cxo voice
  • Business
  • Technology
    • Artificial Intelligence
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • CXO Insights
  • Cyber Security
  • CXO Interviews
No Result
View All Result
  • Business
  • Technology
    • Artificial Intelligence
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • CXO Insights
  • Cyber Security
  • CXO Interviews
No Result
View All Result
Leaders Talk and Latest Tech News | CXO VOICE
No Result
View All Result
Home Cyber Security

58% of retailers hit by ransomware paid the ransom: Report

Arshi Khan by Arshi Khan
November 4, 2025
ransomware retailers

A industry report focused on retail ransomware shows that 58% of retail organisations whose data was encrypted paid the ransom to recover their data, a sharp rise from prior years and well above the cross-sector average. Sophos released its fifth annual Sophos State of Ransomware in Retail report, a vendor-agnostic survey of IT and cybersecurity leaders across 16 countries. This year’s report reveals that nearly half (46%) of retail ransomware incidents were traced to an unknown security gap, underscoring ongoing visibility challenges across the retail attack surface.

In the past year, Sophos X-Ops observed almost 90 different threat groups attack one or more retailers with ransomware or extortion. The most active groups were Akira, Cl0p, Qilin, PLAY, and Lynx. After ransomware, the second most common type of attack was account compromise. Like many other industries, retailers are also often targeted by business email compromise (BEC) groups. These groups try to trick companies into sending money to the wrong accounts.

“Retailers all over the world are facing more complicated threats. Cyber Attackers are always looking for weaknesses, especially in systems connected to the internet. Ransom demands are rising. The good news is that many retailers are starting to understand this and are investing in better cyber defences to stop attacks early and recover more quickly,” says Chester Wisniewski, director, global field CISO at Sophos.

Limited in-house expertise was the second-most common operational driver of compromise (45%), followed by insufficient protection (44%). If retailers lack the right skills and protections, it is hard for them to detect and stop cyber attacks.

The average ransom payment in retail increased by 5% ($1 million in 2025, up from $950,000 in 2024). However, the average payment is only half of what criminals initially ask for. This shows that retailers are more likely to resist high demands and may be getting expert help to handle ransomware attacks.

According to the State of Ransomware in Retail report 2025

Data encryption is becoming less common, but criminals are changing their tactics. The number of retailers hit by extortion-only attacks has tripled, from 2% in 2023 to 6% in 2025.

Backup rates are falling; 62% of retailers who experienced attacks restored their data using backups, the lowest rate in four years.

Retailers are pushing back against ransom demands. Only 29% paid the full amount asked at first. 59% paid less than the first request, and 11% paid more.

Recovery costs are going down. The average cost to recover from a ransomware attack (not including the ransom payment) dropped by 40% in the last year to $1.65 million, the lowest in three years.

Ransomware attacks had a big effect on teams. Almost half (47%) of retail IT and cybersecurity teams felt more pressure after experiencing data encryption, and in 26% of cases, leaders were replaced because of attacks.

Marks & Spencer (M&S) (Ransomeare reported in 2025): a ransomware incident disrupted online operations and store support systems, with analysts estimating tens of millions in short-term profit impact and negative market reaction; M&S reportedly chose not to pay and pursued system rebuild, illustrating the tradeoff between paying vs rebuilding (and the possible long recovery cost of refusal).

Also Read: Top 10 agentic AI threats, and how to defend against them

Arshi Khan

Arshi Khan

A research-focused journalist covering enterprise technology, AI, and cybersecurity. Reporting combines market data, expert interviews, and on-ground industry inputs to produce accurate, context-driven stories for business decision-makers. She can be reached at [email protected]

Related Posts

AI-enabled cyberattacks
Cyber Security

2026 X-Force Threat Index Warns of AI-Enabled Exploits and Rising Cyberattacks

February 26, 2026
Kyndryl cyber
Cyber Security

Kyndryl Launches First Cyber Defense Operations Center in Bengaluru

February 19, 2026
Palo Alto Acquisition of CyberArk
Cyber Security

Palo Alto Networks Completes Acquisition of CyberArk to Lead in AI-Era Security

February 12, 2026
Cyber Resilience
Cyber Security

Why Identity Will Define Enterprise Cyber Resilience in an AI-First World

February 10, 2026
Cyber Attacks AI
Cyber Security

Cyber Attacks Surge 70% as AI-Powered Threats Reach Record Levels, Check Point Report

January 29, 2026
Check Point Exposure Management
Cyber Security

Check Point Unveils AI-Driven Exposure Management to Close Cybersecurity Remediation Gap

January 22, 2026
Cybersecurity predictions 2026
Cyber Security

Prioritizing Proactive Cybersecurity as a Strategic Advantage: The Top 5 Predictions for India in 2026

December 23, 2025
Home Routers
Cyber Security

The Home Router Crisis of 2026: How India’s Living Rooms Became the New Cyberwar Frontline

December 23, 2025
Load More

More Articles

Strait of Hormuz

Chokepoint in Crisis: How important is the Strait of Hormuz for India?

by CXOVoice Editorial Team
March 2, 2026

OpenAI

Amazon, Nvidia, and SoftBank Power OpenAI’s Historic $110 billion Capital Raise

by Deepa Sharma
February 28, 2026

HCLTech and IIT Kanpur

HCLTech, IIT Kanpur Forge Alliance to Accelerate Deep Tech Innovation for GCCs

by Deepa Sharma
February 27, 2026

MeltPlan

MeltPlan Raises $10 Million Seed Round to Build AI Layer for Preconstruction Planning

by Arshi Khan
February 26, 2026

Get Weekly CXO Intelligence.

[wpforms id="31079"]

CXO Insights

AI India
Artificial Intelligence

AI as a Public Good: From Democratic Principles to Ground-Level Practice

by News Desk
February 13, 2026
Cyber Resilience
Cyber Security

Why Identity Will Define Enterprise Cyber Resilience in an AI-First World

by Sunil Sharma
February 10, 2026
HDDs storage
Opinion

5 Reasons HDDs Will Continue to Dominate Enterprise Storage in the AI Era

by Owais Mohammed
January 13, 2026
Cybersecurity predictions 2026
Cyber Security

Prioritizing Proactive Cybersecurity as a Strategic Advantage: The Top 5 Predictions for India in 2026

by Heba Sayed
December 23, 2025

CXO Interviews

1Point1
Business

How 1Point1 Solutions Is Betting Its Future on AI to Redefine BPM

>
NewgenONE
Business

Reimagining Enterprise Transformation: Varun Goswami on the Future of NewgenONE and AI-Driven Automation

>
Jagat Shah, Chairman & CEO of MITSUMI Group
Business

Leadership in Emerging Markets: Exclusive Interview with Jagat Shah, Chairman & CEO of MITSUMI Distribution

>
Tokenization
Blockchain

Revolutionizing Finance: An Exclusive Interview with Sid Ugrankar, Co-founder of Qila.io on the Future of Blockchain and Tokenization

>

CXOVoice.com is a leading online publication for CXOs, entrepreneurs, senior leaders, developers, and industry professionals. We publish informed analysis, news reporting, expert commentary, and expert insights across enterprise technology, digital transformation, cybersecurity, data, AI, sustainability, and governance.

Connect with us

Easy Links

  • Cryptocurrency
  • Company Announcements
  • Event
  • Blockchain
  • Resources & Downloads
[wpforms id="30660"]
  • Home
  • About Us
  • Contact Us
  • Advertise
  • Privacy & Policy
  • Editorial Policy
  • Feedback

Copyright © 2026 CXOVoice - All Rights Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

Our Spring Sale Has Started

You can see how this popup was set up in our step-by-step guide: https://wppopupmaker.com/guides/auto-opening-announcement-popups/

No Result
View All Result
  • Home
  • News
  • Business
  • Technology
  • Cyber Security
  • Opinion

Copyright © 2026 CXOVoice - All Rights Reserved