Cisco cybersecurity report: 9.5K ransomware victims pay ransoms each month, the average ransom is about $300, generating up to $34M a year for hackers
Context & Ripple Effects
Cisco's 2016 security report put hard numbers on a then-nascent criminal market: roughly 9,500 victims paying ransoms each month at an average of about $300, worth up to $34M a year to attackers. At the time that read as a consumer-scale nuisance — cheap locks, small payments, volume economics.
The subsequent record shows how wrong that framing was. A Google study two years later counted $25M+ paid over just two years, and by 2020-2021 the per-victim numbers had transformed: quarterly averages of ~$84K climbing past $220K by Q1 2021 per Coveware, and CrowdStrike finding 56% of surveyed organizations hit within a year. The Cisco report is the baseline against which the entire enterprise-ransomware era is measured.
First-order effects
- Victims face the pay-or-lose-your-data decision at scale — 9.5K per month choosing to pay makes ransomware a self-funding business whose unit economics ($300 average) are published by Cisco itself.
- Security vendors like Cisco gain a commercial hook: quantifying the threat in dollars converts their report into demand for the defensive products they sell.
Second-order effects
- Insurers become a load-bearing player — ransomware went on to account for 41% of cyber insurance claims filed in H1 2020, meaning carriers are effectively underwriting the payment decision and repricing policies as demands climb.
- Attackers reinvest the revenue: each successful payment cycle funds better tooling and bigger targets, which is visible in the trajectory from $300 averages toward six-figure enterprise demands.
Third-order effects
- If the pattern holds, ransomware matures from opportunistic consumer extortion into a structured criminal industry targeting insured enterprises — with insurers' willingness to pay functioning as a price floor that pushes demands upward.
- The reporting cadence itself (Cisco, Google, Coveware, CrowdStrike all publishing payment statistics) signals ransomware becoming a tracked macro category, the way regulators and boards treat it rather than an IT footnote.
The trend: Ransomware has shifted from a low-value, high-volume consumer scam toward enterprise extortion, with average payments rising by three orders of magnitude since Cisco's 2016 baseline.