The sixth annual Sophos State of Ransomware report offers contemporary insights into the components that led organizations to fall sufferer to ransomware and the human and enterprise impacts of an assault.
Based mostly on insights from a vendor-agnostic survey of three,400 IT and cybersecurity leaders throughout 17 nations whose organizations had been hit by ransomware within the final yr, the report combines year-on-year insights with model new areas of research, together with why ransom funds not often match the preliminary demand, and the downstream influence of ransomware incidents on in-house groups.
Obtain the report to get the complete findings and browse on for a style of a number of the matters coated.
Why organizations fall sufferer to ransomware
It’s not often a single challenge that leaves organizations uncovered to ransomware; moderately a mixture of technological and operational components contributes to organizations falling sufferer to assault.
Technical root causes
For the third yr operating, victims recognized exploited vulnerabilities as the most typical root explanation for ransomware incidents, used to penetrate organizations in 32% of assaults total. This discovering highlights the significance of figuring out and patching safety gaps earlier than adversaries can benefit from them.
Compromised credentials stay the second most typical perceived assault vector, though the share of assaults that used this method dropped from 29% in 2024 to 23% in 2025. E mail stays a significant vector of assault, whether or not by malicious emails (19%) or phishing (18%).
Learn the complete report for insights into how assault vectors range based mostly on group measurement.
Operational root causes
For the primary time, this yr’s report explores the organizational components that left firms uncovered to assaults. The findings reveal that victims are sometimes dealing with a number of operational challenges, with respondents citing 2.7 components, on common, that contributed to them being hit by ransomware.
General, there isn’t a single stand-out supply, with the operational causes very evenly cut up throughout safety points, resourcing points, and safety gaps.
Obtain the complete report for a deeper dive, together with insights into the person components behind these numbers, in addition to a breakdown of operational challenges by firm measurement and business sector.
Restoration of encrypted information
The excellent news is that 97% of organizations that had information encrypted had been capable of get better it. Much less encouraging is that information restoration by backups is at its lowest price in six years.
Slightly below half (49%) paid the ransom and bought their information again. Whereas this represents a small discount from final yr’s 56%, it stays the second highest price of ransom funds within the final six years.
Learn the report to study extra about each information encryption charges and information restoration.
Ransoms: Calls for and funds
There’s excellent news on this entrance: each preliminary ransom calls for and precise ransom funds dropped during the last yr – largely pushed by a discount within the share of calls for/funds of $5 million or extra. Whereas encouraging, it’s vital to take into account that 57% of ransom calls for and 52% of funds had been for $1 million or extra.
826 organizations that paid the ransom shared each the preliminary demand and their precise cost, revealing that they paid, on common, 85% of the preliminary ransom demand. General, 53% paid lower than the preliminary ask, 18% paid extra, and 29% matched the preliminary demand.
Learn the complete report to study extra, embody particulars of why some organizations pay greater than the demand and others are capable of pay much less.
The enterprise and human penalties of ransomware
The info reveals that organizations are getting higher at responding to assaults, reporting decrease prices and sooner restoration.
The typical (imply) value to get better from a ransomware assault (excluding any ransom cost) dropped by 44% during the last yr, coming in at $1.53 million, down from $2.73 million in 2024. On the similar time, over half of victims (53%) had been recovered inside every week, a big bounce from the 35% reported in 2024.
Having information encrypted in a ransomware assault has vital repercussions for the IT/cybersecurity crew, with all respondents saying their crew has been impacted indirectly.
Learn the report
Obtain the report to get the complete findings along with suggestions on easy methods to elevate your ransomware defenses based mostly on the learnings from 3,400 organizations that fell sufferer within the final yr. To study extra about how Sophos MDR and Sophos Endpoint Safety ship world-leading ransomware safety, go to our web site or converse together with your Sophos adviser.