Research report · June 2026

Ransomware Recovery in 2026.

Why total loss has decoupled from the ransom, and what an organization needs to prove it can restore. Evidence from 28 public and methodology-disclosed sources.

$820M
On-chain ransom payments, down ~8%
+50%
Rise in claimed attacks, same period
$5.08M
Avg. ransomware breach cost when disclosed

Get the full report

You can unsubscribe anytime. See our Privacy Policy for how we use your data.

By submitting, you consent to Elastio storing and processing your information to provide the content you requested.

Key Findings

The ransom is no longer the unit of damage.

Four numbers that frame the report. Each is tied to a named public source.

$820M
Identified on-chain ransom payments in 2025, down about 8% from 2024 while claimed attacks rose about 50%.
Chainalysis 2026
$5.08M
Average ransomware breach cost in 2025, when the incident was disclosed by the attacker.
IBM Cost of a Data Breach 2025
38%
Of organizations that paid more than the initial ransom demand reported their backups had failed or malfunctioned.
Sophos State of Ransomware 2025
£1.9B
Estimated total economic impact of the 2025 Jaguar Land Rover cyberattack, the costliest cyber event in UK history.
Cyber Monitoring Centre, Oct 2025

Executive Findings

Seven findings that reframe the risk.

Criminal revenue, public victim counts, and enterprise damage now move on different curves. Each finding is corroborated across multiple sources.

01
Payments and losses have decoupled

Lower aggregate criminal revenue does not imply lower enterprise damage. Single incidents now produce billions in operational loss where no public ransom demand emerged, or where a paid ransom did not restore service.

02
Backup ownership is no longer evidence of recoverability

Backup use as the actual recovery method fell to a six-year low of 54%, down from 73%. Among organizations that paid more than the initial demand, 38% reported their backups had failed or malfunctioned.

Sophos 2025
03
The recovery plane is now a primary target

Mandiant, Verizon, and Sophos all observed attackers moving against backup and recovery infrastructure before encryption. MITRE catalogs this as T1490 Inhibit System Recovery, paired with T1486 Data Encrypted for Impact.

04
Initial access is converging on software, identity, and the help desk

Verizon reported software vulnerability exploitation as the top initial entry route at 31% of breaches. Mandiant observed voice phishing at 11% of initial vectors enterprise-wide and 23% in cloud environments.

Verizon DBIR, Mandiant
05
Total economic loss concentrates in third-party and supply-chain incidents

UnitedHealth disclosed $2.2B in direct response costs plus $867M in Optum Insight disruption. CDK Global produced $1.02B in dealer losses over three weeks. Jaguar Land Rover carried an estimated £1.9B total impact.

06
Regulators have shifted from prevention to recovery evidence

NIST CSF 2.0 elevated Recover and added Govern. DORA Article 12 requires documented restoration procedures and periodic testing. NIS2 imposes a 24/72/30 reporting cadence. SEC Item 1.05 makes material incidents disclosable within four business days.

07
Insurance is repricing toward control evidence, not control existence

Cyber claims notifications fell 29% in 2025 and ransomware-specific claims fell 33%, while NAIC reported the first-ever year-over-year decline in US direct written premium. Underwriting diligence now orients toward evidence that recovery controls work.

Marsh, NAIC

The Attack Path

How attackers reach the recovery plane.

The technical center of gravity has shifted from delivering a payload to dismantling the ability to restore. Recovery suppression is now standard tradecraft, which is why detection has to reach inside backup data.

32%
Vulnerability exploitation
Sixth consecutive year leading
11%
Voice phishing
Second-most-observed vector
6%
Email phishing
Down from prior years

Share of observed initial-access vectors. Source: Mandiant M-Trends 2026.

Recovery-suppression actions before encryption
  • Deletion of volume shadow copies and disabling of Windows Recovery Environment.
  • Modification or deletion of snapshot policies on backup appliances and cloud volumes.
  • Encryption of ESXi datastores that host backup-server VMs and management appliances.
  • Compromise of backup-administration accounts and reduction of retention windows.
  • Disabling or evasion of object-versioning protections in cloud object storage.
  • Compromise of identity providers and key-management services the recovery process depends on.

Business Impact

Ransom paid versus total loss disclosed.

Four named incidents. Where a ransom was disclosed, it was a small fraction of total loss. In the rest, operational loss reached hundreds of millions to billions with no public ransom at all.

Ransom paid (or disclosed)
Total loss disclosed
Change Healthcare (UnitedHealth, 2024)
$3.07B total loss
$22M ransom paid
Jaguar Land Rover (2025)
$2.5B (£1.9B) total impact
Ransom not disclosed
CDK Global (Franchised dealers, 2024)
$1.02B dealer losses
Ransom not disclosed
Marks & Spencer (2025)
£300M operating-profit hit
Ransom not disclosed

Per-incident, USD millions (GBP converted at ~1.33). Sources: UnitedHealth 10-K; Anderson Economic Group; Marks & Spencer annual reports; JLR disclosures and UK Cyber Monitoring Centre.

Board Oversight

Five questions a board can ask now.

Each expects an evidence-backed answer, not an assurance. The most useful question is no longer ‘do we have backups.’ These are the questions board reporting should answer.

1

For each tier-zero service, how old is our most recent recovery point that has been independently verified clean and restorable, and who confirmed it?

2

If an attacker moved against our backup and recovery infrastructure before encryption, would we detect it, and what evidence shows the recovery plane survived?

3

What is our exposure to a multi-week outage of a critical service, measured as total loss across operations, suppliers, and disclosure, not the size of a ransom?

4

Can we produce restore-test results, recovery-point integrity logs, and identity-recovery readiness on demand for a regulator or insurer, within hours rather than weeks?

5

Who holds the authority to declare a recovery point unsafe or to override a restore gate, and is that decision recorded?

Recovery Assurance

The control that distinguishes recoverable from not.

Recovery assurance is continuous, evidence-producing verification that a clean, complete, restorable recovery point exists for each in-scope service, and that the restore can be performed under realistic conditions.

Resilience RPO (R-RPO)
Elastio metric

Time since the most recent recovery point independently verified clean, complete, restorable, and within business-policy retention.

Clean recovery coverage

Share of tier-zero and tier-one services with at least one recovery point verified clean within their R-RPO policy window.

Restore confidence score

A composite of data-integrity verification, identity-recovery readiness, dependency status, and runbook completion for a service.

Recovery evidence age

Time since the most recent successful documented restoration test for a given service.

Known-bad containment window

Time between the earliest detected malicious indicator and the last contaminated recovery point. Defines how far back an analyst must search for a safe restore point.

New to these terms? The glossary defines R-RPO, Last Known Clean, Provable Recovery, and more.

DomainLevel 1: ad hocLevel 3: managedLevel 5: assured
Asset coverageBackups tracked by job or storage target.Critical services mapped to workloads and dependencies.Service-tier coverage reconciled with policy and evidence.
Backup integrityBackup success assumed to imply recoverability.Scheduled integrity tests and periodic restore drills.Continuous recovery-point inspection and known-clean classification.
Ransomware detection in backupsLimited to endpoint or production detection.Selected backup sets scanned during incident response.All critical recovery points scanned; results integrated with SIEM and restore gates.
Restore orchestrationManual restore tasks and tribal knowledge.Documented runbooks for critical services.Isolated, tested, dependency-aware recovery with approval workflows and health validation.
Governance evidenceScreenshots and ad-hoc records.Quarterly test reports and exception registers.Board-level metrics and control evidence mapped to NIST, CISA, and sector regulators.
Continuous improvementLessons after major events only.Annual tabletop and disaster-recovery exercises.Threat-informed exercises, red-team backup-targeting scenarios, metric-driven remediation.

Governance & Insurance

The shift is from attestation to artifact.

Regulators and insurers no longer accept that backup and recovery controls exist. They expect proof the controls produce the outcomes they are supposed to. Each framework implies a specific evidence artifact.

NIST CSF 2.0 (RC.RP-03)

Recovery-point scan results, malware / IoC coverage, clean-point decisions, exception approvals.

DORA Article 12

Control map, backup-policy evidence, segregation evidence, periodic restore-test records, data-integrity checks.

NIS2 Article 23

Incident chronology, severity assessment, IoC packet, and root-cause analysis at 24h / 72h / 30 days.

SEC Item 1.05

Materiality decision log, impact assessment, service-restoration evidence, board reporting within four business days.

NYDFS 23 NYCRR Part 500

Plan approvals, test results, incident communications, recovery-dependency evidence.

CISA #StopRansomware

Backup-test calendar, restore evidence, integrity-test results, tabletop records.

Sources

Built on public, methodology-disclosed evidence.

The report synthesizes 28 sources, reconciles where they disagree, and cites each figure with the population it describes. Full numbered citations appear in the downloadable report.

Chainalysis 2026 Crypto Crime ReportVerizon 2026 Data Breach Investigations ReportIBM Cost of a Data Breach 2025Sophos State of Ransomware 2025Mandiant M-Trends 2026FBI IC3 2025 Annual ReportENISA Threat Landscape 2025Dragos 2026 OT Year in ReviewNIST CSF 2.0 and SP 800-184CISA #StopRansomware GuideEU DORA and NIS2 rule textSEC cybersecurity disclosure rule (Item 1.05)NAIC 2025 Cybersecurity Insurance Market ReportMarsh 2025 Cyber Claims ReportAllianz Risk Barometer 2026WEF Global Cybersecurity Outlook 2026UK Cyber Monitoring Centre (Oct 2025)

Elastio

Can you prove a clean recovery
point exists right now?

The Recovery Posture Assessment scores your estate against the evidence regulators and insurers now ask for.