58% Of Retailers Hit By Ransomware Pay The Ransom: Security Survey


Mohul Ghosh

Mohul Ghosh

Nov 05, 2025


The global retail industry continues to face severe ransomware threats, losing millions to increasingly sophisticated cyberattacks even as defensive capabilities improve. Sophos’ latest State of Ransomware in Retail report highlights that ransomware remains one of the most financially damaging risks for retailers, driven by stealthy infiltration techniques, escalating ransom demands, and operational disruptions.

58% Of Retailers Hit By Ransomware Pay The Ransom: Security Survey

Unknown Security Gaps: The Biggest Threat

Sophos found that 46% of ransomware attacks in retail originated from unknown security gaps, underscoring persistent visibility challenges. While known vulnerabilities remain a major entry point, retailers are increasingly being targeted through overlooked weaknesses in remote access systems and internet-exposed infrastructure.


Ransom Demands Surge, Retailers Still Paying

The median ransom demand doubled to $2 million, while average payments rose to $1 million, reflecting a more aggressive posture from cybercriminals. Although some companies successfully negotiated lower payments, 58% of retailers whose data was encrypted still paid ransom, highlighting the urgent need for stronger recovery mechanisms.


Encryption Falling, But Attackers Are Adapting

For the first time in five years, data encryption rates dropped to 48%, indicating improved early-attack detection. However, attackers have shifted tactics, tripling extortion-only attacks—from 2% in 2023 to 6% in 2025—where data is stolen and used for blackmail without encryption.


Financial and Operational Damage Persists

Despite improvements, ransomware remains costly. Average recovery expenses (excluding ransom) have fallen to $1.65 million, still a major burden for retailers. The attacks also took a human toll: 47% of IT teams reported increased pressure, and 26% of retailers replaced leadership after encryption-related incidents.


Limited Expertise and Patch Gaps Hampering Defense

A lack of in-house expertise (45%) and gaps in security coverage (44%) were major contributors to successful attacks. Many retailers continue to struggle with timely patching, real-time threat visibility, and round-the-clock monitoring.


Industry’s Path Forward

Sophos recommends retailers strengthen risk management by improving asset visibility, patching aggressively, practicing incident response drills, and adopting Managed Detection and Response (MDR) services to mitigate sophisticated threats. As retail digitization accelerates, ransomware readiness is now central to ensuring business continuity and protecting customer trust.



Mohul Ghosh
Mohul Ghosh
  • 3995 Posts

Subscribe Now!

Get latest news and views related to startups, tech and business

You Might Also Like

Technology
Jun. 2, 2023

Future-Proofing Financial Operations: The Impact of Guru4Invest on Business Sustainability

As global markets grow increasingly complex, businesses face significant challenges in maintaining financial stability. Inefficient resource allocation and a lack of timely insights can prevent companies from reaching their full potential. To address these issues, organizations need tools that offer clear direction and practical solutions. Guru4Invest meets these demands by delivering innovative strategies to optimize […]

Technology
Sep. 8, 2022

Samsung Launches The Wall All-In-One and Flip Pro: Is This The Future Of Display Technology?

Samsung has launched The Wall All-In-One – the modular MicroLED it says is revolutionizing the future of display and the Flip Pro, which is an interactive display. Both were unveiled at the InfoComm India 2022 which is India’s Professional AudioVisual (Pro AV) and Systems Integration Technology Exhibition. This took place in Mumbai from September 5-7. […]

Technology
Jul. 28, 2022

Google Street View Launches In India Across These 10 Indians Cities! Plans To Expand To 700,000 Kms, 50 Cities In 2 Years

Google’s Street View is finally available in India a decade after it was prevented from capturing data for its Street View services. Second coming Street view offers a 360-degree interactive panorama feature initially for 10 Indian cities with data from local partners Tech Mahindra and Mumbai-based Genesis International. Its entry into India is facilitated by […]

Technology
Jul. 10, 2022

This Electricity-Free Cooler Developed By IIT Researchers Can Replace Air Conditioners! How It Work?

Indian Institute of Technology Guwahati researchers have built a ‘Radiative Cooler’ which does not require electricity to operate. This is an affordable and efficient ‘passive’ radiative cooling system that can serve as an alternative to ACs. The coating material is an electricity-free cooling system that can be applied in the rooftops and functions during both […]

Recent Posts

Related Videos

   

Subscribe Now!

Get latest news and views related to startups, tech and business

who's online