from a criminal, and frequently a second demand.

The Pivot: Steal, Threaten, Skip the Lock Icon

Criminal groups did not exit the market; they changed product. Pure data extortion removes the part of the operation with the worst risk-reward ratio — reliable encryption across heterogeneous environments, key management, and the decryption support process that generated so much friction and bad press. Instead the operator steals data, proves the theft with samples, and threatens publication or regulatory exposure. It is faster, cheaper, and requires no decryption infrastructure at all. Regulated sectors are the softest targets, because the cost of disclosure, notification, fines, and litigation can dwarf a ransom demand, which lets the attacker price high without ever touching production systems. A related evolution is the pursuit of third parties — processors, vendors, and service providers whose compromise yields leverage over many downstream victims at once.

Why Backups Are No Longer an Answer

This is the strategic consequence most organizations have not internalized. If the loss event is a leak rather than an outage, then a pristine, immutable, tested backup restores availability and leaves the actual problem completely untouched. The question an executive team must be able to answer changes from how fast can we recover to what did they take, and what does it cost us if it appears publicly. That shifts investment toward a different set of controls: data minimization, so that sensitive records do not accumulate beyond their operational need; classification, so you know what a leak would actually contain; and egress monitoring, because exfiltration requires volume moving somewhere unusual, and large transfers to unfamiliar cloud storage are detectable if anyone is watching.

Rehearse the Extortion Decision

  • Decide policy before the incident: Who has authority to refuse or engage, under what sanctions and legal constraints, and with what pre-agreed communication posture?
  • Assume the leak is the deadline: Disclosure clocks run on your schedule, not the attacker's, and the data may already be staged for release.
  • Preserve evidence deliberately: Extortion negotiations and data theft are investigations, and hasty remediation can destroy the trail.
  • Plan for customers, not just regulators: Notification obligations extend outward, and the leak's second-order cost is usually reputational.

Ransomware has not disappeared and backups remain essential; a locked-out business is still a business in crisis. But the loss model migrated from availability to confidentiality while most defensive narratives stayed behind. The industry spent a decade engineering for the padlock on the file. The extortionists moved to the folder that holds it.