Ransomware victims should think twice before handing cash or crypto over to their attackers, with new research finding that only half of organisations that pay ransoms to cybercriminals actually recover their data.
Fresh research from CyberEdge Group’s 2025 Cyberthreat Defense Report has found that just 54% of ransom-paying victims recovered their data, down from 73% only two years ago.
The slightly better news is that successful ransomware attacks have declined over the period, now at 63% from a peak of 73% in 2023, while only 41% of targeted organisations chose to pay out last year, a drastic fall from 63% three years ago.
Ransom demands have also dropped, with attackers now fleecing firms for an average of $553,959 (£418,601), down from a peak of $850,700 (£642,835) in Q3 2023.
According to CyberEdge Group, ransomware victims are now refusing to capitulate to their attackers for a number of reasons, including having more reliable and attack-resistant backup and recovery methods, increasing doubts that ransomware gangs will honour their promises and decrypt stolen data, and a growing number of laws prohibiting ransom payments.
“Organisations are finally wising up,” said Steve Piper, founder and CEO of CyberEdge Group.
“They’re investing in resilience, improving backups, and refusing to reward cybercriminals. But for those still tempted to pay, this year’s results are a wake-up call: nearly half who paid got nothing in return. It’s like handing over a bag of cash and watching the crooks vanish.”
However, despite that, fears over ransomware remain high, with security professionals ranking it just behind malware and phishing attacks as their top concerns in 2025.
Recommended reading
- ‘Big Game’ Ransomware Tactics Drives Spike in Attacks
- Is Automation Fuelling a New Era of Cyber-crime?
- Phishing Attacks Spiked in 2024 As Other Cyber-threats Declined
According to the figures, these concerns might be largely fuelled by low security awareness among employees and a persistent shortage of skilled cybersecurity personnel, cited as the main barriers facing IT security teams.
Meanwhile, the security tech most firms plan to acquire this year includes next-generation firewalls, deception technology for endpoint security, bot management applications, and advanced security analytics, although AI tools will remain popular, with 84% of security pros preferring security gear powered by artificial intelligence.
Added to that, almost all (98%) plan to strengthen their identity security postures this year, with detecting and responding to identity-related threats at the top of the list.





