Ransomware Payment Trends Q2 2026: What the Coveware by Veeam Report Reveals

The Coveware by Veeam Q2 2026 report shows ransomware payments splitting sharply, with averages climbing while medians fall, reflecting a wider gap between mass-extortion incidents and smaller cases.

Ransomware Payment Trends Q2 2026: What the Coveware by Veeam Report Reveals

Ransomware payment activity in Q2 2026 told a story of two very different economies running side by side. According to the latest Coveware by Veeam quarterly report, the average ransom payment climbed 176 percent from Q1 to roughly $1.88 million, while the median payment dropped by about 50 percent to around $150,000. That wide divergence is the most important data point of the quarter, because it shows that a small number of unusually large payoffs are pulling the average away from what most victims actually experience.

For website owners, hosting customers, and the developers and agencies who support them, the takeaway is straightforward: ransomware actors are not behaving like a single, predictable threat. They are mixing high-value data theft with low-value encryption-only attacks, and the risk picture for any single business depends heavily on which kind of incident it faces.

Key Takeaways

  • The average ransom payment in Q2 2026 rose 176 percent quarter over quarter, while the median fell about 50 percent, signaling a widening outcome gap.
  • Most of the large payments were tied to data exfiltration and double-extortion cases, not to straightforward encryption events.
  • Historical outcome averages can hide rare but damaging results, including cases where paid ransoms did not actually protect stolen data.
  • SaaS supply chain compromises are creating repeat exposure for the same enterprise customers within a single calendar year.
  • Defenders should plan for both the statistically common outcome and the low-probability, high-impact scenario.

Why Average and Median Ransoms Diverged

When the average rises while the median falls, the distribution of payments is stretching. The Coveware by Veeam report attributes the gap primarily to a handful of high-value extortions that involved data exfiltration rather than traditional encryption-only ransomware.

For practitioners, this means a single number like "the average ransom is $1.88 million" can be misleading. A business is far more likely to face something closer to the median than the average, unless it holds regulated data, large customer databases, or intellectual property that an attacker can monetize through resale or public shaming.

Exfiltration-Driven Extortion Is Reshaping Risk

The Q2 2026 figures underline a shift that defenders have been tracking for several quarters. In those cases, the negotiation leverage is based on the value of the data, not on the cost of restoring systems.

This matters for hosting customers in particular. If that data is exfiltrated, the extortion demand is driven by the sensitivity of the records, not by the size of the website.

Ransom Payments Do Not Guarantee Data Deletion

One of the strongest warnings in the Coveware by Veeam commentary is that paying a ransom is not a reliable way to ensure stolen data is actually deleted.

In the Icarus case, Klue was hit through a coordinated supply chain attack that exfiltrated millions of CRM records. The lesson echoed in the report is simple: outcomes that look statistically rare can still occur, and "regression to the mean" thinking can leave organizations exposed to tail events that actually happen more often than expected.

Comparing Q1 and Q2 2026 Ransomware Payment Metrics

MetricQ1 2026Q2 2026Direction
Average ransom paymentApproximately $681,000 (implied by 176% rise)$1,880,612Up sharply
Median ransom paymentApproximately $300,000 (implied by 50% drop)$150,000Down sharply
Primary driver of large paymentsMix of encryption and exfiltrationData exfiltration and double extortionShift toward exfiltration
Outcome volatilityModerateHigh, with rare events occurringIncreasing

What This Means for Website Owners and Hosting Customers

The Q2 2026 numbers reinforce a few practical priorities that go beyond patching and antivirus:

  • Treat backups and restore testing as a core control, not a compliance checkbox. Many smaller victims can recover from encryption without paying if they have clean, offline, and tested backups.
  • Inventory the data you actually store. Customer records, sales communications, and pricing details are exactly the categories that drove the largest Q2 payoffs.
  • Watch for supply chain risk. When a SaaS vendor you depend on is breached, your data can be exposed even if your own environment is secure.
  • Plan for both the common case and the unusual case. Tabletop exercises that only model average outcomes miss the scenarios that actually drive large losses.
  • Evaluate your hosting and infrastructure posture for resilience, including the geographic distribution of workloads through providers with multiple SiteCountry Data Centers.

How Incident Response Teams Should Read the Data

For incident response vendors and legal advisors, the report is a reminder that outcome forecasts should not rely on historical averages alone. Qualitative factors such as law enforcement pressure, global health events, or shifting criminal alliances can dramatically change what actually happens during a negotiation.

Translating that into practical advice: counsel and responders should present decision-makers with both the central outcome and a clearly explained tail-risk scenario. Avoid framing the choice as "pay and the data is deleted" versus "refuse and recover." The honest framing is closer to "pay, recover, and still face uncertain data exposure" versus "refuse, recover from backups, and accept the possibility of public data release."

For organizations reviewing how they pay for hosting and infrastructure, it is also worth confirming that vendor billing and account recovery workflows are documented and resilient, including verifying supported SiteCountry Payment Methods in advance of an incident so that emergency spending is not blocked by payment-method confusion.

Looking Ahead to the Rest of 2026

If Q2 is any indication, the rest of 2026 is likely to feature a bimodal extortion market: many smaller victims paying modest sums for encryption-only recovery, and a smaller pool of high-value victims paying multi-million-dollar amounts to limit the fallout from large-scale data theft. SaaS supply chain compromises, in particular, look set to keep producing repeat exposure for enterprise customers who thought a single incident was behind them.

Defenders should expect more cases like the Klue incident, where data continues to circulate even after payment. That trend alone argues for treating exfiltration containment, including rapid detection of data egress and tight controls on third-party integrations, as a top priority.

Frequently Asked Questions

What did the Coveware by Veeam Q2 2026 report say about ransomware payments?

The report found that the average ransom payment in Q2 2026 rose 176 percent from Q1 to $1,880,612, while the median payment fell 50 percent to $150,000. The gap was driven by a small number of large payments tied to data exfiltration cases.

Why are average and median ransom payments moving in opposite directions?

The average is pulled up by a handful of unusually large payoffs, while the median reflects the typical victim. When those two numbers diverge, it usually means a few extreme cases are distorting the overall picture rather than a uniform rise in what every victim pays.

Does paying a ransom actually protect stolen data?

Not reliably. The Coveware by Veeam report cites past examples, including LockBit and the recent Icarus-linked Klue supply chain attack, where data resurfaced or remained in criminal hands even after payment. Paying may reduce immediate pressure, but it does not guarantee deletion.

Why are SaaS supply chain attacks driving extortion outcomes?

When attackers compromise a SaaS provider, they can reach many customers at once and exfiltrate large volumes of CRM, sales, and pricing data. That shared data pool can be extorted repeatedly, which is why enterprise customers are seeing the same exposure multiple times in a single year.

What should small businesses and hosting customers do differently after this report?

Focus on tested backups, clear data inventories, supply chain risk reviews, and incident response plans that account for both common and tail-risk outcomes. The goal is to be able to recover without paying when possible, and to make informed decisions about data exposure when paying is being considered.

Conclusion and Action Checklist

The Q2 2026 ransomware payment data shows an extortion market that is more uneven, more dependent on stolen data, and less predictable by historical averages. Use this checklist to guide next steps:

  • Confirm that backups are offline, immutable, and tested for full restore at least quarterly.
  • Maintain an up-to-date inventory of customer and business data, including what is stored in third-party SaaS tools.
  • Review SaaS vendor security posture and contract terms for breach notification and cooperation.
  • Run an incident response tabletop that includes both a routine encryption case and a high-impact data exfiltration case.
  • Document decision criteria for paying or not paying, including legal counsel and insurance input, before an incident occurs.
  • Verify that hosting and infrastructure providers support secure, documented payment and account recovery workflows.