/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Total on-chain ransomware payments fell 8% YoY to $820M in 2025, despite a record 50% rise in claimed victims; the median payment grew 368% YoY to nearly $60K

TL;DR  — Ransomware payments stagnated despite record attacks claimed.  Total on-chain ransomware payments fell by approximately 8% …

Chainalysis

Context & Ripple Effects

Ransomware payment volumes have swung sharply in the coverage: they reached a record $1.1B in 2023 before falling to about $813.55M in 2024. The 2025 result keeps total on-chain receipts near that lower level rather than returning to the prior peak.

The new divergence matters because claimed victim growth, aggregate payments and typical payment size are no longer moving together. That makes payment conversion—not attack claims alone—a more important measure of the ransomware economy.

First-order effects

  • Ransomware operators collectively received about $820M on-chain in 2025, 8% less than a year earlier, despite a sharp increase in claimed victims.
  • For victims that did pay, the nearly $60K median payment signals materially higher typical exposure than the prior year.

Second-order effects

  • Security teams, insurers and incident-response providers will need to separate claimed attacks from paid incidents when assessing ransomware risk; the two measures now point in different directions.
  • The combination of lower aggregate receipts and a higher median payment suggests attackers' revenue is becoming more dependent on which victims convert to payment and at what amount, rather than on claimed attack volume alone.

Third-order effects

  • If this divergence persists, ransomware reporting will increasingly require separate indicators for attack volume, payment rates and payment size; aggregate on-chain receipts alone will not describe operational harm.
  • The longer-run market may be defined by more selective monetization: fewer paid incidents can coexist with broad attack activity and higher costs for the organizations that do pay.

The trend: Ransomware is shifting from a cycle where attack volume and criminal receipts broadly rise together toward one where payment conversion and deal size determine revenue.