/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Coalition: ransomware victims reported an average $365K+ loss in H1 2023, up from $227K+ in H2 2022; the average ransom demand was $1.62M, up 74% from 2022

James Reddick / The Record :

The Record James Reddick

Context & Ripple Effects

Earlier coverage had already shown ransomware becoming a material cyber-insurance exposure, with incidents accounting for a large share of claims in H1 2020, while average payments rose sharply in early 2021. Coalition's H1 2023 figures extend that escalation from payments to the broader losses borne by victims.

The report sits between evidence that some victims were refusing to pay in 2022 and record aggregate ransomware payments in 2023. That contrast matters: lower willingness to pay does not necessarily reduce the operational and financial damage from attacks.

First-order effects

  • Organizations hit in H1 2023 faced substantially higher average losses and ransom demands, increasing the financial stakes of incident response and recovery.
  • The widening cost burden makes ransomware a more consequential exposure for organizations and the providers that finance or support their recovery.

Second-order effects

  • Higher loss severity can put pressure on cyber-insurance underwriting, coverage terms, and the security controls required of insured customers, given ransomware's earlier prominence in claims.
  • Attackers' larger demands raise the value of resilience measures that reduce disruption without payment, even as victims may continue to resist paying ransoms.

Third-order effects

  • If losses and demands keep rising independently of payment rates, ransomware risk will be measured less by ransom transfers alone and more by business interruption and recovery costs.
  • The pattern points toward a security market organized around loss containment and recoverability, rather than treating payment refusal as a complete solution to ransomware exposure.

The trend: Ransomware is evolving from a payment-focused cybercrime metric into a broader operational-loss problem, with attack severity remaining consequential even when more victims decline to pay.