Skip to main content

What Ransomware Payments Actually Cost

John Gunn, CEO, Token
3 minute read
Ransomware payments surged 500% due to legacy MFA failures
What Ransomware Payments Actually Cost | TokenCore™
6:10

When ransomware hits, most organizations face the same question immediately. Pay the ransom and try to recover quickly, or refuse and rebuild from backups. The answer is rarely obvious in the moment. Attackers count on that.

This page covers what the payment data actually looks like, what paying costs beyond the ransom itself and what the research says about organizations that pay versus those that do not.

What Ransomware Payments Look Like Now

The numbers have moved sharply in a short period. Sophos’ State of Ransomware 2024 report puts the average ransom payment at $2 million, up from $400,000 the year before. RISK & INSURANCE reported the median ransom demand jumping from $1.4 million in 2022 to $20 million in 2023.

These are the payment amounts. They do not capture total incident cost. MGM Resorts suffered losses of $100 million from a single attack. Change Healthcare’s breach cost exceeded $1 billion. CDK Global’s incident shut down operations across thousands of car dealerships for weeks.

The gap between what attackers demand and what the incident actually costs is significant. The ransom is the entry fee. The real bill arrives after.

What Paying Actually Costs

The ransom payment is the most visible cost. It is rarely the largest.
Recovery does not begin when the ransom is paid. Attackers encrypt files, delete backups and often maintain persistent access through malware left behind after decryption keys are delivered. Organizations that pay still face forensic investigation costs, system remediation, data recovery, legal fees and regulatory fines if personal data was exposed.

Operational downtime is often the biggest cost driver. A business that cannot process payments, access patient records or run logistics for two weeks sustains losses that dwarf the ransom demand. Change Healthcare’s disruption affected pharmacies across the country for months.

Paying also does not guarantee full recovery. Decryption tools provided by attackers are imperfect. Corrupted files do not always restore cleanly.

What the Data Says About Paying

Research on ransomware payment outcomes points in a consistent direction.

Organizations that pay are more likely to be targeted again. Attackers share data on which victims paid and how quickly. A payment signals willingness to pay. It also indicates that the security posture was vulnerable enough to breach once and may be again.

Paying does not remove the original vulnerability. Attackers who gained access through phishing or a compromised credential have already demonstrated how to get in. Closing that entry point requires addressing the authentication architecture, not settling the ransom.

Regulators and cyber insurers are increasingly scrutinizing payment decisions. Some jurisdictions restrict payments to sanctioned groups. Insurers are tightening ransomware coverage. A payment that resolves the immediate crisis can create compliance and coverage complications that follow.

Preventing Ransomware Before the Decision Arises

Ninety percent of successful ransomware attacks start with phishing. The attacker’s first move is not a technical exploit. It is a credential. Getting through the front door with a stolen username and password, then escalating from there.

Legacy MFA does not stop this. SMS codes, push notifications and authenticator apps all produce factors that a phishing relay can capture and forward in real time. The attacker does not need to break authentication. They just need to be in the middle of it.

Authentication that is bound to a specific device and domain removes the relay attack surface entirely. No code to capture. No push to approve. No transferable factor for an attacker to work with.

The Role of Biometrics

Biometric authentication binds the authentication step to a physical trait that cannot be phished or transferred. A fingerprint cannot be captured in a phishing campaign. It cannot be shared, relayed or socially engineered out of the user.

For enterprise deployments, the critical property is where biometric verification happens. On-device verification, where the template never leaves the hardware, means no central database exists for an attacker to target. Authentication happens on the device. Nothing is transmitted that an attacker can intercept.

Combined with FIDO2 origin binding, biometric wearable authentication closes both attack vectors that ransomware relies on. The attacker gets no credential and the relay has nothing to forward.

Emphasizing User Convenience

Biometrics enhances user experience by providing quick and seamless authentication, reducing errors, lockouts, and helpdesk calls. Convenient MFA solutions increase user adoption and compliance with security protocols, ensuring that security measures are effective and user-friendly.

Implementing the Right MFA Solution

Choosing the right next-generation MFA solution involves considering factors such as supported authentication methods, integration capabilities, ease of use, and scalability. Implementing these solutions in phases can minimize disruption and ensure a smooth transition.

Continuous monitoring and regular updates are vital to maintaining the effectiveness of next-generation MFA solutions. Organizations should establish a framework for ongoing security assessments and threat intelligence integration to stay ahead of emerging threats.

Conclusion

The sharp increase in ransomware payments highlights the urgent need for enhanced security measures. Legacy MFA systems are no longer sufficient to combat sophisticated cyberattacks. By adopting next-generation MFA technologies, organizations can significantly bolster their defenses against ransomware, safeguarding critical data and ensuring operational resilience.

Discover how Token's identity assurance can protect your organization from phishing and ransomware.

Stay Identity Assured

Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.