Average Ransom Payment Spikes Even as Fewer Victims Pay
Ransomware economics took a strange turn last quarter. According to a new Q2 2026 report from Coveware by Veeam, the average ransom payment surged 176% from the previous quarter to $1,880,612. At the same time, the median payment, which reflects what a typical victim actually pays, fell by half to just $150,000.
That split matters. A rising average paired with a falling median usually signals that a small number of very large payouts are skewing the overall picture, while most organizations that do pay are handing over less than before. It's a pattern worth understanding if you run a business, manage IT infrastructure, or simply want to know where the threat landscape is heading.
Why the Average and Median Are Moving in Opposite Directions
Coveware's data suggests the widening gap between average and median payments is being driven by a handful of high-value cases, likely large enterprises or organizations with deep pockets, that paid enormous sums to resolve an attack. Meanwhile, the broader pool of victims who chose to pay did so at lower amounts than in prior quarters.
This divergence lines up with a broader shift the report highlights: data exfiltration is increasingly the primary leverage attackers use, rather than simply locking up files with encryption. When criminals threaten to leak stolen data publicly, especially data involving customers, employees, or regulated information, the pressure to pay can escalate quickly for organizations with the most to lose. Smaller businesses, by contrast, may be negotiating harder or relying more on backups and incident response plans to avoid paying large sums at all. Our earlier coverage of the same Q2 2026 ransomware payment data breaks down this contradiction in more detail, including how the split reflects changing attacker tactics.
Equally notable is that the overall payment rate, the share of victims who agreed to pay anything at all, dropped to one of the lowest levels Coveware has tracked. Fewer companies are giving in to ransom demands, even as the stakes for those that do pay have never been higher.
What's Driving Fewer Payments Despite Bigger Demands
Several factors likely contribute to this record-low payment rate. Organizations have spent years investing in backup systems, incident response planning, and network segmentation, all of which reduce the leverage attackers hold when encryption alone is the threat. If a company can restore its systems from clean backups within days, there's little incentive to pay a ransom just to unlock files.
But data exfiltration changes the calculus. Even with solid backups, a company facing the threat of leaked customer records, financial data, or intellectual property may feel it has no choice but to negotiate. This is likely why the payments that do occur are trending larger at the top end, even as fewer organizations overall are willing to pay.
The result is a ransomware ecosystem that's becoming more selective and more severe. Attackers appear to be adapting their targeting toward organizations where a leak would cause maximum reputational or regulatory damage, rather than casting a wide net and hoping smaller victims pay modest sums.
What This Means For You
If you're responsible for protecting an organization's data, this report is a reminder that ransomware defense can't stop at encryption prevention. Backups matter, but so does limiting what data attackers can access and exfiltrate in the first place. Segmenting sensitive information, encrypting data at rest, and monitoring for unusual outbound data transfers are all steps that reduce your exposure to the kind of extortion driving these record-high payments.
For everyday consumers, the takeaway is more indirect but still relevant. As ransom demands grow, so does the incentive for attackers to monetize stolen personal data, whether that's through direct sale, further extortion, or use in follow-on scams. If a company you do business with experiences a breach tied to a ransomware attack, assume your data could be part of what was exfiltrated, not just encrypted.
Actionable Takeaways
- Businesses should prioritize data minimization and access controls, since exfiltration, not just encryption, is now the primary ransom lever.
- Regularly test backup and recovery processes so operational disruption alone doesn't force a payment decision.
- Monitor accounts and credit activity closely if you're notified of a breach linked to a ransomware incident, since exfiltrated data often surfaces later.
- Treat unsolicited emails or calls referencing a known breach with skepticism, as leaked data frequently fuels targeted phishing.
The latest average ransom payment figures show an industry in flux: fewer victims paying overall, but those who do facing far steeper demands. Staying informed about these trends, and adjusting your own data protection habits accordingly, remains one of the most effective ways to avoid becoming part of next quarter's statistics.




