Originally reported by Infosecurity Magazine
TL;DR
Despite a 50% increase in ransomware attacks during 2025, total payments to criminals dropped 8% according to Chainalysis research. However, median ransom payment sizes increased significantly, suggesting threat actors are targeting fewer but higher-value victims.
Industry analysis showing mixed ransomware trends with overall payment decline but increased attack volume. Significant for threat landscape understanding but not an immediate actionable threat.
Chainalysis blockchain analysis reveals a paradoxical shift in the ransomware landscape during 2025: while attack volumes surged 50%, total payments to ransomware operators declined 8%. The cryptocurrency intelligence firm's latest findings indicate threat actors are adapting their strategies amid increased organizational resilience and law enforcement pressure.
The most striking trend identified by Chainalysis researchers is the significant increase in median ransomware payment sizes throughout 2025. This data suggests ransomware groups are pivoting toward targeting fewer, higher-value organizations rather than casting wide nets across smaller entities.
Several factors likely contribute to this strategic shift:
The divergence between attack frequency and payment success rates indicates that current defensive strategies are having measurable impact on ransomware economics. Organizations implementing comprehensive backup strategies, network segmentation, and incident response capabilities appear to be successfully disrupting the traditional ransomware business model.
However, the increase in median payment sizes suggests that when ransomware groups do succeed, they are extracting significantly higher values from their victims. This trend underscores the importance of preventing initial compromise rather than relying solely on post-incident recovery capabilities.
The Chainalysis data reflects a maturing threat landscape where both attackers and defenders are adapting their approaches. Ransomware operators are demonstrating increased sophistication in target selection and valuation, while organizations are showing improved resilience through better preparation and response capabilities.
This evolutionary pressure is likely to continue driving changes in ransomware tactics, techniques, and procedures throughout 2026, with groups potentially focusing even more heavily on high-value targets and developing new methods to bypass improved organizational defenses.
Originally reported by Infosecurity Magazine