Ransomware attacks soar as hackers pivot to small businesses

2026-2-27 11:09

Ransomware activity accelerated sharply in 2025, but the money flowing to attackers moved in the opposite direction.

New research from Chainalysis shows that while the number of attacks jumped significantly, overall ransom payments declined.

The firm’s annual report, published on February 26, recorded nearly 8,000 public leak events in 2025.

That represents a 50% increase compared with 2024. Yet total on-chain ransom payments fell to $820 million, down 8% year on year.

The figures point to a structural shift in how ransomware groups operate and who they choose to target.

Source: Chainalysis

Small businesses under pressure

According to Chainalysis, attackers are increasingly turning their attention to small and medium-sized enterprises.

Heightened regulatory scrutiny, enforcement actions against laundering networks, and a broader refusal by large organisations to pay ransoms have changed the economics of high-profile attacks.

With major firms more resistant and law enforcement more active, criminals appear to be pursuing smaller targets that may lack robust cyber defences.

The report references comments from eCrime.ch founder Corsin Camichel, who noted that fewer large, headline-making breaches are being observed.

Instead, there is a higher volume focused on smaller victims.

However, Chainalysis data shows that despite record public claims of attacks, actual ransom payments are trending downward.

This gap between reported incidents and confirmed payments suggests attackers are facing diminishing returns.

Payments fall despite record claims

The nearly 8,000 leak events recorded in 2025 mark an all-time high.

Even so, the $820 million in on-chain payments signals a drop in overall revenue for ransomware operators.

Chainalysis attributes the decline to enforcement actions that have disrupted laundering infrastructure and made it harder for criminal groups to move funds.

At the same time, many large corporations and institutions are choosing not to pay, reducing incentives for attackers to stage major breaches.

As profitability narrows, ransomware activity appears to be shifting towards volume-based strategies rather than large individual payouts.

Cheap access and AI tools

The surge in attempted attacks is also linked to falling prices for victim access on dark web marketplaces.

Chainalysis found that the average price for victim access declined from $1,427 at the start of 2023 to $439 at the start of 2026.

An influx of low-cost ransomware strains, alongside AI integrations that streamline attack processes, has lowered the barrier to entry.

The report describes industrialised access pipelines, AI-assisted tooling, and a proliferation of infostealer logs.

This oversupply of inexpensive but operationally limited tools has flooded underground markets and pushed pricing lower, contributing to the rise in overall attack volume.

Crypto scams surge in early 2026

Although ransomware payments dipped in 2025, broader crypto-related crime remains active.

A recent report from cybersecurity company CertiK found that $370.3 million in crypto was stolen in January 2026 alone.

https://twitter.com/certikalert/status/2017568546747035835

Phishing scams accounted for $311.3 million of that total, representing the largest share of losses.

The data indicates that while ransomware revenue is under pressure, attackers are adapting.

The post Ransomware attacks soar as hackers pivot to small businesses appeared first on Invezz

origin »

Bitcoin price in Telegram @btc_price_every_hour

Heart Number (HTN) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.02 %, 7d: 0.00 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 2.216b HTN / 7.163b HTN

ransomware attacks shows new research chainalysis number

ransomware attacks → Результатов: 126


Фото:

Microsoft Warning – Hospitals Vulnerable to Bitcoin Ransomware

Microsoft has issued a chilling warning that many hospitals in the United States are at risk of bitcoin ransomware attacks right now amid the coronavirus pandemic. Bitcoin Ransomware Attackers Target Hospitals The giant software company said that “dozens” of hospitals are using vulnerable gateways and that this makes them easy targets for the REvil ransomware that is currently scanning the internet for these types of flaws.

2020-4-6 17:00


Фото:

Could Ransomware Be Driving Up Bitcoin Prices?

Research is suggesting that the number of ransomware incidents has risen in 2019. The payment method of choice for the majority of this cybercrime is cryptocurrency, predominantly bitcoin. Could BTC price fluctuations be linked to the increase in this online nefarious activity? Bitcoin Price and Ransomware US state departments, public sector facilities schools, hospitals, and businesses are increasingly falling victim to ransomware attacks.

2019-10-21 10:35


Europol: Bitcoin is the still the dark web’s favorite cryptocurrency

Bitcoin is still very much the dark web‘s favorite cryptocurrency, but those looking to cover their tracks are slowly learning to use privacy-focused alternatives. “While we have previously reported a small shift towards more privacy-focused cryptocurrencies such as Monero, Bitcoin still remains the currency of choice for both legitimate and criminal use,” reports Europol with its latest assessment of internet-based organised crime.

2019-10-14 15:45


Фото:

US preps voting systems against ransomware attacks ahead of 2020 elections

The US government is looking to protect voter registration databases and systems from ransomware threats ahead of the 2020 presidential election. The Cybersecurity Infrastructure Security Agency (CISA) — a division of the Homeland Security department instituted by president Donald Trump in November last year — fears the databases could be at the receiving end of a ransomware attack.

2019-8-27 09:31


Фото:

Vicious malware threatens to turn search engine into crypto-mining zombie botnet

Enterprise search engine Elasticsearch is under threat of being turned into a sophisticated cryptocurrency mining botnet to be used in distributed denial of service (DDoS) attacks. Cybersecurity firm Trend Micro describes a new malware strain that launches multi-stage attacks on publicly accessible databases and servers that run old versions of Elasticsearch software.

2019-7-23 17:54


Ransomware Crooks Cashed Out $16 Million from Defunct Bitcoin Exchange: Google Research

By CCN: In the two years leading up to 2018, a spate of ransomware attacks were analyzed in a report by a team of researchers hailing mostly from leading U. S. universities and Google. Results showed a conservative estimate of total funds stolen to be $16 million, with bitcoin providing a way for malicious actors to take payment from anywhere in the world.

2019-5-9 11:50


Фото:

PayPal Wins Patent for Ransomware Detection Solution

Global payment processing platform PayPal has been awarded a patent for a technique that can help with the timely detection and reduction of ransomware attacks. Ransomware attacks are a form of malware that takes over the victim's computer, locks up the files therein and demands a ransom before the files can be accessed again — often to be paid in cryptocurrency.

2019-4-19 21:17


Фото:

Lazarus Hacker Group Continues to Target Crypto Using Faked Trading Software

This article was originally published by 8btc and written by Lylian Tang. The Chinese security service provider 360 Security has issued a warning that a large number of crypto exchanges have been targeted by the North Korean hacker group Lazarus and that the number is still rising after the recent hacks of crypto exchanges DragonEx, Etbox and BiKi.

2019-4-2 21:54