Record-Low Ransom Payments Push Extortion Tactics Physical

Ransomware groups are having a harder time getting paid. New reporting shows that the share of victims who agree to pay a ransom has dropped to its lowest point on record, a trend that's reshaping how criminal groups pressure their targets. Rather than backing off, some of the largest remaining payouts are now tied to a single group aggressively targeting the legal sector, and other operators appear to be compensating for lower payment rates by escalating from digital coercion to threats that spill into the physical world.

This shift matters for anyone responsible for protecting an organization's data, because it means the old calculus of ransomware defense (backups, patching, endpoint protection) is no longer the whole story. Extortion is becoming a human problem as much as a technical one.

Why Ransom Payment Rates Are Hitting Record Lows

For years, ransomware groups could count on a predictable percentage of victims paying to get their data back or to prevent leaks. That math is breaking down. Payment rates have now fallen to a record low, according to the latest reporting, suggesting that organizations are increasingly willing to absorb the operational pain of an attack rather than fund the criminals behind it.

This tracks with broader shifts across the ransomware landscape. As covered in vpn.social's look at how the ransomware ecosystem fractures, the criminal underground itself is splintering into dozens of smaller, less coordinated groups. Fragmentation makes it harder for any single operator to build the kind of reputation and negotiating leverage that once encouraged victims to pay quickly. At the same time, high-profile settlements like the 23andMe $18M payout show that organizations are increasingly funneling money toward legal and regulatory resolution rather than directly rewarding attackers.

Interestingly, even as fewer victims pay, the payments that do go through can be enormous. A separate vpn.social report on Q2 2026 ransom payments found the average payment jumped 176% to $1.88 million in a single quarter, even as the overall percentage of paying victims declined. Fewer people are paying, but the ones who do are paying much more, often because the attackers behind those cases are applying unusually intense pressure.

How Extortion Is Turning Physical: Threats Beyond the Network

With fewer victims willing to pay simply to avoid a data leak, some extortion groups appear to be raising the stakes beyond the network itself. Instead of relying solely on encrypted files or the threat of publishing stolen data, these groups are reportedly turning to more direct forms of intimidation aimed at the people connected to a target organization, not just its systems.

This is a meaningful escalation. A ransomware negotiation used to be, at its core, a technical and financial decision: restore from backup, pay the ransom, or accept the data loss. When threats move into the physical realm, the decision-making shifts to an organization's security and legal teams, and potentially to law enforcement, in ways that firewalls and VPNs were never designed to address. It's a reminder that cybercriminal groups adapt their tactics based on what's working financially, and when digital leverage stops producing payouts, some are willing to look for other pressure points.

The Legal Sector's Outsized Exposure to Targeted Payouts

While payment rates overall are falling, the reporting notes that a disproportionate share of the large payouts still occurring can be traced back to one group focused specifically on the legal sector. Law firms are attractive targets for a reason: they hold sensitive client information, privileged communications, and case materials that can be professionally and legally devastating if exposed. That combination of high stakes and time-sensitive obligations can make legal organizations more likely to pay, even as the broader trend moves in the opposite direction.

This concentration also illustrates how ransomware has moved away from opportunistic, spray-and-pray attacks toward more deliberate targeting of industries where the cost of saying no is especially high.

What This Means for You

For most individuals, this trend won't translate into a direct threat, but it does underscore how much more sophisticated and targeted ransomware operations have become. If you work in a legal practice, a healthcare provider, or any organization that holds sensitive client or patient data, the risk calculus has changed. It's no longer just about whether your files get encrypted; it's about who might be threatened, contacted, or intimidated as part of an extortion attempt.

Reducing Risk in a Hybrid Cyber-Physical Threat Environment

Technical defenses still matter, but they're no longer sufficient on their own. Organizations should maintain tested, offline backups, enforce multi-factor authentication, and keep software patched. Just as important now is having a clear incident response plan that accounts for threats to employees, executives, or clients, not just to servers. As vpn.social has previously reported, double extortion tactics already showed that backups aren't enough to guarantee safety once data has been stolen; the emergence of physical intimidation tactics extends that lesson even further. Employees should be trained to recognize and report suspicious contact, and legal and security teams should coordinate in advance on how to handle threats that go beyond a ransom note.

Key Takeaways

  • Ransom payment rates have fallen to a record low, reducing the financial incentive for opportunistic attacks.
  • Some groups are compensating by escalating to physical threats, a tactic that VPNs and endpoint tools can't address alone.
  • The legal sector remains disproportionately exposed to large, targeted payouts.
  • Strong backups and network security remain essential, but organizations also need incident response plans that account for coercion aimed at people, not just data.

As ransomware economics shift, staying informed about how extortion tactics evolve is one of the most practical steps any organization can take to prepare.