Median Ransomware Payment Jumps 50% as Mid-Market Becomes More Targeted

Stu Sjouwerman | Nov 9, 2021

Median Ransomware PaymentChanges in attack tactics in the last quarter alone demonstrate a shift in focus for ransomware gangs, as the number of companies attacked with 100 to 1,000 employees grows.

Everyone always thinks it’s “the other company” that gets attacked; another vertical, another geo, another size, etc. But the reality is, every organization is a potential target and it’s only a matter of time until it’s your organization’s turn.

New data from Coveware’s Q3 Quarterly Ransomware Report shows that the lower end of mid-market organizations (those between 100 and 1,000 employees) has risen significantly from Q2 to Q3 this year. According to the data, this grouping of companies has grown in focus by 13%. This coming at a time when the median ransomware payment has increased by 50% to over $71K and the average has grown only slightly to nearly $140K. And with 83% of all ransomware attacks threatening to publish exfiltrated data, it’s likely organizations are facing tough decisions when it comes to paying these increased ransoms.

The primary attack vectors in the mid-market as a whole continue to be RDP compromise and phishing attacks – making it fairly easy for these organizations to put protective measures in place to address the majority of ransomware attacks:

  • RDP – kill basic Remote Desktop access that is Internet-facing. Put additional factors in place like VPN/SASE, MFA, and even Zero Trust solutions to minimize the risk of inappropriate access.
  • Phishing – block malicious content with email filtering, sandboxing, endpoint protection, and Security Awareness Training to include users as part of your propped-up defense.

Topics: Ransomware

Test Your Network’s Defenses with our Free Ransomware Simulator

When employees bypass guidance and fall for social engineering, your network security is the last line of defense. Run our 100% harmless RanSim tool on Windows 10+ workstations to safely simulate 25 ransomware and cryptomining infection scenarios, pinpoint technical vulnerabilities, and get your results in minutes.

Launch Your Free Ransomware Simulation

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.