In early 2024, a co-ordinated international law enforcement effort sought to dismantle the notorious ransomware group LockBit, which is considered one of the largest cyber-crime organisations to have ever existed.
The operation led to the seizure of LockBit’s leak site and multiple arrests, but the group’s activities persist. LockBit recently orchestrated a significant data leak at a US financial institution, demonstrating the group’s resilience despite efforts to shut it down.
The fact that LockBit carries on despite this high-profile, international law enforcement effort provides yet another illustration of the insidiousness, the relentlessness, and the stealthiness of ransomware.
The reason why is simple: It’s a lucrative business model. Total payouts surpassed $1 billion last year (around £786.9 billion). LockBit alone demanded a $50 million (£39.33m) ransom, while other notorious groups like REvil, Conti, BlackCat, and Phoenix have demanded $70 million (£55.07m), $20 million (£15.73m), $22 million (£17.30m), and $40 million (£31.47), respectively.
To better understand what today’s IT leaders think about this chaos, ExtraHop, a Network Detection and Response (NDR) firm, surveyed 1,100 IT and cybersecurity leaders to get their take on the ransomware epidemic.
Widespread Impact Across Sectors and Regions
Ransomware continues to affect organisations worldwide, regardless of size, industry, or geography.
The survey, which included responses from 1,100 IT and cybersecurity leaders, shows that 91% of organisations experienced ransomware incidents in the past year. Despite only 22% of respondents considering ransomware the biggest risk, the average paid for these kinds of cyber-incidents was an eyebrow-raising $2.5 million (£1.97m).
The survey also highlighted geographic differences in the perception of ransomware risk. Nearly half of German respondents identified ransomware as the biggest threat, compared to 26.69% in the UK and 20% in Singapore (rounding out the top three). The US and Singapore reported the highest average ransom payouts, with some US organisations paying over $25 million (£19.67m).
Global Ransomware Stats
A deeper dive into the survey data reveals that the frequency and financial impact of ransomware are escalating. The average number of ransomware incidents per organisation last year was alarmingly high. While only 22% of respondents deemed ransomware the biggest risk, 91% of those affected paid the ransom, with the average cost – as stated previously – reaching $2.5 million (£1.97m).
In terms of industry impact, the manufacturing, construction, and utilities sectors reported the highest concern, with 39.16% of respondents citing ransomware as a top risk. This was followed by retail (34.29%) and telecomms (21.5%).
Recommended reading
- UK Businesses Face New Cyber-attacks Every 44 Seconds in Q2 2024
- Half of Cybersecurity Professionals Expect to Burnout Within the Next Year
- Cyber Leaders Reveal Compliance and Boardroom Struggles
Other industries, including finance, technology, agriculture, education, government, and transportation, also reported notable levels of concern, though they were less likely to rank ransomware as the foremost risk to their operations.
As ransomware becomes more pervasive and costly, organisations are increasingly aware of the need for robust cybersecurity measures. The ExtraHop report recommends that companies understand their attack surfaces, train employees to recognise potential threats, and implement comprehensive resiliency plans to prepare for potential attacks.





