Ransomware attacks soar as hackers pivot to small businesses

2026-2-27 11:09

Ransomware activity accelerated sharply in 2025, but the money flowing to attackers moved in the opposite direction.

New research from Chainalysis shows that while the number of attacks jumped significantly, overall ransom payments declined.

The firm’s annual report, published on February 26, recorded nearly 8,000 public leak events in 2025.

That represents a 50% increase compared with 2024. Yet total on-chain ransom payments fell to $820 million, down 8% year on year.

The figures point to a structural shift in how ransomware groups operate and who they choose to target.

Source: Chainalysis

Small businesses under pressure

According to Chainalysis, attackers are increasingly turning their attention to small and medium-sized enterprises.

Heightened regulatory scrutiny, enforcement actions against laundering networks, and a broader refusal by large organisations to pay ransoms have changed the economics of high-profile attacks.

With major firms more resistant and law enforcement more active, criminals appear to be pursuing smaller targets that may lack robust cyber defences.

The report references comments from eCrime.ch founder Corsin Camichel, who noted that fewer large, headline-making breaches are being observed.

Instead, there is a higher volume focused on smaller victims.

However, Chainalysis data shows that despite record public claims of attacks, actual ransom payments are trending downward.

This gap between reported incidents and confirmed payments suggests attackers are facing diminishing returns.

Payments fall despite record claims

The nearly 8,000 leak events recorded in 2025 mark an all-time high.

Even so, the $820 million in on-chain payments signals a drop in overall revenue for ransomware operators.

Chainalysis attributes the decline to enforcement actions that have disrupted laundering infrastructure and made it harder for criminal groups to move funds.

At the same time, many large corporations and institutions are choosing not to pay, reducing incentives for attackers to stage major breaches.

As profitability narrows, ransomware activity appears to be shifting towards volume-based strategies rather than large individual payouts.

Cheap access and AI tools

The surge in attempted attacks is also linked to falling prices for victim access on dark web marketplaces.

Chainalysis found that the average price for victim access declined from $1,427 at the start of 2023 to $439 at the start of 2026.

An influx of low-cost ransomware strains, alongside AI integrations that streamline attack processes, has lowered the barrier to entry.

The report describes industrialised access pipelines, AI-assisted tooling, and a proliferation of infostealer logs.

This oversupply of inexpensive but operationally limited tools has flooded underground markets and pushed pricing lower, contributing to the rise in overall attack volume.

Crypto scams surge in early 2026

Although ransomware payments dipped in 2025, broader crypto-related crime remains active.

A recent report from cybersecurity company CertiK found that $370.3 million in crypto was stolen in January 2026 alone.

https://twitter.com/certikalert/status/2017568546747035835

Phishing scams accounted for $311.3 million of that total, representing the largest share of losses.

The data indicates that while ransomware revenue is under pressure, attackers are adapting.

The post Ransomware attacks soar as hackers pivot to small businesses appeared first on Invezz

origin »

Bitcoin price in Telegram @btc_price_every_hour

Heart Number (HTN) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.02 %, 7d: 0.00 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 2.216b HTN / 7.163b HTN

ransomware attacks shows new research chainalysis number

ransomware attacks → Результатов: 126


Фото:

Microsoft Warning – Hospitals Vulnerable to Bitcoin Ransomware

Microsoft has issued a chilling warning that many hospitals in the United States are at risk of bitcoin ransomware attacks right now amid the coronavirus pandemic. Bitcoin Ransomware Attackers Target Hospitals The giant software company said that “dozens” of hospitals are using vulnerable gateways and that this makes them easy targets for the REvil ransomware that is currently scanning the internet for these types of flaws.

2020-4-6 17:00


Фото:

Vicious malware threatens to turn search engine into crypto-mining zombie botnet

Enterprise search engine Elasticsearch is under threat of being turned into a sophisticated cryptocurrency mining botnet to be used in distributed denial of service (DDoS) attacks. Cybersecurity firm Trend Micro describes a new malware strain that launches multi-stage attacks on publicly accessible databases and servers that run old versions of Elasticsearch software.

2019-7-23 17:54


Ransomware Crooks Cashed Out $16 Million from Defunct Bitcoin Exchange: Google Research

By CCN: In the two years leading up to 2018, a spate of ransomware attacks were analyzed in a report by a team of researchers hailing mostly from leading U. S. universities and Google. Results showed a conservative estimate of total funds stolen to be $16 million, with bitcoin providing a way for malicious actors to take payment from anywhere in the world.

2019-5-9 11:50


Фото:

PayPal Wins Patent for Ransomware Detection Solution

Global payment processing platform PayPal has been awarded a patent for a technique that can help with the timely detection and reduction of ransomware attacks. Ransomware attacks are a form of malware that takes over the victim's computer, locks up the files therein and demands a ransom before the files can be accessed again — often to be paid in cryptocurrency.

2019-4-19 21:17


Фото:

Lazarus Hacker Group Continues to Target Crypto Using Faked Trading Software

This article was originally published by 8btc and written by Lylian Tang. The Chinese security service provider 360 Security has issued a warning that a large number of crypto exchanges have been targeted by the North Korean hacker group Lazarus and that the number is still rising after the recent hacks of crypto exchanges DragonEx, Etbox and BiKi.

2019-4-2 21:54


Here’s how personalized ransomware attacks work, and how to protect yourself

Once a piece of ransomware has got hold of your valuable information, there is very little you can do to get it back other than accede to the attacker’s demands. Ransomware, a type of malware that holds a computer to ransom, has become particularly prevalent in the past few years and virtually unbreakable encryption has made it an even more powerful force.

2019-3-28 19:54


IBM Data Says Cybercriminals Are Replacing Ransomware and Malware Attacks For Cryptojacking

Hackers are always trying to find the most profitable ways to steal money from people online. Because of this, their attacks evolve together with the technology. If hackers used to send emails with simple viruses attached to them before, now they are using a lot more methods, including using other people’s computers to mine crypto. […]

2019-2-28 05:19


Фото:

Coinbase Neutrino Acquisition Reveals History Of Spying and Gov’t Data Selling

Cryptocurrency exchange Coinbase is facing an increasing publicity nightmare after it emerged the CEO of a company it took over sold private user data to governments. Coinbase: Neutrino ‘Will Help Prevent Theft’ Announced February 19, Coinbase now owns Italian blockchain surveillance startup Neutrino, having acquired the company for an undisclosed sum.

2019-2-19 20:00


Фото:

Pirated Content and Software Drives Malicious Crypto Mining, Says New Report by Kaspersky Lab

Cryptocurrency mining malware attacks, which infected over five million people in the first three quarters of 2018 alone could be entering your systems via pirated software and content. Malicious cryptocurrency mining is the biggest threat to internet users in 2018, leaving behind ransomware which had been most prevalent over the last few years.

2018-11-30 15:59


Bitcoin Ransomware: The U.S. Indicts Iranians Over $6 Million Cryptocurrency Cyber-crimes

The U. S. Justice Department recently announced the indictment of two Iranians involved in a high-profile Bitcoin ransomware attack. Iranian Hackers Collect Bitcoin as Ransom According to a report by The Washington Post, the Justice Department of the United States on Wednesday (November 28) announced the indictment of two Iranian nationals involved in cryptocurrency ransomware attacks, […] The post Bitcoin Ransomware: The U.

2018-11-29 12:16