/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Cisco cybersecurity report: 9.5K ransomware victims pay ransoms each month, the average ransom is about $300, generating up to $34M a year for hackers

Jonathan Vanian / Fortune :

Fortune Jonathan Vanian

Context & Ripple Effects

Cisco's 2016 security report put hard numbers on a then-nascent criminal market: roughly 9,500 victims paying ransoms each month at an average of about $300, worth up to $34M a year to attackers. At the time that read as a consumer-scale nuisance — cheap locks, small payments, volume economics.

The subsequent record shows how wrong that framing was. A Google study two years later counted $25M+ paid over just two years, and by 2020-2021 the per-victim numbers had transformed: quarterly averages of ~$84K climbing past $220K by Q1 2021 per Coveware, and CrowdStrike finding 56% of surveyed organizations hit within a year. The Cisco report is the baseline against which the entire enterprise-ransomware era is measured.

First-order effects

  • Victims face the pay-or-lose-your-data decision at scale — 9.5K per month choosing to pay makes ransomware a self-funding business whose unit economics ($300 average) are published by Cisco itself.
  • Security vendors like Cisco gain a commercial hook: quantifying the threat in dollars converts their report into demand for the defensive products they sell.

Second-order effects

  • Insurers become a load-bearing player — ransomware went on to account for 41% of cyber insurance claims filed in H1 2020, meaning carriers are effectively underwriting the payment decision and repricing policies as demands climb.
  • Attackers reinvest the revenue: each successful payment cycle funds better tooling and bigger targets, which is visible in the trajectory from $300 averages toward six-figure enterprise demands.

Third-order effects

  • If the pattern holds, ransomware matures from opportunistic consumer extortion into a structured criminal industry targeting insured enterprises — with insurers' willingness to pay functioning as a price floor that pushes demands upward.
  • The reporting cadence itself (Cisco, Google, Coveware, CrowdStrike all publishing payment statistics) signals ransomware becoming a tracked macro category, the way regulators and boards treat it rather than an IT footnote.

The trend: Ransomware has shifted from a low-value, high-volume consumer scam toward enterprise extortion, with average payments rising by three orders of magnitude since Cisco's 2016 baseline.