Ransom Payments Jump 176% as Data Theft Replaces Encryption as the Main Threat

A new Q2 2026 report from Coveware by Veeam shows that the average ransom payment climbed 176% quarter over quarter, reaching $1.88 million. That's a dramatic jump, but the reason behind it is arguably more important than the number itself: a handful of large data exfiltration cases involving law firms and other organizations sitting on troves of sensitive information pushed the average sharply upward.

This isn't the old story of ransomware locking up computer systems until a company pays for a decryption key. Increasingly, attackers skip the encryption step entirely, steal the data, and threaten to publish or sell it unless they're paid. For organizations that hold confidential client files, medical records, or financial documents, that threat carries a different kind of weight than downtime alone. We've covered the broader numbers behind this shift in our look at how Q2 2026 ransom payments split between encryption and data-theft cases, and the trend lines are consistent: fewer victims are paying overall, but the ones who do are paying much more.

Why Law Firms and Data-Rich Organizations Are Prime Targets

Coveware's report points to law firms specifically as a driver of the quarter's biggest payouts. That makes sense when you consider what a law firm actually stores: privileged client communications, litigation strategy, merger and acquisition details, personal injury records, family law documents, and financial disclosures. This is exactly the kind of information that's devastating if leaked, and firms often have limited leverage to simply walk away from a ransom demand when client confidentiality obligations are on the line.

The same logic extends to any organization holding what Coveware describes as "highly sensitive" data: healthcare providers, financial services firms, HR platforms, and consumer-facing businesses that collect personal identifiers. Attackers have figured out that the threat of exposure, rather than the threat of downtime, is often the more effective lever. Encryption can be recovered from backups. A leaked client list or a batch of medical histories posted to a dark web forum cannot be un-published.

This shift also explains why average payments can spike even as the overall number of victims paying goes down. A small number of high-stakes, high-sensitivity cases can pull the average up dramatically, while the median organization facing a more routine attack is increasingly likely to refuse payment altogether, often because better backups and incident response planning give them other options.

What This Means For You

If you're a consumer, you're probably not paying a ransom yourself, but your data very likely lives inside the systems of organizations that could be targeted. Law firms, medical practices, insurers, and countless service providers hold your personal records, and a data exfiltration attack against any of them can expose your information regardless of whether they pay.

This is part of a broader pattern of privacy erosion driven by data breaches: information you never directly shared with an attacker ends up at risk because a third party you trusted was compromised. You can't control whether a law firm or clinic gets breached, but you can control how much you limit your exposure and how quickly you respond if you're notified. Being cautious about who you share sensitive documents with, asking service providers about their data retention and security practices, and monitoring for signs your information has surfaced in a breach are all reasonable, practical steps rather than paranoid overreactions.

Practical Steps If Your Data Is Caught in a Breach

If you receive a breach notification tied to a ransomware or data exfiltration incident, treat it seriously even if no financial account numbers were involved. Names, addresses, case details, or health information can be used for targeted phishing or identity theft long after the initial incident fades from headlines.

Start by freezing or monitoring your credit if financial or identity data was involved. Change passwords on any accounts tied to the breached organization, and enable multi-factor authentication wherever it's offered. Be skeptical of unexpected calls or emails referencing details from the breach, since attackers often use stolen information to make follow-up scams look convincing. And if you're evaluating professional services, whether legal, medical, or financial, it's reasonable to ask how they protect client data and whether they've had past incidents.

The Bottom Line

The 176% jump in average ransom payments isn't just a headline number. It reflects a real shift in how attackers extract value from breaches, moving from disruption toward exposure of sensitive personal and client data. Organizations that hold this kind of information, and the people whose data they're entrusted with, both face higher stakes than a simple system outage. Staying informed about how these attacks work, and taking basic precautions when your data is involved in a breach, remains the most effective way to limit the damage when the next incident makes headlines.