Indian companies paid USD 481,636 on average for cyber attack demands: Report
Indian companies paid a median payment of USD 481,636 (over Rs 4 crore), spending an average of USD 1.01 million on recovery, highlighting the broader financial toll of ransomware cyber attacks, says a report by UK-based global security solution firm Sophos.

- Country:
- India
Indian companies paid a median payment of USD 481,636 (over Rs 4 crore), spending an average of USD 1.01 million on recovery, highlighting the broader financial toll of ransomware cyber attacks, says a report by UK-based global security solution firm Sophos. It stated that the median ransom demand fell by 52 per cent, from USD 2 million to USD 961,289, while the median payment dropped even more sharply by 79 per cent.
The report said that about 41 per cent of Indian organisations paid less than the original demand, nearly half paid the full amount, and 12 per cent paid even more, underscoring the unpredictable outcomes many face during ransomware incidents. The report, whose findings are based on a survey, claimed that nearly 53 per cent of Indian companies paid the ransom to get their data back, which is a considerable drop from the 65 per cent reported last year.
The sixth annual State of Ransomware 2025 report surveyed around 3,400 IT and cybersecurity leaders across 17 countries, including 378 organisations in India that were hit by ransomware in the last year. The report added that exploited vulnerabilities were the most common technical root cause of attack, used in 29 per cent of attacks. These are followed by compromised credentials, which were the start of 22 per cent of attacks. Malicious emails were used in 21 per cent of attacks, the report said.
The report said that from an operational perspective, 41 per cent of organisations cited a lack of people or capacity and/or poor-quality protection as common root causes, while 39 per cent acknowledged that not having the necessary cybersecurity products or services played a factor in their organisation falling victim to ransomware. According to the survey, which was conducted between January and March this year, 31 per cent of Indian organisations reported data theft in attacks involving encrypted data, representing a modest decrease from 34 per cent the previous year.
The report claimed USD 1 million or more was demanded in ransom for 49 per cent of Indian organisations, down from 62 per cent the previous year. (ANI)
(This story has not been edited by Devdiscourse staff and is auto-generated from a syndicated feed.)