Press Releases
New ExtraHop® Research Helps Organizations Predict Where Ransomware May Strike Next
August 6, 2024
Analysis identifies ransomware trends across various industries and geographies
SEATTLE – August 6, 2024 – ExtraHop®, a leader in cloud-native network detection and response (NDR), today released its global ransomware trends report, a data-driven analysis of ransomware impacts across geographies, industries, and organizations of different sizes.
According to the research, security leaders report that they are increasingly being targeted by ransomware actors, averaging nearly eight incidents per year and paying out an average of just under $2.5 million in ransom payments. And while ransomware activity is up across the board, some businesses find themselves to be a more likely target, depending on different demographics, such as the markets in which they operate or size of their organizations.
The U.S. is feeling the heat.
U.S. organizations felt the impact of ransomware the most, experiencing the highest number of incidents on average and paying out the largest ransoms (nearly $2 million more than the global average). German respondents, on the other hand, experienced the fewest incidents.
Governments are paying big ransoms.
Despite stating ransomware isn’t its biggest risk, the government sector averaged more than eight attacks last year and had one of the largest average ransom payments of $3.8 million. The government sector also noted the largest percentage of organizations paying more than $25 million in ransom payments.
Bigger isn’t always better.
The larger the company, the more likely it was to experience a ransomware incident. Organizations with more than 5,000 employees were more likely to pay the ransom every time and, on average, paid more than $4 million in ransom payments.
“Ransomware is targeting some organizations more than others, but despite this notion, everyone needs to be prepared to curtail exposure to the risks and damage posed by an incident,” said Mark Bowling, Chief Information Security and Risk Officer at ExtraHop. “As ransomware continues to find ways to bypass and evade existing security controls, we can anticipate that these statistics will only grow more dire. Amid high-profile political elections and a growing call for regulatory action across the globe, it is time that the cybersecurity industry comes together to develop and adopt a more resilient security framework that can identify a ransomware attack before it devastates entire organizations, industries, and even economies.”
Read the full report, “Global Ransomware Trends: Predicting Attackers’ Next Victims.”
About ExtraHop
ExtraHop empowers enterprises to stay ahead of evolving threats with the most comprehensive approach to network detection and response (NDR).
Since 2007, the company has helped organizations across the globe extract real-time insights from their hybrid networks with the most in-depth network telemetry. ExtraHop uniquely combines NDR, network performance management (NPM), intrusion detection (IDS), and packet forensics in a single, integrated console for complete network visibility and unparalleled context that supports data-driven security decisions. With a powerful all-in-one sensor and cloud-scale machine learning, the ExtraHop RevealXTM platform enhances SOC productivity, reduces overhead, and elevates security postures.
Unlock the full power of network detection and response with ExtraHop. To learn more, visit www.extrahop.com or follow us on LinkedIn.
© 2025 ExtraHop Networks, Inc., RevealX, RevealX 360, RevealX Enterprise, and ExtraHop are registered trademarks or trademarks of ExtraHop Networks, Inc.