69% of Ransomware Victims Refused to Pay Last Year — the Highest Rate Ever Recorded. Here's What Changed.


Good News What's Working
August 2026  ·  7 min read

Most of what this series covers is a warning. This one isn't. New research shows that more businesses said no to ransomware demands last year than at any point on record — and the reason isn't luck. It's preparation, catching up. Here's the record-breaking number, and a look back at every quiet win this series has documented this year that never made a scary headline.


Ransomware coverage tends to follow one shape: the number of attacks goes up, the story gets written, everyone feels a little worse about the internet. That shape is accurate as far as it goes — attacks are up. But it leaves out the half of the story where businesses are winning, quietly, in ways that don't make headlines because nothing dramatic happened. This post is about that half.

Verizon's newest global breach research, drawing on real incident data from the past year, found something worth sitting with: a record share of ransomware victims looked at the demand in front of them and said no.

69%

of ransomware victims refused to pay in 2025 — the highest refusal rate ever recorded, up from 65% the year before

This is a genuine, measured shift, not a survey of intentions. It describes what businesses actually did when the moment arrived — and the trend line has been climbing for several years running. Refusing to pay isn't free; it means leaning on backups, on incident response, on the hard work done beforehand. The fact that a growing majority can do that and walk away is the story.

The researchers behind the report were specific about why. The shift, in their words, doesn't come only from competition and crowding among attackers — it comes from what they called improved defensive adaptation. In plainer language: businesses got better prepared, and it changed the outcome of the fight. Not every fight. But more of them than at any point since anyone started counting.

65% → 69% the refusal rate's trajectory in just one year — a fast-moving trend, not a one-off blip Verizon 2026 Data Breach Investigations Report
median ransom payment fell year over year, even as attacks became more frequent — attackers are extracting less leverage per incident Verizon 2026 Data Breach Investigations Report
Preparation not luck, is the researchers' own explanation for the shift — tested backups and incident response plans changing the outcome Verizon 2026 Data Breach Investigations Report
To be honest about the other half of the picture: ransomware still showed up in nearly half of all breaches this year, and it isn't going away. This isn't a "problem solved" story. It's a "the fight is winnable, and more people are winning it" story — which is a meaningfully different and more useful thing to know than either extreme.

The quiet wins this series has already documented

Once you start looking for it, this year's coverage — most of it written as warnings — has actually been full of moments where preparation worked exactly as intended. None of these made a splashy headline, because a defense that works doesn't produce a victim. Here's the ledger, pulled from stories already told in this series.

Preparation winning, quietly, all year
A warning arrived hours before the attack, and it worked. When a widely used remote-access product came under active exploitation, a federal agency was able to alert exposed organisations in real time — hours before attackers reached them. The businesses that acted on that warning simply weren't there when the attack arrived. No breach. No story. Just a patched system and a quiet Tuesday.
A single habit defeats an entire category of AI fraud. Voice cloning technology can now convincingly fake a CEO's voice from three seconds of audio — and it doesn't matter. A callback-verification policy, calling the requester back on a known number before moving any money, stops the fraud cold regardless of how perfect the clone is. The defense doesn't need to keep pace with the technology. It already doesn't care how good the fake is.
Sometimes the attackers' own mistakes save the day. One ransomware operation's file-locking software turned out to be so poorly built that, in some cases, security researchers can reconstruct the encryption keys and hand victims their data back for free. Not every attacker is as competent as the warnings about them suggest.
Businesses using AI defensively are winning the same arms race attackers are trying to win offensively. Global research this year found organisations using AI and automation in their own security operations cut their breach costs by close to two million dollars on average. The same technology accelerating attacks is, in the right hands, one of the most effective tools for stopping them.
A plan that's never been used is still worth having. Businesses with a tested, documented incident response plan consistently recover faster and cheaper than those improvising in the moment — the single most repeated, most boring, most reliably true fact in cybersecurity research. It costs nothing but an afternoon, and it works every time someone actually needs it.
Look at what these five things have in common: not one of them required predicting the future or out-innovating an attacker. A callback policy. A tested backup. A plan written down before it was needed. None of it is exotic. All of it is available to a business with no security budget at all. The 69% figure isn't a story about better technology beating attackers at their own game. It's a story about ordinary preparation, done consistently, adding up.

Why this matters more, not less, for a small business

It would be easy to assume record refusal rates are a large-enterprise phenomenon — the kind of statistic driven by companies with dedicated security teams and seven-figure budgets. The research doesn't support that reading. The controls behind this shift are disproportionately the cheap, low-effort ones: backups that get tested, not just scheduled; a written plan that exists before the bad day, not improvised during it; a habit of verifying anything urgent by a second channel. None of that requires scale. It requires having done it.

That's the genuinely hopeful part of this story, and it's worth saying plainly: the businesses driving this record aren't necessarily the ones with the biggest budgets. They're the ones that did the unglamorous preparation — and a small business can do every item on that list for the cost of a few focused afternoons.

What this looks like in practice

If you've read this series for any length of time, none of the individual pieces here will be new. What might be new is seeing them add up. A tested backup, a written response plan, a callback rule for anything involving money, session revocation instead of just a password reset, knowing which of your systems face the internet — none of these are separate projects. They're the same handful of habits, showing up again in every single story this year, quietly working.

There's a useful reframe hiding in this data: preparation isn't insurance against a hypothetical. It's already changing outcomes, measurably, for a majority of businesses that faced the real thing last year. The 69% aren't the lucky ones. They're the prepared ones — and preparation is the one part of this entire threat landscape that's fully within a business's control, regardless of size or budget.
The Veriti Spottr CyberScore exists to make that preparation visible and trackable — turning the same handful of habits behind this year's record refusal rate into a clear, continuously updated picture of where your business actually stands. Not because the threats are going away. They're not. But because, for the first time on record, more than two in three businesses facing the real thing had done enough to say no — and there's no reason yours can't be one of them.

The short version

Ransomware attacks are up this year. So is the share of businesses that face one and walk away without paying — the highest ever recorded, and climbing. The difference between the two groups isn't luck, budget, or size. It's whether the boring preparation got done before the day it was needed. Every story in this series has, underneath the warning, been describing exactly what that preparation looks like. This is what it adds up to.

See exactly where your preparation stands today — free to start.

View the Threat Intelligence feed → Find Out More About Veriti Spottr →
VS
Veriti Spottr Team AI-powered cyber risk clarity for SMBs  ·  veritispottr.com

Comments

Popular posts from this blog

The Hidden Cost of Cybersecurity Inaction for Small Businesses

Small Business Ransomware Protection Guide (2026 Edition)

Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.