Ransomware Statistics on Attacks and Recovery Costs
Ransomware statistics can describe complaints, affected organizations, encryption, ransom payments, or recovery work. Those measures belong to different stages of an event and often come from different populations. Combining them into one average “cost of ransomware” can hide the information a business needs most.
A recovery budget needs to distinguish direct reported losses from the work required to restore operations. A security review needs to distinguish attacks represented in a dataset from the probability that any particular company will be attacked. A survey of organizations already hit by ransomware cannot answer that probability question for all businesses.
The FBI’s complaint data and Sophos’s victim-conditioned survey provide useful but separate views. Keeping their definitions intact allows a business to discuss financial consequences without presenting an unsupported universal forecast.
Key Statistics and Data
The following figures should remain attached to their source populations and cost definitions.
- Reported complaints: The FBI’s 2025 IC3 report records 3,611 ransomware complaints and $32,320,105 in associated reported losses.
- Loss exclusions: IC3’s ransomware loss measure excludes costs such as downtime and remediation. It is not a complete recovery-cost total.
- Recovery survey: Sophos’s 2026 report gives mean recovery costs excluding ransom of $1,700,200 and a median of $375,000 among the relevant survey responses.
- Encryption: Sophos reports encryption in 56% of the surveyed ransomware-hit organizations. The survey population was already conditioned on experiencing ransomware, so this is not an attack rate across all companies.
Understand the Complaint-Based View
The FBI’s reported complaints and losses provide a defined record of submissions to IC3. The ransomware category contains 3,611 complaints and approximately $32.3 million in reported losses for 2025. Those figures should not be relabeled as every ransomware incident or all economic harm caused by ransomware.
The loss definition is particularly important. Downtime and remediation are excluded from this ransomware figure. A company restoring systems may incur substantial operational work that does not appear in this category under the report’s definition.
| IC3 Measure | 2025 Finding | Interpretation |
|---|---|---|
| Ransomware complaints | 3,611 | Complaints submitted under the report’s category |
| Associated reported losses | $32,320,105 | Reported loss measure with stated exclusions |
| Downtime and remediation | Excluded from this loss measure | Cannot be assumed to be included in the total |
Dividing the loss total by the complaint count would produce an arithmetic quotient, but it would not establish an average full recovery cost per organization. The unit is a complaint, the loss definition is narrower than total recovery, and the relationship between submissions and unique affected organizations must not be assumed.
Use the data to describe reported activity and its scope. When a finance team asks about broader reported cybercrime losses, keep each category’s definitions visible rather than treating all reported dollar amounts as equivalent measures of business interruption or restoration expense.
Read Recovery Costs as a Separate Survey Finding
Sophos’s recovery costs excluding ransom come from its 2026 ransomware study. Vanson Bourne surveyed 2,158 decision-makers in the first quarter of 2026 across 17 countries. The organizations had 100–5,000 employees and had experienced ransomware during the preceding 12 months.
The mean of $1,700,200 and median of $375,000 summarize the relevant recovery-cost responses. They describe different features of the distribution. The mean is sensitive to large values; the median identifies the middle response. Neither is a guarantee of what an individual organization will spend.
| Recovery Measure | Reported Value | Scope |
|---|---|---|
| Mean recovery cost excluding ransom | $1,700,200 | Relevant Sophos survey responses |
| Median recovery cost excluding ransom | $375,000 | Same reported cost measure |
| Encryption reported | 56% | Surveyed ransomware-hit organizations; separate question |
The encryption finding has its own question and denominator. It should not be used to estimate that 56% of all businesses suffered encryption. Nor should it be combined with a cost mean to manufacture an expected annual loss for every company.
Ransomware statistics become more useful when the study’s selection rule is stated plainly: these respondents represented organizations already hit by ransomware. The survey can describe their reported experiences. It cannot establish the prevalence of ransomware across the entire business population.
Do Not Add Unlike Cost Measures
A business can incur ransom-related payments, restoration costs, interruption losses, professional fees, and other consequences. Different reports include different combinations. Before adding or comparing figures, confirm that the categories are compatible and do not overlap.
The IC3 total and the Sophos recovery figures are not components of one dataset. They use different reporting channels, populations, units, and definitions. Adding the IC3 total to a survey mean would have no meaningful interpretation. Adding a ransom median from another source to a recovery mean would also mix incompatible summaries.
Verizon’s incident and breach counts provide another form of evidence. An incident, a confirmed disclosure, and a ransomware event need not be mutually exclusive descriptions. A single event can involve operational disruption and information exposure. The classification used by the source determines what a particular count means.
The wider sector and company-size comparisons should therefore remain context rather than a multiplier for a recovery estimate. A sector’s contributed event count does not supply a company-specific probability, and a revenue-band insurance median does not become a ransomware-only cost forecast.
For an internal model, define the cost categories yourself and document how they will be measured. Keep actual invoices, estimated interruption, internal labor, and unresolved amounts distinguishable. That creates a model the organization can update as evidence improves.
Build Recovery Scenarios Around Business Services
A practical recovery scenario begins with a business service rather than an industry average. Identify what must continue, what can pause, and which dependencies are required to restore the service. The result may involve systems, people, suppliers, credentials, and data that do not sit within one technical team.
For each service, establish a realistic restoration sequence. An application may depend on identity, network connectivity, a database, and an external integration. Restoring one component does not prove the service can resume useful work. The acceptance test should follow the business transaction through its dependencies.
Keep recovery assumptions separate from demonstrated capability. A documented backup policy does not establish that a usable recovery point can be restored within the required conditions. A recovery plan should be tested against the specific service and its access requirements.
The following categories support a structured scenario without supplying invented customer costs.
| Cost or Work Category | Evidence Needed |
|---|---|
| Technical restoration | Recovery tasks, dependencies, staffing, and tested restoration evidence |
| Operational interruption | Affected process, duration assumptions, and business-owner estimate |
| External support | Relevant scope, rates, activation conditions, and contractual coverage |
| Retained or temporary systems | Required services and the period they must remain available |
| Internal effort | Roles, time basis, and work displaced during recovery |
| Unresolved exposure | Known uncertainties, responsible owner, and next review point |
This scenario is a planning tool, not a prediction. Its value comes from showing which assumptions drive the decision and which capabilities the organization can demonstrate.
Evaluate Prevention and Recovery Spending Separately
Prevention, detection, containment, and recovery address different parts of the problem. A purchase that improves one area should not be credited with resolving all of them. Ask what specific action the investment enables and how the team will verify it.
Endpoint consolidation illustrates the distinction. A review of CrowdStrike consolidation costs should connect the proposed capabilities to the existing estate, the tools that can genuinely be retired, and the operational tests that justify retirement. A broader platform purchase does not automatically remove migration, overlap, support, or recovery responsibilities.
For a recovery investment, define the evidence of success before approval. That may include restoration of a representative service, confirmation of required dependencies, and a documented handoff between technical and business owners. The test should reflect the intended operating condition rather than a simplified demonstration with key dependencies omitted.
Avoid using a published cost mean as the sole justification for a specific product. The fact that ransomware recovery can be expensive does not establish that a quoted package produces a particular reduction in loss. A defensible proposal explains the control gap, the capability to be delivered, and the acceptance evidence.
Ransomware statistics can explain the significance of the problem. The spending decision still requires a concrete connection between the proposed work and the organization’s own services.
Prepare the Decision Record Before an Event
During disruption, teams need clear ownership and usable information. A recovery decision record should identify service owners, escalation routes, relevant contracts, and the evidence needed to authorize restoration or a temporary operating arrangement.
Keep the financial record usable as well. Distinguish paid amounts from estimates and potential future costs. Record the period and category for each item so that later reporting does not combine overlapping figures. This is especially important when multiple departments incur costs under different account codes.
Review the record through an exercise. Ask whether the team can find the required information, contact the relevant owners, and explain the restoration sequence. An exercise can reveal missing dependencies and unclear authority without requiring a claim that it reproduces every condition of a real event.
After the exercise, assign the unresolved issues. A list of lessons is not a completed improvement plan until each important gap has an owner, an expected action, and evidence that the action works. Keep accepted limitations visible so they are not mistaken for resolved controls.
Use the Evidence to Improve Readiness
The most useful ransomware statistics preserve the difference between reported complaints and surveyed recovery experiences. The IC3 figure is a complaint-based loss measure with exclusions. The Sophos figures describe a selected population of ransomware-hit organizations and separate survey questions.
Those sources support a serious discussion about readiness, but they do not supply a universal probability or cost forecast. Build the next decision around a critical service, its recovery dependencies, and the evidence that the organization can restore it.
That produces a practical outcome: a clearer recovery plan, a more honest cost model, and a spending proposal tied to demonstrated gaps. The value lies in what the organization can do with the evidence, not in choosing the largest number available.
A recovery exercise can make the financial assumptions more concrete. Select a service and ask the business owner what work can continue manually, what must stop, and which backlog will remain after systems return. The technical team can then explain the restoration sequence and the dependencies that may delay useful service. Finance can distinguish the direct restoration work from interruption estimates and later cleanup.
Record where the teams disagree. A system may be technically available before users can complete the business transaction, and a restored service may still need reconciliation of work performed during the interruption. Those gaps belong in the scenario. Resolving them produces a more useful planning input than adopting a survey average without examining what recovery means for the organization.
Keep the review focused on a decision that can change. A useful action has an accountable owner, a defined completion condition, and evidence that the intended behavior works. Revisit the result when the service or measurement scope changes, rather than treating the first review as permanent assurance.
Frequently Asked Questions
These answers separate complaint-based losses from surveyed recovery experiences.
Why Is the IC3 Loss Figure Lower Than Broader Recovery Estimates?
The measures have different definitions and populations. IC3’s ransomware loss figure excludes downtime and remediation, while the Sophos study asks affected organizations about recovery costs excluding ransom. They are not competing estimates of the same total.
Is the Mean Recovery Cost the Best Budget Assumption?
Not by itself. The mean and median describe survey responses, not your organization’s dependencies or recovery requirements. Build a scenario from critical services and explicit cost categories, then use the survey as context for reviewing the assumptions.
Does the Encryption Percentage Describe All Businesses?
No. The cited Sophos survey included organizations that had experienced ransomware. Its encryption finding describes that selected population under the relevant question. It should not be presented as the share of all companies experiencing encryption.
Can Different Reports Be Combined Into One Risk Score?
Only with a defensible model and compatible inputs. The figures here do not provide those conditions. Complaint counts, victim-conditioned survey results, and contributed incident data should remain separate unless their populations, units, and relationships are explicitly reconciled.
Resources
The FBI’s 2025 IC3 Annual Report supplies the complaint and loss figures. Sophos’s State of Ransomware 2026 supplies the survey method and recovery findings, including the relevant material on pages 12, 22, and 26. Verizon’s 2026 DBIR executive summary supplies event-definition context.
