A Widening Gap Between Average and Median Ransom Payments

A new report on ransomware payment trends for Q2 2026 reveals a striking contradiction in the numbers. According to data published by Coveware by Veeam, the average ransom payment jumped 176% quarter over quarter to $1,880,612. At the same time, the median payment, which reflects what a typical victim actually pays, dropped by half to $150,000.

That divergence matters more than either number on its own. When the average rises sharply while the median falls, it usually signals that a small number of extreme outliers are skewing the overall picture. According to the report, this is exactly what happened: a handful of unusually large, or "lumpy," payments tied to extortion cases involving stolen data pushed the average far higher, even as most victims paid considerably less than in previous quarters.

For anyone tracking ransomware payment trends, this pattern is a reminder that headline averages can be misleading. The typical organization hit by ransomware in Q2 2026 was negotiating down to a much smaller figure than the eye-catching average suggests, but a small subset of victims, likely larger organizations or those facing especially damaging data exposure, paid dramatically more.

Why Data Exfiltration Is Driving the Biggest Payouts

The report points to data exfiltration as the primary driver behind the largest, most disruptive payments of the quarter. Rather than relying solely on encrypting files and demanding payment for a decryption key, many ransomware operators are now stealing sensitive data before deploying encryption, then threatening to leak or sell that information if the victim refuses to pay.

This dual-threat model, encrypt and exfiltrate, gives attackers more leverage. Even if a victim has solid backups and can restore encrypted systems without paying, the threat of a public data leak creates a separate, often more urgent, pressure point. Regulatory exposure, customer notification requirements, and reputational damage all factor into a victim's calculus once stolen data is on the table, and that appears to be exactly why certain payments in Q2 2026 ballooned into seven-figure territory.

This fits a broader pattern that other recent analyses have documented. As covered in Ransomware 2026: More Gangs, More Victims, No Slowdown, the ransomware ecosystem has become more fragmented, with a growing number of smaller operators competing for victims rather than a handful of dominant gangs controlling the field. That fragmentation, combined with a separate report showing victims doubling and extortion rising in Q2 2026, suggests attackers are casting a wider net while reserving their most aggressive, data-theft-driven tactics for targets where the payoff can be maximized.

What This Means For You

If you run a business, manage IT for an organization, or simply want to understand how ransomware payment trends affect your own risk, a few things stand out from the Q2 2026 data.

First, the median payment falling to $150,000 suggests that for most organizations, ransom demands (and what victims ultimately pay) may be trending lower, not higher. That's a modestly encouraging sign, and it likely reflects improved backup practices, faster incident response, and a growing willingness among victims to refuse payment when encryption alone is the threat.

Second, the surge in the average payment is a warning about what happens when data exfiltration is involved. If attackers can prove they've stolen sensitive customer records, financial data, or intellectual property, the pressure to pay increases substantially, regardless of whether encrypted systems can be restored from backup. This means data protection strategy can no longer focus solely on recovery. Preventing unauthorized data access and monitoring for unusual outbound data transfers matters just as much as maintaining clean backups.

Third, for everyday individuals, this trend is a reminder that a ransomware attack on a company you do business with, a hospital, a retailer, a service provider, carries privacy risk even if you never interact with the attackers directly. When exfiltrated data becomes the leverage point, your personal information stored by that organization is part of what's being held hostage.

Actionable Takeaways

Organizations should prioritize detecting data exfiltration attempts, not just ransomware encryption, since that's increasingly where the highest-value extortion leverage comes from. Reviewing data access controls, segmenting sensitive information, and monitoring for large or unusual data transfers can reduce exposure to the kind of lumpy, high-value payments driving Q2 2026's average upward.

For individuals, the takeaway is to stay alert to breach notifications from companies you interact with, since exfiltration-driven extortion means your data could be exposed even when a ransomware attack doesn't make headlines for encryption alone. Keeping tabs on ransomware payment trends isn't just an IT concern; it's increasingly a personal privacy issue worth watching.