/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Average ransom payment for ransomware attacks rose 43% from Q4 2020 to Q1 2021, from $154,108 to $220,298, and median payment was up 58% from $49,450 to $78,398

Bill Siegel / Coveware :

Coveware Bill Siegel

Context & Ripple Effects

Coveware's Q1 2021 numbers extend an escalation arc that was already visible in its own earlier data: the average payment to unlock files had doubled quarter-over-quarter in late 2019, reaching ~$84K, and ransomware was already the dominant driver of cyber insurance claims, accounting for 41% of filings in H1 2020 with demands climbing alongside. A 58% jump in the median — not just the average — signals the price floor itself moved, meaning smaller victims without negotiating leverage were paying far more.

The longer view matters here too: this Q1 2021 spike sits near what later Chainalysis tracking shows as the peak of attacker revenue before aggregate ransom payments fell 35% in 2024 as more victims refused to pay. The Coveware print captures the market at its most coercive moment.

First-order effects

  • Victims who pay in Q1 2021 are absorbing a materially higher cost of capitulation — a $78K median means even small organizations now face six-figure-or-near decisions under downtime pressure.
  • Cyber insurers footing these claims see their loss ratios climb directly with the payment curve, since ransomware was already 41% of claims volume in H1 2020.

Second-order effects

  • Insurers respond by repricing coverage, tightening limits, or steering policyholders toward pre-approved negotiators and backup requirements — shifting the cost of escalation back onto insureds.
  • Rising realized payments make ransomware economics more attractive relative to other criminal revenue models, drawing more affiliates into ransomware-as-a-service ecosystems and raising attack frequency against mid-market targets where the median buyer sits.

Third-order effects

  • If the pattern holds, the market bifurcates: attackers concentrate demands on organizations that can pay seven figures — consistent with Coalition's later finding of a $1.62M average demand in 2023 — while low-value targets get priced out of the criminals' own funnel.
  • Sustained payment inflation eventually breaks the willingness-to-pay model itself, which is the trajectory Chainalysis documents: total on-chain ransom receipts falling year after year as refusal rates rise, forcing attackers toward volume over yield.

The trend: Ransomware pricing escalated sharply through 2020-21 toward a payments peak, before victim refusal rates inverted the economics and drove aggregate ransom flows down.