Ransomware has been a major cybersecurity threat for well over a decade, and blockchain intelligence has grown dramatically more sophisticated in that same period, to the point where a large share of major ransomware payments are eventually traced to some degree. Given that, a reasonable question is why ransomware operators still insist on cryptocurrency payment at all. The answer is a mix of practical necessity and a genuine, ongoing arms race between attackers and investigators.
The Core Reason: Speed and Reach, Not True Anonymity
It is a common misconception that ransomware groups demand cryptocurrency because it is untraceable. As covered in our guide on how to trace stolen Bitcoin, transactions on a public blockchain like Bitcoin are permanently recorded and can often be traced with real precision. What cryptocurrency actually offers ransomware operators is something more practical: a payment method that works instantly across borders, requires no banking relationship or intermediary approval, cannot be reversed once confirmed, and can be received by an anonymous or pseudonymous wallet without the identity verification a bank account would require. For an attacker operating internationally against victims who need to pay quickly to restore operations, that combination is hard to replace with any traditional payment rail.
What Recent Data Shows About Ransomware Payments
Blockchain analytics research shows a notable shift in ransomware payment dynamics over the past couple of years. According to Chainalysis research, total cryptocurrency payments to ransomware operators fell substantially from the 2023 peak of roughly 1.1 billion dollars, continuing to decline through 2025, even as the number of publicly claimed ransomware attacks kept climbing. The share of attacked organizations that actually pay has also dropped to a record low, a trend widely attributed to improved backup practices, stronger law enforcement disruption of major ransomware groups, and growing organizational reluctance to pay following years of guidance from agencies like CISA discouraging it.
At the same time, individual ransom demands have grown sharply, with the median demand rising considerably year over year even as fewer victims agree to pay, and actual payments settling at only a fraction of the amount originally demanded. This points to a market where ransomware groups are asking for more per attack while succeeding less often, a dynamic consistent with a criminal ecosystem under increasing pressure but not yet close to disappearing.
Why the Ransomware Landscape Keeps Changing Shape
Rather than a single dominant group, the ransomware landscape has fragmented into a much larger number of smaller, independent operators, partly a direct consequence of law enforcement takedowns and sanctions against previously dominant ransomware as a service operations. This fragmentation makes the overall threat harder to track as a whole, even as individual groups within it become more identifiable, since smaller operators are more numerous but each maintains less operational sophistication and fewer resources to invest in evading detection than the larger operations that preceded them.
The shift toward privacy coins
Bitcoin remains the most commonly reported ransomware payment currency, but ransomware operators have shown increasing interest in privacy focused cryptocurrencies like Monero, which do not expose transaction details on a fully public ledger the way Bitcoin does. This shift is a direct response to the effectiveness of blockchain tracing against Bitcoin specifically, and represents one of the more significant emerging complications for investigators working ransomware cases, since standard clustering and chokepoint techniques described in our tracing guides are far less effective against a privacy coin's design.
Why Agencies Continue to Discourage Payment
CISA, the FBI, and equivalent international agencies have maintained a consistent position that organizations should not pay ransomware demands, for several concrete reasons rather than simple principle.
- Paying does not guarantee that files will actually be decrypted, working, or complete, and a meaningful share of victims who pay report incomplete or corrupted data recovery
- Payment provides direct funding for further criminal operations, including tooling, infrastructure, and payouts to affiliate operators in a ransomware as a service model
- Organizations known to have paid once are frequently targeted again, either by the same group or by others who obtain a reputation for payment through leaked victim data
- Paying can create separate legal exposure in some jurisdictions, particularly where a demand originates from or is linked to a sanctioned individual or organization
Regardless of whether an organization ultimately decides to pay, agencies consistently recommend reporting the incident to a local FBI field office or through IC3, since reported incidents feed both immediate investigative response and the broader intelligence picture used to disrupt ransomware infrastructure.
The Role of Legal Counsel and Incident Response Firms
In practice, few organizations make a ransomware payment decision without involving outside counsel and a specialized incident response firm, and for good reason beyond the purely technical response. Legal counsel typically leads a sanctions screening process before any payment is considered, since the Office of Foreign Assets Control maintains a list of sanctioned individuals and organizations, and a number of major ransomware groups or their known affiliates have been formally sanctioned. Paying a ransom to a sanctioned entity can expose the paying organization to separate civil liability regardless of the circumstances of the attack, which is why counsel generally insists on at least attempting to screen a ransomware group's known wallet addresses against sanctions lists before authorizing payment, even under significant time pressure.
Incident response firms handle the parallel technical track: containing the intrusion, assessing what was actually encrypted or exfiltrated, and in many cases directly negotiating with the ransomware operator on the victim's behalf, since direct contact by inexperienced staff can inadvertently reveal information that increases the ransom demand. Cyber insurance, where a policy exists, frequently plays a coordinating role here, since many policies require using a panel of incident response and legal firms approved in advance as a condition of coverage.
Common Misconception: Cyber Insurance Makes Payment Risk Free
A common assumption among organizations that carry a cyber insurance policy covering ransomware is that the existence of coverage removes most of the risk from the decision to pay. This is not accurate. Insurance may reimburse the ransom payment itself and associated incident response costs up to policy limits, but it does not undo the sanctions exposure described above, does not guarantee that paying will actually result in usable decryption keys or that exfiltrated data will not still be leaked, and does not reverse the reputational and regulatory consequences of the underlying breach, which in many industries carries separate notification obligations regardless of whether a ransom was ultimately paid. Insurers themselves have also grown more selective, in some cases requiring proof that specific security controls were in place before agreeing to cover a ransomware related loss at all.
A Worked Example: What Happens After a Ransom Is Paid
Consider a mid sized company that pays a six figure ransom in bitcoin after a ransomware attack encrypts its production systems, following legal and incident response guidance and a sanctions screening that clears the known wallet address. The payment itself does not end the organization's exposure. The transaction is now a permanent, public record, and blockchain intelligence firms and law enforcement routinely monitor known ransomware wallet clusters on an ongoing basis, not just in response to a single victim's report.
Months later, the wallet that received the payment consolidates funds with proceeds from several other victims and moves them through a chain of intermediary addresses before reaching a deposit at an exchange with weak compliance controls in a jurisdiction with limited cooperation. In some documented cases, this is where the trail effectively ends for practical recovery purposes, even though it remains fully visible on chain. In other cases, particularly where a ransomware group has drawn significant law enforcement attention, that same exchange deposit, combined with deposits tracked from other victims of the same group, has contributed to a broader law enforcement action resulting in wallet seizures and, in a smaller number of cases, partial restitution to victims identified through the same investigation.
The Tracing Angle: What Happens to Ransom Payments After They Are Paid
Even when a ransom is paid, the payment itself becomes a new investigative thread. Ransomware payments move through the same blockchain infrastructure as any other cryptocurrency transaction, and are subject to the same clustering and chokepoint analysis described in our guide on how blockchain investigators actually trace stolen funds. A meaningful number of ransomware operators and their laundering infrastructure have been identified, sanctioned, or in some cases had funds seized specifically because a paid ransom eventually touched an identifiable exchange or laundering service. This is part of why some paid ransoms have, in rare but documented cases, been partially recovered by law enforcement well after the fact, though this remains the exception rather than something any victim organization should plan or budget around.
Cryptocurrency's usefulness to ransomware operators comes from speed, reach, and irreversibility, not true untraceability. Blockchain analysis has become sophisticated enough that a meaningful share of ransomware payments are eventually connected to identifiable infrastructure, even though that tracing rarely happens fast enough to prevent the initial payment or guarantee its return.
What This Means Going Forward
Ransomware is not disappearing, and the shift toward higher demands, smaller more numerous operators, and increased use of privacy coins suggests the groups behind these attacks are adapting to the pressure that tracing and law enforcement disruption have created, rather than being deterred by it entirely. For organizations facing an active ransomware incident, the practical guidance from CISA and the FBI remains consistent: avoid paying where possible, report the incident promptly, and involve experienced incident response and, where cryptocurrency has already been paid, blockchain tracing expertise as early as possible in the response.
- Engage legal counsel and an incident response firm before making any payment decision, not after
- Screen any known ransomware wallet address or group identity against current sanctions lists before authorizing payment
- Preserve forensic evidence of the intrusion itself, separate from the ransom note and payment demand, since this supports both insurance claims and any later law enforcement referral
- Report the incident to a local FBI field office or through IC3 regardless of the payment decision
- Document every transaction hash and wallet address involved if a payment is made, since this becomes the starting point for any tracing effort
Frequently asked questions
Bank transfers require an account at a regulated institution, are reversible in some circumstances, and are subject to identity verification and anti money laundering controls that would quickly expose the recipient. Cryptocurrency allows instant, irreversible, cross border payment without those same barriers, which is why it remains the near universal demand despite growing traceability.
CISA and the FBI consistently discourage payment, since it does not guarantee data recovery, funds further criminal activity, and can invite repeat targeting. Organizations facing an active incident should weigh that guidance against their specific operational situation, ideally with experienced incident response and legal counsel, rather than defaulting to payment under pressure.
Often to some degree, yes. Ransomware payments move through the same public blockchain infrastructure as any cryptocurrency transaction and can be analyzed using clustering techniques to identify wallets and, in some cases, connect them to exchange accounts or known criminal infrastructure, though privacy coins and sophisticated laundering can significantly limit what tracing can establish.
Ransomware groups appear to be compensating for a declining payment rate by demanding larger amounts per successful attack, and by targeting organizations they assess as more likely to pay or more capable of paying a larger sum, rather than relying on a high volume of smaller, more reliable payments.
It can, primarily where the recipient wallet or the ransomware group behind it is on a sanctions list maintained by the Office of Foreign Assets Control. This is why legal counsel typically insists on screening known wallet addresses against sanctions lists before any payment is authorized, regardless of how urgent the operational pressure to pay may feel.
Sources and further reading
- Crypto Ransomware: 2026 Crypto Crime Report · Chainalysis
- #StopRansomware: Play Ransomware · Cybersecurity and Infrastructure Security Agency
- #StopRansomware · Cybersecurity and Infrastructure Security Agency