/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Ransomware negotiation firm Coveware: the number of ransomware victims paying ransom demands dropped to a record low of 29% in Q4 2023, down from 85% in Q1 2019

The number of ransomware victims paying ransom demands has dropped to a record low of 29% in the final quarter of 2023, according to ransomware negotiation firm Coveware.

BleepingComputer Bill Toulas

Context & Ripple Effects

Coveware’s payment-rate measure reverses the economics visible in its earlier reporting, when average and median ransom payments climbed sharply in early 2021. By late 2023, reported losses and demands were still rising, including higher average victim losses and demands in H1 2023.

The 29% payment rate is therefore a useful indicator distinct from headline ransom sizes: attackers may ask for more, but fewer victims are agreeing to transfer funds. Later coverage of a decline in ransomware payments during 2024 is consistent with that pressure on collections.

First-order effects

  • A smaller share of ransomware victims is paying, directly reducing the pool of incidents that convert into ransom revenue for extortion groups.
  • Victims and their incident-response partners have greater leverage to pursue recovery and containment rather than treat payment as the default outcome.

Second-order effects

  • Attackers face pressure to improve conversion—through target selection, negotiation tactics, or larger demands—because rising demands do not guarantee payment when refusal rates increase.
  • Insurers, negotiators, and security providers must evaluate ransomware exposure using both demand severity and payment propensity; the two were already diverging in 2023.

Third-order effects

  • If refusal persists, ransomware economics could become less dependent on broad-volume encryption campaigns and more concentrated around incidents where victims have the least recovery flexibility.
  • Payment totals may remain volatile even as payment rates fall: later data shows fewer payments can coexist with larger individual transfers, making victim preparedness more consequential than aggregate payment trends alone.

The trend: Ransomware is shifting from an environment of routinely paid disruption toward a tougher, less predictable monetization model in which attacker revenue depends increasingly on a smaller set of vulnerable victims.