Key Highlights
- Ransomware attacks hit record highs in 2025, but total payments fell, forcing criminals to work harder for less.
- Big firms like Jaguar Land Rover faced billions in losses, while smaller companies also suffered major operational impacts.
- Law enforcement targeting hosting and access services raises costs, disrupting both criminal and state-linked cyber operations.
Ransomware attacks surged globally in 2025, yet total on-chain payments stagnated, signaling a shift in cybercrime economics. According to a Chainalysis’ Crypto Ransomware: 2026 Crypto Crime Report, cybercriminals received over $820 million in cryptocurrency payments, down 8% from 2024’s $892 million.
At the same time, reported ransomware attacks jumped 50%, making 2025 the busiest year on record. As per the report, although the number of attacks increased, the average ransom payment increased by 368% from approximately $12,700 in 2024 to nearly $60,000 in 2025. Large organizations suffered the most damage. For example, Jaguar Land Rover’s networks were attacked so severely that the cost of the attack resulted in production stoppage in several countries, amounting to approximately $2.5 billion.
The retail and healthcare sectors were not spared either. Marks & Spencer had prolonged operational downtime, while kidney dialysis firm DaVita had 2.7 million patient records leaked.
However, the data shows that stronger defenses, stricter regulations, and targeted disruptions are making it harder for attackers to get paid.
Fragmented threat landscape
Ransomware isn’t controlled by just a few big groups anymore. Chainalysis found at least 85 active extortion groups, many smaller and spread out. “Fewer large, headline-grabbing intrusions and more volume focused on small and medium enterprises. Smaller victims pay faster,” said Corsin Camichel, founder of eCrime.ch. Despite this shift, overall payments actually went down, showing that attackers now have to work harder for less money.
Besides the ransomware gangs, Initial Access Brokers (IABs) are becoming more important. They sell access to networks, letting ransomware groups strike more easily. In 2025, IABs earned at least $14 million in cryptocurrency, highlighting their key role in the cybercrime chain. Cybercrime prevention firm Darkweb IQ noted that AI tools and industrialized pipelines have made entry cheaper, though high-level access still commands a premium.
Infrastructure disruption drives change
Law enforcement has shifted focus to the backbone of ransomware operations, targeting services like bulletproof hosting and proxy networks. These moves make it more expensive and complicated for criminals and state-linked hackers to operate.
For example, Europol’s expanded Operation Endgame disrupted key malware loaders and servers used by multiple ransomware groups. Sanctions against companies like AEZA Group and Zservers show that authorities now go after the service providers that support attacks, not just the gangs themselves.
State-linked groups, including Iran’s Charming Kitten and Russian or Chinese actors, also rely on this same infrastructure. This overlap blurs the line between espionage and financial crime.
The widespread availability of hosting and anonymization services allows attackers to launch different campaigns while staying under the radar, but disruptions to these services now create significant hurdles for them.
In light of this, ransomware is still a serious threat, but falling payments and targeted disruptions of key infrastructure show the tide may be turning. Attackers now have to spend more effort for smaller rewards, suggesting the balance in cybercrime is slowly starting to shift.
Also Read: Fake Celebrity Profile Siphons ₹2.65 Crore in India’s New Crypto Scam
