A new report highlighted by Medical Economics found that only 29% of ransomware victims paid the ransom in the fourth quarter of last year. The headline framing is blunt: "just say no." The summary points to changing trends and better preparedness as the reasons payments are declining.
The trend of ransomware victims refusing to pay ransom is good news for defenders, but it comes with a catch. Declining payments do not mean declining attacks, and they do not mean stolen data stays private. Here is what the figure tells us, and what it leaves out.
Why only 29% of victims paid in Q4
The source article offers a short explanation: ransomware payments are falling because of shifting trends and improved preparedness. The report itself does not break down every reason, so it is worth being careful about what can be said with confidence.
In general, an organization pays a ransom for one of two reasons: to get its systems back, or to keep stolen data from being published. If a victim can restore from clean backups and has a rehearsed response plan, the first reason largely disappears. That is the most plausible reading of "better preparedness."
A 29% payment rate also means roughly seven in ten victims chose not to pay, or could not be pressured into it. That is a meaningful shift in leverage. Ransomware is a business model, and it depends on victims believing that paying is the fastest or only way out.
What is making extortion less effective
Several practical factors tend to weaken a ransomware group's hand. The report points broadly to preparedness, and these are the building blocks that usually sit behind that word:
- Reliable, tested backups. Backups that are kept separate from the main network and actually tested for restoration let a victim rebuild without a decryption key.
- Practiced incident response. Teams that have a plan can isolate affected systems quickly, which limits how much damage the attackers can do.
- Greater awareness. Paying offers no guarantee. Criminals may not deliver working decryption tools, and a payment can mark an organization as willing to pay again.
None of this makes a victim immune. The pressure on attackers is real, though. When fewer targets pay, groups have to attack more victims or find new ways to squeeze the ones they hit.
Why not paying doesn't end the data exposure
This is the part of the story that matters most for privacy. Many modern ransomware operations use double extortion: they steal data first, then encrypt systems. Even if a victim restores everything from backups and refuses to pay, the attackers still hold copies of the stolen files and can threaten to publish them.
That changes what "just say no" actually protects. Refusing to pay can keep a business running and avoid funding criminals. It does not retrieve data that has already left the network. The people most affected are often not the company but its customers, patients, and employees, whose personal information may end up on a leak site.
Real cases show how this plays out. In the Flink breach, where LPG Group demanded ransom from customers, the pressure was aimed at the people whose data was allegedly stolen, not just the company. Our explainer on the Settra ransomware group and its double-extortion data risk covers the same mechanics in more detail.
Attack volume also remains high. ThreatMon tracked 1,067 victims worldwide in the August 2026 ransomware wave, a reminder that a falling payment rate is not the same as fewer incidents.
What This Means For You
If you are an individual, your exposure usually comes through organizations that hold your data. You cannot control their backups, but you can limit the damage if their records leak. If you run a small business, you are in the group that benefits most from preparation, because a tested recovery plan is what turns "pay or lose everything" into a manageable outage.
The Akira ransomware victim breakdown is a useful reality check: no industry or company size is immune. Being small is not a shield.
What individuals and small businesses can do now
For individuals:
- Use unique passwords for every account, with a password manager, so a leaked credential in one breach does not unlock others.
- Turn on multi-factor authentication wherever it is offered.
- Be alert to phishing and extortion emails that reference real data about you. Criminals use leaked information to sound convincing.
- Share only the personal data a service truly needs.
For small businesses:
- Keep multiple backups, with at least one stored offline or isolated from your main network.
- Test restoring from those backups. An untested backup is a guess.
- Write down a simple incident response plan: who to call, which systems to isolate, and who talks to customers.
- Limit what data you store. Information you do not keep cannot be stolen and leaked.
- Plan for data theft, not only encryption, since refusing to pay does not undo a leak.
The bottom line
The drop to 29% shows that ransomware victims refusing to pay ransom is becoming more common, and that preparation is paying off. But the fight has shifted: attackers increasingly rely on the threat of publishing stolen data, and that threat survives even when the ransom goes unpaid.
Take time this week to review your own backup and data-protection habits, and make sure you understand how double extortion works. For real-world context, read about the Akira ransomware victim list and the August 2026 ransomware wave. Preparation will not stop every attack, but it makes saying no a realistic option.




