Did you know cyber extortion statistics are becoming more alarming every day? Cybercriminals are using fear and pressure to extort money, and it’s hitting everyone—from small businesses to big corporations.
Did you know that, according to IBM Security X-Force 2023, extortion was involved in 27% of cyberattacks? This clearly shows how ransomware tactics are becoming the go-to strategy for attackers, making it a serious problem.

In this report, I’ve gathered some essential cyber extortion statistics to help you understand what’s happening and why it matters. Let’s find out the numbers and see what they reveal about this growing threat.
VPNRanks’ Insights: Analyzing Cyber Extortion Statistics
VPNRanks used past data to predict cyber extortion statistics for 2025. This analysis helps anticipate future threats and prepare for evolving cyber risks:
- 📈 Cyber extortion reports could reach 5,900 by 2025.
- 💰 The average ransom payment for cyber extortion is expected to reach $2.99 million by 2025.
- 📊 In 2025, the ransomware extortion totals could reach $224 million.
- 🏥 Ransomware extortion attacks on healthcare organizations could reach 420 incidents by 2025.
Disclaimer: These figures are estimates provided by VPNRanks, based on historical data and current trends analyzed through predictive models. They represent potential future scenarios and should not be considered exact predictions. The actual outcomes may vary depending on various factors, including new interventions and changes in online behavior.
What is Cyber Extortion?
Cyber extortion involves threatening or executing an attack while demanding money or specific actions to halt or fix the situation. This crime leverages fear and urgency, often targeting organizations’ vulnerabilities.
These attacks commonly manifest as ransomware, where payment is demanded to undo harm, or DDoS assaults, which disrupt systems and steal sensitive data, with threats of public exposure.
Surge in Cyber Extortion Cases
📈VPNRanks predicts cyber extortion reports to reach 5,900 by 2025, fueled by advanced ransomware tactics and expanding attack surfaces.

Data Collection
The data on the increase in cyber extortion reports has been sourced from RPC Legal, highlighting a sharp rise in incidents reported to Action Fraud. This showcases the growing prevalence of ransomware and related extortion tactics.
| Year of Survey | Number of Reports to Action Fraud | Percentage Increase |
|---|---|---|
| 2021 | 2,300 | – |
| 2022 | 3,200 | 39% |
VPNRanks Future Predictions
VPNRanks predicts cyber extortion reports to rise to approximately 5,900 by 2025, driven by factors like the increasing sophistication of ransomware-as-a-service, growing attack surfaces, and inadequate cybersecurity measures in organizations.
This calculation was made using a linear regression model based on the reported increase in cases from 2021 to 2022, indicating a consistent upward trend.
Understanding How Cyber Extortion Works
Extortion cybercrime often starts with attackers infiltrating a victim’s system or network using phishing emails, malicious ads, or compromised websites.
These methods grant access to sensitive data, which attackers exploit to make demands. Interestingly, some cybercriminals outsource these operations via ransomware-as-a-service or cybercrime-as-a-service platforms, amplifying the scale and accessibility of such attacks.
According to a VPNRanks report, the number of cybercrime victims could rise to approximately 8.5 billion by 2025, fueled by the increasing use of outsourced attacks and sophisticated cyber extortion tactics. This highlights the growing urgency for robust cybersecurity measures to combat these evolving threats.
Ransom Payments on Cyber Extortion Victims
💰VPNRanks predicts that the average ransom payment for cyber extortion could reach $2.99 million by 2025 as ransomware attacks grow more sophisticated and cybercriminals demand higher payouts.

Data Collection
The data on ransom payments was sourced from Astra, showcasing a sharp rise in average payments for cyber extortion. This reflects the growing financial pressure on victims as attackers demand higher payouts.
| Year of Survey | Average Ransom Payment | Percentage Increase |
|---|---|---|
| 2022 | $812,380 | – |
| 2023 | $1.54 million | Nearly double (approximately 90%) |
VPNRanks Future Predictions
The average ransom payment for cyber extortion could rise to $2.99 million by 2025, driven by the increasing sophistication of ransomware tactics, reliance on cryptocurrencies, and higher stakes for targeted organizations.
This prediction was calculated using a linear regression model based on the sharp increase in ransom payments observed between 2022 and 2023.
Cyber Extortion vs. Ransomware: What’s the Difference?
Cyber extortion encompasses a range of tactics designed to force victims into meeting attackers’ demands. It includes threats, blackmail, and other forms of coercion aimed at extracting money or valuable assets. Cyber extortion methods can vary widely, from data breaches to distributed denial of service (DDoS) attacks.
Ransomware, on the other hand, is a specific subset of cyber extortion where attackers use malicious software to lock victims out of their systems or encrypt their files. Victims are then instructed to pay a ransom, usually in cryptocurrency, to regain access to their data.
While ransomware is one form of cyber extortion online, it’s not the only method used by cybercriminals.
Total Ransomware Extortion Amounts
📊 For 2025, VPNRanks predicts that ransomware extortion totals could reach $224 million as cybercriminals leverage advanced tactics and target increasingly digital-dependent organizations.

Data Collection
The data on ransomware extortion was sourced from the National University blog, highlighting a sharp rise in both the frequency and severity of ransomware attacks. The first half of 2023 alone saw ransomware payments exceeding the total for all of 2022.
| Year of Survey | Ransomware Extortion Total |
|---|---|
| 2022 | $176 million |
| First Half 2023 | $176 million |
VPNRanks Future Predictions
The ransomware extortion totals could rise to approximately $224 million by 2025, driven by the increasing sophistication of ransomware tactics, higher ransom demands, and the growing reliance on digital infrastructure. This indicates a continued escalation in cybercriminal activities targeting vulnerable organizations.
The calculation for cyber extortion statistics was based on a linear regression model, factoring in an upward trend in extortion totals observed between 2022 and the first half of 2023.
Common Types of Cyber Extortion Attacks
Following are the different types of cyber extortion tactics used by attackers to exploit individuals and organizations:
- Cyber Blackmail: Hackers steal sensitive data and demand payment, threatening to release it if the ransom isn’t paid, as seen in the Netflix and HBO breaches in 2017.
- Database Ransom Attacks: Attackers exploit vulnerabilities in outdated or misconfigured databases, replacing data with ransom notes demanding Bitcoin payments.
- Denial of Service (DDoS) Attacks: Cybercriminals disrupt access to servers or threaten attacks, demanding payment to stop or prevent them.
- Ransomware: Victims lose access to their devices or data due to malware and are forced to pay a ransom to regain control.
- Doxing: Hackers threaten to release private information unless their demands are met, causing distress to individuals or groups.
- Phone Extortion: Attackers make direct threats over the phone, demanding payment to avoid harm to the victim or their loved ones.
- Website Extortion: Cybercriminals threaten to deface or shut down websites unless a ransom is paid.
The Impact of Cyber Extortion
Cyber extortion can have devastating consequences for companies, including data breaches, reputational damage, and financial losses. When customers lose access to services, they often turn to competitors, further impacting revenue.
Attackers also use the threat of exposing trade secrets or intellectual property to pressure victims into paying ransoms. The impact of cyber extortion spans globally, affecting businesses of all sizes.
For instance, the Colonial Pipeline ransomware attack in 2021 disrupted U.S. fuel supplies, while the University of Manchester attack in 2023 exposed over a million patient records. According to VPNRanks, ransomware attacks are expected to surge, reaching approximately 564.48 million in 2025.
Cyber Extortion in Healthcare: A Growing Crisis
🏥VPNRanks predicts that ransomware extortion attacks on healthcare organizations could reach 420 incidents by 2025 as growing vulnerabilities and reliance on digital records make the sector a prime target.

Data Collection
Cyber extortion statistics in the healthcare sector was sourced from Keepnetlabs, highlighting the alarming rise in ransomware attacks and their financial consequences.
- Ransomware attacks on healthcare organizations have surged by 264% over the past five years, marking this sector as a prime target for cyber extortion.
- The average cost of a healthcare data breach has reached approximately $10.93 million, underscoring the severe financial impact of these incidents.
VPNRanks Future Predictions
The ransomware attacks on healthcare organizations could rise to approximately 420 incidents by 2025, driven by increasing vulnerabilities in healthcare systems, reliance on digital records, and the lucrative nature of healthcare data. This trend emphasizes the urgent need for enhanced cybersecurity measures in the sector.
The prediction was calculated using a linear regression model based on a 264% rise in attacks over the past five years, projecting a consistent annual increase.
How to Prevent Cyber Extortion

Cyber extortionists continuously search for new vulnerabilities to exploit and innovative ways to threaten victims. As a result, companies must stay proactive and implement robust measures to reduce the risk of cyber extortion.
Here are some best practices for preventing cyber extortion:
- Back up and encrypt data. Regularly back up sensitive data, encrypt it, and test recovery procedures to ensure resilience.
- Authenticate. Use multifactor authentication to enhance system security and prevent unauthorized access.
- Update systems. Keep all systems and security tools updated and patched to close potential vulnerabilities.
- Educate and train. Provide employees with training to identify phishing attempts, avoid sharing sensitive data, and reduce attack surfaces.
- Have an incident response strategy. Develop and test incident response and disaster recovery plans to ensure quick recovery after an attack.
- Set up strong security measures. Use firewalls, antimalware tools, and updated antivirus software while hardening network defenses and limiting access.
- Implement risk analysis and management. Follow risk management programs, review audit logs for suspicious activity, and stay informed on emerging cyber threats through information-sharing platforms.
Real-Life Examples: Cyber Extortion Case Study

In this section, I have added a case study to provide real-world insights into the impact of cyber extortion. It highlights key events, strategies used by attackers, and the lessons learned from the incident.
Case 1: Domino’s Pizza Cyber Extortion (2014)
In 2014, the hacker group Rex Mundi claimed to have stolen the records of 650,000 Domino’s Pizza customers in Europe. They demanded a 30,000 euro ransom, threatening to release the data if their demands weren’t met. Domino’s refused to pay, instead notifying customers and advising them to change their passwords.
Impact:
Domino’s reputation faced scrutiny, but the company avoided significant long-term damage as Rex Mundi never followed through with their threat. The incident highlighted the growing risks of customer data breaches.
Lesson Learned:
- Transparency and prompt communication with customers can help mitigate reputational damage.
- Not all threats result in action; assessing the credibility of attackers is crucial.
- Proactive measures, such as advising customers to change passwords, can reduce potential risks.
Case 2: Ashley Madison Cyber Extortion (2015)
The hacktivist group The Impact Team attacked Ashley Madison, a dating site for married individuals, in 2015. They compromised data of 37 million users and demanded the removal of two dating websites owned by Avid Life Media (ALM) due to alleged fraudulent practices. When ALM refused, the group leaked sensitive customer data.
Impact:
The breach had devastating effects on Ashley Madison’s users, exposing private information and leading to public humiliation, lawsuits, and even reports of suicides. It was a major scandal in the history of cyber extortion.
Lesson Learned:
- Cyber extortion isn’t always financially motivated; ideological motives can cause significant harm.
- Weak data protection can lead to severe consequences, including loss of trust and legal actions.
- Companies must address ethical concerns, such as proper handling and deletion of user data, to avoid becoming targets.
Source: Tech Target
Insights from Experts on Cyber Extortion
In this section, I have included expert opinions to provide professional insights into the evolving landscape of cyber extortion. These perspectives shed light on effective strategies and preventive measures to tackle this growing threat.
1. Andre Ripla
Andre Ripla highlights that the evolution of cyber extortion, with threats like double and triple extortion, reflects the growing sophistication of attackers. He stresses the urgency for organizations to adopt robust cybersecurity frameworks to counteract the risks of ransomware and DDoS attacks.
Without these proactive measures, businesses face significant financial losses, operational disruptions, and reputational damage.
Ripla emphasizes that effective cybersecurity against extortion requires collaboration between the public and private sectors.
Governments must create stringent legal frameworks while businesses prioritize incident response planning and employee training. Such coordinated efforts, Ripla notes, are critical to addressing the escalating threat landscape.
2. Matt Yarranton
Matt Yarranton highlights cyber extortion as a growing concern, with small businesses being four times more likely to be targeted than larger ones. He emphasizes the rise of double extortion, where attackers encrypt and steal data, threatening to leak it. In 2024 alone, over 1,000 businesses reported such incidents, with many more likely unreported.
Yarranton stresses a 77% rise in cases over the past year, with industries like healthcare and manufacturing at high risk. He notes a 96% increase in attacks in regions like the UK, driven by economic growth and shared languages. This underscores the critical need for businesses to enhance their cybersecurity defenses.
3. Mitch Redekopp
Mitch Redekopp explains that cyber extortion involves ransomware and data theft, often escalating to double extortion, where attackers threaten to leak stolen data. Small businesses are especially vulnerable, being four times more likely to be targeted. With over 1,000 cases reported in early 2024, the real numbers are likely much higher due to underreporting.
He highlights that industries like manufacturing, healthcare, and professional services are frequent targets, with cybercriminals exploiting economic growth and common languages.
Redekopp emphasizes the need for proactive measures, such as robust data backups, regular patch management, and implementing Multi-Factor Authentication (MFA) to strengthen defenses against this growing threat.
4. Lee Hewson
Lee Hewson highlights cyber extortion as a critical threat involving ransomware and double extortion, where attackers encrypt and steal data to demand ransoms. He notes a 77% surge in cases in 2024, with small businesses being four times more likely to be targeted due to their limited defenses.
Hewson points out that industries like healthcare, manufacturing, and professional services are frequent targets, with attacks doubling in regions like the UK.
He emphasizes proactive measures, including data backups, software updates, and Multi-Factor Authentication (MFA), as essential defenses to protect businesses from these growing threats.
VPNRanks’ Methodology for Cyber Extortion Predictions
In this section, I have outlined the methodology VPNRanks used to predict cyber extortion statistics for 2025. The approach combines data-driven analysis and expert insights to ensure accurate and reliable projections.
- Data Collection: VPNRanks gathered data from reputable sources, including industry reports, cybersecurity organizations, and historical trends, to identify patterns and growth rates in online extortion incidents.
- Trend Analysis: The team analyzed historical data, such as increases in ransomware attacks and financial demands, to detect consistent growth trends. This was crucial for creating a baseline for future predictions.
- Linear Regression Modeling: A linear regression model was applied to calculate future projections. This statistical approach factored in the percentage increases observed in recent years to estimate figures for 2025 and beyond.
- Expert Opinion: Insights from cybersecurity experts were incorporated to validate the projections. Their perspectives helped refine predictions, ensuring they aligned with emerging threats and industry developments.
- Validation and Cross-Referencing: The predictions were cross-referenced with similar industry forecasts to verify accuracy. This step ensured the methodology was robust and results were consistent with broader trends in cybersecurity.
Explore More In-Depth Statistics and Reports by VPNRanks
- Cybersecurity spending– Explore the stats to understand how businesses allocate resources to safeguard their digital assets.
- What gets hacked more iPhone or Android– Delve into the data by comparing vulnerabilities between these two popular platforms.
- Black Friday scams– Find out how cybercriminals exploit this shopping frenzy to target unsuspecting buyers.
- AI cyberattacks– Examine how artificial intelligence is used to defend against and execute sophisticated cyberattacks.
FAQs
What is an example of cyber extrotion
One common example of cyber extortion is ransomware. In such attacks, hackers infiltrate a network, hijack critical data, and demand a ransom—often in cryptocurrency—for its release. Victims are locked out of their digital assets until payment is made, making ransomware a prevalent and disruptive threat.
What is covered under cyber extortion?
Cyber extortion covers a variety of attack methods beyond ransomware. It includes threats to expose sensitive data, disrupt operations through DDoS attacks, or demand payment to prevent a potential security breach. These tactics leverage fear and urgency to pressure victims into compliance.
Should cyber extortion victims pay demands?
While paying a ransom may seem like a quick solution to regain access to critical files, the FBI strongly discourages it. Paying can embolden attackers, fund criminal activities, and offers no guarantee of data recovery. Instead, victims are urged to report cyber extortion threats to the FBI or the Internet Crime Complaint Center.
Is cyber liability insurance worth having?
Cyber liability insurance is increasingly valuable as it encourages businesses to adopt preventive measures while providing financial protection against cyber incidents. Many clients now require vendors to have cyber insurance as part of compliance. However, organizations should assess their specific risks and consult experts before deciding on coverage.
Conclusion
Cyber extortion remains a growing threat, targeting individuals, businesses, and critical sectors like healthcare. As tactics evolve, the frequency and severity of attacks are expected to rise, with cyber extortion statistics projecting reports to reach 5,900 by 2025. These alarming numbers underscore the urgency of strengthening cybersecurity measures globally.
The financial toll of ransomware is also escalating, with extortion totals predicted to hit $224 million by 2025. Such predictions highlight the need for proactive strategies, including robust data protection, employee training, and collaboration with cybersecurity experts to mitigate risks and safeguard digital infrastructures.