Should you pay the ransom? What to weigh before deciding
It’s the question every ransomware victim faces under pressure. The honest answer is that paying is unreliable, risky and best avoided — and the best time to make that true is before an attack.
Fewer victims are paying, and the demands are falling with them
The first useful thing to know is that you would not be an outlier. Verizon’s 2026 Data Breach Investigations Report found that 69% of ransomware victims did not pay, up from 64% the year before, with a median amount paid of USD 139,875. Sophos, surveying 2,158 IT and cybersecurity leaders across 17 countries whose organisations were hit in the previous year, saw the same direction of travel: 48% of the organisations whose data was encrypted paid — the lowest rate in three years — while 66% recovered from backups.
The two reports measure different populations — the DBIR draws on incident data, Sophos surveys victims — so their median-paid figures are not comparable and should not be blended. What they agree on is the trend, and the demands are moving with it. In the Sophos data the median ransom demand fell to USD 698,000, continuing a multi-year decline from USD 1.3 million in the 2025 report and USD 2 million in the 2024 report; across those two years median demands are down 65% and payments down 62%. The median payment is now USD 769,000, from USD 1 million last year, and 48% of payments were USD 1 million or more, down from 52%.
What payment buys, and what it does not
| What people expect | What the data shows |
|---|---|
| "We’ll get our data back" | Recovery is near-universal, but rarely because of the payment: 66% of organisations whose data was encrypted restored from backups and 48% paid, and only 2% got no data back at all. Paying is one route to recovery, not the route. |
| "We’ll pay what they asked" | Across 507 organisations that disclosed both figures, the median payment was 90% of the demand (mean 85%): 51% paid less, 30% matched it and 18% paid more than the original ask. |
| "It’ll be cheaper than recovering" | The median payment was USD 769,000, and that sits on top of an average recovery cost of USD 1.7m excluding any ransom. |
| "The data won’t leak" | 16% of all ransomware attacks ended with data both encrypted and stolen. A decryption key does not retrieve the copy the actor already took. |
| "It ends the incident" | CISA’s response guide still has you hunt for dropper malware and evidence of a previous, unresolved compromise before rebuilding from backups. |
The negotiation, in numbers
Almost nobody writes down what actually happens between the demand and the transfer, so here it is. Of the 507 organisations that shared both their demand and their payment, the median settled at 90% of the initial ask: 51% paid less than the demand, 30% paid exactly what was demanded, and 18% paid more.
Leverage is unevenly distributed. The largest enterprises — USD 5 billion or more in revenue — negotiated best, with 57% paying below the demand and only 11% paying above it. Mid-sized organisations in the USD 50–250 million band did worst, with 25% paying more than the demand. The demand itself scales with what the attacker thinks a foothold is worth: 59% of demands from attacks that started with an exploited vulnerability on the firewall were for USD 1 million or more, against 48% of demands overall.
What none of that measures is where the leverage comes from. A negotiator argues from a position, and the position is whether you can walk away — decided by the state of your backups long before the demand arrives.
Check whether you need to pay at all
Before any commercial discussion, CISA’s #StopRansomware Guide — written with MS-ISAC, the NSA and the FBI — tells you to "consult federal law enforcement, even if mitigation actions are possible, regarding possible decryptors available, as security researchers may have discovered encryption flaws for some ransomware variants and released decryption or other types of tools". Free decryptors exist for a number of families. Checking costs a phone call.
The legal exposure, stated precisely
The clearest published position belongs to the US Treasury’s Office of Foreign Assets Control, in its Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments of 21 September 2021, which superseded its 1 October 2020 advisory. OFAC states that "the U.S. government strongly discourages all private companies and citizens from paying ransom or extortion demands and recommends focusing on strengthening defensive and resilience measures".
Three details matter operationally. First, the advisory reaches beyond the victim: companies that facilitate payments on a victim’s behalf, "including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response", may risk violating OFAC regulations. Second, "OFAC may impose civil penalties for sanctions violations based on strict liability" — not knowing who received the money is not a defence, and you rarely know at the time of payment. Third, OFAC names its mitigating factors: meaningful steps taken in advance to reduce extortion risk, including practices from CISA’s guidance, are "a significant mitigating factor", and a self-initiated, complete and timely report to law enforcement, with full cooperation during and after the attack, is treated as a voluntary self-disclosure and a significant mitigating factor in its own right.
Paying does not close the incident
A decryption key restores files. It does not remove the access that produced them. CISA warns that "a ransomware event may be evidence of a previous, unresolved network compromise" and names Bumblebee, Dridex, Emotet, QakBot and Anchor as precursor malware to look for. It is blunter still about the sequence: "Malicious actors often drop ransomware variants to obscure post-compromise activity. Care must be taken to identify such dropper malware before rebuilding from backups to prevent continuing compromises."
So the work after a payment is the same work as after a refusal: find the entry point, hunt for the dropper, rebuild on a clean network, and meet your reporting obligations. Payment buys you back one input to that process, at a price, from a counterparty with no obligation to deliver. The full sequence is set out in building a ransomware recovery plan that works under pressure.
The cost you are actually comparing against
The alternative is not "unlimited downtime". In the Sophos data the average recovery cost excluding any ransom is USD 1.7 million, up 11% on the year; 55% of organisations were fully recovered within a week, 16% within a day and 83% within a month, with only 3% taking longer than three months. Recovery is expensive and slow. It is also finite, priced in advance, and does not require a criminal counterparty to keep a promise.
Preparation is what makes "no" available
Notice what the numbers keep pointing at. Backup-based recovery surged to 66% of the attacks where data was encrypted, up from 54% — a rebound Sophos reads as renewed investment in backup infrastructure — while the share of victims paying fell to its lowest in three years. The two move together. The organisations that could say no had done the work beforehand.
- Keep offline or immutable backups and test the restore, against a stated recovery time.
- Rehearse the incident plan so the decision is made by prepared people, not panicking ones.
- Reduce the odds of a successful attack in the first place — malicious email and phishing are now half of all ransomware root causes.
- Report early: OFAC treats a self-initiated, timely and complete report to law enforcement as a significant mitigating factor, and it costs nothing to make.
Get those right and the question largely answers itself. What builds them is set out in the ransomware readiness checklist.
Sources
- The State of Ransomware 2026Demand and payment medians, the demand-versus-payment split, recovery cost and recovery time. Do not swap this for the assets.sophos.com asset ID ending 9brgj5n44hqvgsp5f5bqcps: that URL ignores its filename slug entirely and serves the 2025 edition whatever year you put in it.
- 2026 Data Breach Investigations ReportThe share of victims who did not pay, and the median amount paid. Verizon serves this edition from the /T10/ path; the plain /reports/ path returns a page shell rather than the PDF.
- Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware PaymentsStrict-liability civil penalty exposure, facilitator scope, and the mitigating factors.
- #StopRansomware GuideConsulting law enforcement about available decryptors, and identifying dropper malware before rebuilding.
- Directive (EU) 2022/2555 (NIS2 Directive)Article 23 reporting obligations, which apply regardless of any payment decision.
FAQ
Related questions
Is it illegal to pay a ransom?
It depends on the jurisdiction and on who receives the money. The US Treasury’s OFAC advisory of 21 September 2021 strongly discourages payment and warns that it "may impose civil penalties for sanctions violations based on strict liability" — so not knowing the recipient was sanctioned is not a defence. That advisory is explanatory and has no force of law, and it is US guidance; your own and your Member State’s obligations must be checked with counsel before any payment.
If we pay, will we get our data back?
Usually, but not because of the payment alone. Only 2% of organisations whose data was encrypted got nothing back — 66% restored from backups and 48% paid. Paying also does not undo exfiltration: 16% of ransomware attacks ended with data both encrypted and stolen.
What is the alternative to paying?
Recovering from tested offline backups, guided by a rehearsed incident-response plan, while closing the entry point the attackers used. Average recovery cost excluding any ransom was USD 1.7 million and 55% of victims were fully recovered within a week.
Do we have to report the incident even if we pay?
Payment does not remove reporting obligations. Under NIS2 Article 23(4), in-scope entities must submit an early warning within 24 hours and an incident notification within 72 hours, and Article 23(1) states that "the mere act of notification shall not subject the notifying entity to increased liability". OFAC separately treats a self-initiated, timely and complete report to law enforcement as a significant mitigating factor.
Keep reading
More guides
-
Ransomware readiness checklist: the controls that matter most
A prioritised checklist to prepare for ransomware — starting with the backups and access controls that decide whether you recover or pay.
Read guide -
Building a ransomware recovery plan that works under pressure
A recovery plan is what turns a ransomware crisis into a procedure. Here’s what belongs in one — and why rehearsal matters.
Read guide