Fewer Ransomware Victims Pay. Those Who Do Pay More, GuidePoint Finds

Estimated reading time: 5 minutes

Ransomware victims hit a record 2,760 in the third quarter, GuidePoint Security’s research team found. Its own data on ransomware payments carries the insurance story. Fewer clients paid ransoms. Those who paid, paid more. GuidePoint also says risk models built on attacker effort need revisiting.

Fewer ransomware victims are paying. The ones who pay are paying more.

That is the pattern in ransomware payments across GuidePoint Security‘s own negotiation cases. Its Research and Intelligence Team (GRIT) published the figures in its Q3 2026 Ransomware and Cyber Threat Insights report.

GuidePoint handled 29 ransomware negotiation engagements in the third quarter. That is up 61% from 18 a year earlier. The share of clients who paid fell from 50% to just under 21%. Among those who paid, the average payment rose 34%, from $240,000 to $321,000.

“Many of our clients carry cyber insurance,” GuidePoint notes. Insurance can shape payment decisions in ways that differ from uninsured organizations, it says.

The sample is small. At just under 21% of 29 cases, about six clients paid. GuidePoint says its engagements skew toward severe cases, where victims are more likely to consider paying. It calls its figures one data point in a larger picture.

Three-panel bar chart of GuidePoint ransomware negotiation cases, showing engagements up from 18 to 29, the share of clients paying down from 50 percent to just under 21 percent, and average payments up from 240,000 to 321,000 dollars, cyber insurance news produced.
GuidePoint ransomware negotiation engagements, Q3 2025 against Q3 2026. Small sample, skewed toward severe cases. Source: GuidePoint GRIT Q3 2026 report.

Ransomware Payments Fall As Attacks Rise

Ransomware payments are only part of the loss. GuidePoint points to operational disruption, regulatory exposure, and reputational fallout.

Attack volume keeps climbing. GRIT tracked 2,760 victims on ransomware leak sites in the third quarter. That is up 21% from the second quarter and 75% from a year earlier. Active groups reached a record 112, up from 76 a year ago.

See also  Cyber Insurance "Policy Buyback" Approved for Victims of 23andMe Hack

TheGentlemen narrowly overtook Qilin as the most active group, GuidePoint said. Together the two claimed about one in four victims. The US accounted for 42% of victims. Manufacturing led all industries.

Banking and finance returned to the top 10, according to GuidePoint. A sustained social engineering campaign against private equity firms drove part of that rise.

The victim counts come from leak-site posts. Victims have not confirmed them, and groups often remove victims who pay.

Ransomware Frequency And The Effort Assumption

GuidePoint’s sharpest point targets risk models.

AI agents now carry out parts of intrusions, the report says. That erodes a limit that once protected smaller targets. GuidePoint expects more frequent losses at organizations once too small or obscure to justify a human attacker’s time.

“Risk models that assume attacker effort is a limiting factor should be revisited,” the report says. GuidePoint also recommends updating cyber risk quantification for more attacks on mid-market firms.

GreyNoise research cited in the report shows the speed. One actor used hundreds of AI agents against PaperCut print-management servers. Once the campaign launched, it compromised at least 11 organizations in 26 seconds. In all, it hit 440 PaperCut instances at 395 organizations in 48 countries.

The methods themselves are familiar. Stolen credentials, weak identity controls and unpatched systems still open the door, GuidePoint says. AI makes those known weaknesses turn into losses faster.

YouTube video

Data Extortion Pays When The Data Matters

More groups now skip encryption and simply steal data. ShinyHunters runs that model. Tracked payments attributable to the group average about $600,000 per victim in 2026, GuidePoint said.

See also  Cyber Resilience Under Fire: New Data Exposes a Global Confidence Gap

Clop shows the other side. Its latest campaign exploited PTC’s Windchill product lifecycle software. Clop named about 71 victims by late September. GuidePoint has confirmed no payments from the campaign.

The difference is the data. Clop’s haul was mostly engineering files and product specifications. That intellectual property carries less regulatory pressure to pay than customer personal data, GuidePoint said.

GRIT also cites Zscaler data showing data theft volumes up 275% year over year. Cyber Insurance News covered that Zscaler report last month.

Ransomware Exposure Through Shared Vendors

Education shows how one breach can spread. In May, ShinyHunters claimed an attack on Instructure, the parent company of the Canvas learning platform. GRIT then tracked six more education technology platforms hit by six separate groups.

One vendor breach can expose every institution it serves, GuidePoint said. Nudge Security’s Russell Spitler told Cyber Insurance News that insurers cannot yet see that kind of aggregation.

GuidePoint’s advice for the next quarter is about time. It urges organizations to treat internet-facing flaws with a public exploit as a 48- to 72-hour problem. CrowdStrike found that 88% of that exploitation in the first half of 2026 occurred within 48 hours of the exploit’s release.

FAQ – Ransomware Payment Rate

How many ransomware victims did GuidePoint track in Q3 2026?

2,760 victims posted to leak sites, a record. That is up 21 percent from Q2 2026 and 75 percent from Q3 2025. Active groups reached a record 112.

Are fewer ransomware victims paying?

In GuidePoint’s own negotiation cases, yes. The share of clients who paid fell from 50 percent in Q3 2025 to just under 21 percent in Q3 2026.

See also  Third-Party Cyber Risk Drove Major Financial Losses in 2024, Resilience Finds

Are ransomware payments getting bigger?

Among GuidePoint clients who paid, the average payment rose 34 percent, from 240,000 dollars to 321,000 dollars. The sample is small, about six payments in Q3 2026.

Does cyber insurance affect these figures?

GuidePoint says many of its clients carry cyber insurance, which can influence payment decisions in ways that differ from uninsured organizations.

What does GuidePoint say about risk models?

It says AI agents erode the effort that once protected smaller targets. Risk models that assume attacker effort is a limiting factor should be revisited, it says.

Which ransomware groups were most active?

TheGentlemen narrowly overtook Qilin. Together the two claimed about one in four victims, GuidePoint said.

Leave a Comment

×