Nearly Half of Ransomware Victims Suffer Data Theft Before Detection

  • 49% of organizations detected ransomware attacks only after data theft occurred, up from 31% in 2025.
  • LockBit and RansomHub were the most detected threat groups for the second consecutive year.
  • Average ransom payments dropped to $2.8M from $3.6M in 2025, but payment frequency increased to 83% of victims.
  • AI infrastructure was cited as the biggest cybersecurity risk by 55% of respondents.

The report highlights a growing disconnect between the speed of AI-powered attacks and the manual, reactive nature of current cyber defenses. As threat actors exploit AI infrastructure vulnerabilities, security teams struggle with prolonged dwell times and alert fatigue, forcing many organizations to pay ransoms despite decreasing average payment amounts.

AI Security Effectiveness
Whether AI-driven security tools can reduce false positives and improve investigation timelines.
Threat Actor Evolution
How ransomware groups like LockBit and RansomHub will leverage AI to scale attacks further.
Dwell Time Reduction
The pace at which organizations can shorten detection times amid increasing attack sophistication.