Ransomware Crooks Are Busier Than Ever — But Making Less Money, Researchers Say

bitcoinist發佈於 2026-02-27更新於 2026-02-27

文章摘要

According to a Chainalysis report, ransomware attacks increased by 50% in 2025, with nearly 8,000 incidents recorded. However, total ransom payments fell by 8% to $820 million. This decline is attributed to stricter regulations, improved law enforcement, and more companies refusing to pay. Attackers have shifted focus to small and medium-sized businesses, which pay faster but yield smaller sums. The cost of launching attacks has also decreased significantly, with access to victim systems on the dark web dropping from $1,427 in 2023 to $439 in early 2026. Despite the drop in ransomware revenue, broader crypto crime remains significant, with $370 million stolen in January 2026 alone, mostly through phishing attacks.

The cybercrime business is booming, at least on paper. According to a new report from blockchain analytics firm Chainalysis, the number of ransomware attacks jumped 50% in 2025, with nearly 8,000 separate incidents recorded throughout the year. Yet for all that hustle, hackers walked away with less cash than the year before.

Smaller Targets, Smaller Payouts

Total ransom payments collected in 2025 came in at $820 million — an 8% drop from 2024. Reports say the decline is tied to several factors: tougher rules from regulators, law enforcement cracking down on the networks criminals use to launder money, and a growing number of companies simply refusing to pay.

With big organizations shutting the door, attackers moved on to easier prey. Small and medium-sized businesses became the new focus. “Smaller victims pay faster,” said Corsin Camichel, founder of eCrime.ch, in the Chainalysis report.

But faster doesn’t mean bigger. Those smaller targets yield smaller sums, and that math is catching up with the criminals running these schemes.

Source: Chainalysis

The gap between how many attacks are being claimed publicly and how much money is actually being collected tells its own story. Attackers are filing more claims than ever, yet the money flowing back to them keeps shrinking.

BTCUSD now trading at $67,800. Chart: TradingView

According to Chainalysis, that gap signals something important — the people running these operations are putting in more work for a worse result.

Source: Chainalysis

Ransomware: The Cost Of Breaking In Has Fallen Sharply

Part of what’s fueling the surge in attack numbers is how cheap it has become to launch one. Reports note that the average price for purchasing access to a victim’s system on the dark web fell from $1,427 in early 2023 to just $439 by early 2026.

Artificial intelligence tools and an oversupply of ready-made attack software have made it easier for more people to get into the ransomware game.

The result is a crowded field of attackers competing for the same pool of victims — and driving down their own profits in the process. It mirrors what happens in any flooded market. More sellers, same number of buyers, prices fall.

2026 Has Already Seen Major Crypto Losses

Even as ransomware payments trended downward last year, the broader picture of crypto-related crime remains grim. According to cybersecurity firm CertiK, $370 million in crypto was stolen in January 2026 alone through various exploits and scams.

Phishing attacks were responsible for the bulk of those losses, accounting for $311 million of the total. Ransomware may be generating less revenue for its operators, but the wider world of crypto theft is far from slowing down.

Featured image from Unsplash, chart from TradingView

相關問答

QAccording to the Chainalysis report, what was the percentage increase in ransomware attacks in 2025 and the total number of incidents?

AThe number of ransomware attacks jumped 50% in 2025, with nearly 8,000 separate incidents recorded.

QWhat was the total value of ransom payments collected in 2025 and how does it compare to the previous year?

ATotal ransom payments collected in 2025 came in at $820 million, which is an 8% drop from 2024.

QWhat are the three main factors cited for the decline in ransom payments?

AThe decline is tied to tougher rules from regulators, law enforcement cracking down on money laundering networks, and a growing number of companies refusing to pay.

QHow much did the average price for purchasing access to a victim's system on the dark web fall between early 2023 and early 2026?

AThe average price fell from $1,427 in early 2023 to just $439 by early 2026.

QHow much cryptocurrency was reported stolen in January 2026 by CertiK, and what type of attack was responsible for the majority of those losses?

A$370 million in crypto was stolen in January 2026, with phishing attacks accounting for the bulk of those losses at $311 million.

你可能也喜歡

如果 AI 泡沫已经在破了,谁会真正留下?

AI行业存在泡沫已成为市场共识,观点两极分化:达利欧认为泡沫已高,黄仁勋则视其为巨大机遇的开始。文章指出,泡沫类似于2000年互联网泡沫,虽导致市场暴跌和公司倒闭,却沉淀了关键基础设施(如海底光缆、宽带),为后来亚马逊、Netflix等巨头崛起奠定基础。当前AI领域,巨头正投入数千亿美元建设数据中心、电力、GPU等基础设施,而应用层收入尚未完全匹配,形成“基建投入远大于应用收入”的明显落差。 然而,AI推理成本(Token成本)已暴跌超99.7%,这使得企业AI支出不降反升。成本下降解锁了大量长尾需求,AI正从聊天工具深入代码、医疗、金融、制造等行业的真实工作流,进入智能体与多模态应用时代。市场正在自我净化,淘汰缺乏核心竞争力的“套壳”公司,但AI赋能千行百业的大趋势不可逆转。 未来,价值将从资本支出(CapEx)的基础设施层,逐渐转向运营支出(OpEx)的应用层。那些能真正解决垂直行业痛点、重塑业务流程的AI原生企业将获得超额利润。尽管估值存在压力,但企业盈利增长有望逐步消化高估值。最终,泡沫破裂后留下的将是坚实的基础设施和高度优化的技术,推动社会进入一个所有行业均由AI驱动的智能时代。泡沫终会破灭,但底层的生产力革命真实无水分。

marsbit24 分鐘前

如果 AI 泡沫已经在破了,谁会真正留下?

marsbit24 分鐘前

微软CEO:在AI时代,如何定义一家公司的护城河?

微软CEO萨提亚·纳德拉认为,AI时代企业的核心竞争力并非依赖于单一的最强大模型,而在于能否构建一个持续进化的“学习闭环”。这一系统能将企业内部的工作流程、专业知识、组织判断和员工经验沉淀下来,并让人工智能与人类能力相互强化、共同提升。 未来的公司将积累两类关键资产:一是以员工知识、判断力、创造力和模式识别能力为核心的“人力资本”;二是企业自身构建并拥有的AI能力,即“Token资本”。纳德拉强调,AI不仅不会削弱人力资本的价值,反而会让人类的目标设定、跨领域连接和关键决策能力变得更为重要。缺乏人的引导,算力将失去方向;没有企业自身知识的注入,再强的模型也仅是外部工具。 因此,企业的真正护城河在于建立私有的评估体系、强化学习环境和知识库,将隐性经验转化为可迭代、可扩展的系统能力。即使更换底层通用模型,企业独有的“公司老员工式”的专业经验和学习成果也不会丢失。这确保了企业的知识产权与控制权。 纳德拉指出,健康的AI未来应是一个繁荣的“前沿生态”,而非由少数通用模型垄断价值。只有这样,价值才能广泛惠及每家公司、每个行业和国家,让各组织能基于自身知识创造并保留经济价值,最终实现企业、员工与社区的共同繁荣。

marsbit1 小時前

微软CEO:在AI时代,如何定义一家公司的护城河?

marsbit1 小時前

ZEC 联创回应 Orchard 漏洞:暂无被盗痕迹,将封存 Orchard 池

近期Zcash的Orchard模块曝出安全漏洞,引发了对代币总量是否异常及用户资产安全的两大关切。本文针对漏洞引发的四个核心问题进行分析。 首先,关于漏洞是否已被利用,目前尚无证据表明已被恶意使用。该漏洞由专业团队主动发现,门槛较高,且曝光后开发团队迅速冻结资金池并修复,极大限制了攻击窗口。历史经验表明,黑客获利后通常会快速变现并留下痕迹,目前尚未发现此类证据。 其次,关于Orchard内合法资产的取回,若漏洞从未被利用,用户资产可正常转出。但如果虚假代币已混入池中并抢先转出,则可能影响部分用户的取回。考虑到漏洞被利用的概率较低,将资产留在原隐私钱包内是稳妥选择。若选择转出,需注意转入公开地址会完全失去隐私性,转入Sapling池则依赖2018年的可信初始化仪式,存在额外安全隐患。 第三,目前用户无法自行验证Zcash代币总量是否被增发。但计划中的Ironwood网络升级将永久关闭Orchard池,只允许资产按原合法存入数量转出,从而从协议层面杜绝超发。升级后,任何用户均可通过运行节点独立验证总量。 最后,关于是否存在其他造假漏洞,多支团队(包括借助先进AI工具)已进行全面排查,目前未发现新的同类高危漏洞,但仍无法给出绝对保证。 总结来说,漏洞很可能未被利用,用户资产目前安全,且暂未发现其他类似漏洞。但关键问题在于用户目前无法自主验证总量,而Ironwood升级将解决此问题,恢复Zcash的可验证性基础。

Foresight News1 小時前

ZEC 联创回应 Orchard 漏洞:暂无被盗痕迹,将封存 Orchard 池

Foresight News1 小時前

交易

現貨
合約
活动图片