69% of Ransomware Victims Refused to Pay Last Year — the Highest Rate Ever Recorded. Here's What Changed.
Most of what this series covers is a warning. This one isn't. New research shows that more businesses said no to ransomware demands last year than at any point on record — and the reason isn't luck. It's preparation, catching up. Here's the record-breaking number, and a look back at every quiet win this series has documented this year that never made a scary headline.
Ransomware coverage tends to follow one shape: the number of attacks goes up, the story gets written, everyone feels a little worse about the internet. That shape is accurate as far as it goes — attacks are up. But it leaves out the half of the story where businesses are winning, quietly, in ways that don't make headlines because nothing dramatic happened. This post is about that half.
Verizon's newest global breach research, drawing on real incident data from the past year, found something worth sitting with: a record share of ransomware victims looked at the demand in front of them and said no.
of ransomware victims refused to pay in 2025 — the highest refusal rate ever recorded, up from 65% the year before
This is a genuine, measured shift, not a survey of intentions. It describes what businesses actually did when the moment arrived — and the trend line has been climbing for several years running. Refusing to pay isn't free; it means leaning on backups, on incident response, on the hard work done beforehand. The fact that a growing majority can do that and walk away is the story.
The researchers behind the report were specific about why. The shift, in their words, doesn't come only from competition and crowding among attackers — it comes from what they called improved defensive adaptation. In plainer language: businesses got better prepared, and it changed the outcome of the fight. Not every fight. But more of them than at any point since anyone started counting.
The quiet wins this series has already documented
Once you start looking for it, this year's coverage — most of it written as warnings — has actually been full of moments where preparation worked exactly as intended. None of these made a splashy headline, because a defense that works doesn't produce a victim. Here's the ledger, pulled from stories already told in this series.
Why this matters more, not less, for a small business
It would be easy to assume record refusal rates are a large-enterprise phenomenon — the kind of statistic driven by companies with dedicated security teams and seven-figure budgets. The research doesn't support that reading. The controls behind this shift are disproportionately the cheap, low-effort ones: backups that get tested, not just scheduled; a written plan that exists before the bad day, not improvised during it; a habit of verifying anything urgent by a second channel. None of that requires scale. It requires having done it.
That's the genuinely hopeful part of this story, and it's worth saying plainly: the businesses driving this record aren't necessarily the ones with the biggest budgets. They're the ones that did the unglamorous preparation — and a small business can do every item on that list for the cost of a few focused afternoons.
What this looks like in practice
If you've read this series for any length of time, none of the individual pieces here will be new. What might be new is seeing them add up. A tested backup, a written response plan, a callback rule for anything involving money, session revocation instead of just a password reset, knowing which of your systems face the internet — none of these are separate projects. They're the same handful of habits, showing up again in every single story this year, quietly working.
The short version
Ransomware attacks are up this year. So is the share of businesses that face one and walk away without paying — the highest ever recorded, and climbing. The difference between the two groups isn't luck, budget, or size. It's whether the boring preparation got done before the day it was needed. Every story in this series has, underneath the warning, been describing exactly what that preparation looks like. This is what it adds up to.
See exactly where your preparation stands today — free to start.
View the Threat Intelligence feed → Find Out More About Veriti Spottr →📚 Credential Security Series → Read the full series

Comments
Post a Comment