The share of companies paying ransoms to cybercriminals rose significantly in 2025, reversing two years of decline as hackers increasingly deploy artificial intelligence to conduct more sophisticated attacks. According to a study conducted by cybersecurity firm S-RM and advisory group FGS Global, 24.3 percent of businesses that suffered cyberattacks last year chose to pay ransom demands. The figure marks a steep increase from 14.4 percent in 2024 and 16.4 percent in 2023, though it remains slightly below the peak of 27.6 percent recorded in 2022.
The study suggests that companies in industrial and manufacturing sectors were particularly likely to make ransom payments in 2025. Analysts believe this trend reflects the severe operational disruption caused by ransomware attacks, which can halt production lines and cripple supply chains. When operations grind to a standstill, businesses may feel compelled to pay hackers quickly to restore systems and minimize financial losses.
Several high-profile companies experienced major cyber incidents during the year. Automaker Jaguar Land Rover was among the most prominent victims, after a cyberattack on its IT systems forced factories around the world to shut down throughout September. Major British retailers Marks & Spencer and Co-op were also targeted by hackers in 2025. None of these companies has publicly confirmed whether ransom payments were made.
While the report does not identify the businesses that paid hackers, it offers rare insight into a practice companies typically keep secret. Many organizations avoid publicly acknowledging ransom payments because doing so could signal vulnerability and potentially attract future cyberattacks.
Financially, the ransom demands varied widely. According to the research, payments ranged from as little as $10,000 to more than $1 million, with an average payout of approximately $296,000. The wide spread reflects both the size of targeted organizations and the scale of damage attackers claim they can inflict if demands are not met.
Cybersecurity experts say artificial intelligence is rapidly changing the tactics used by hackers. Jamie Smith, head of cybersecurity at S-RM, said attackers are now using AI tools to identify the most sensitive and damaging information within a company’s systems. By pinpointing critical data and tailoring threats more precisely, criminals are able to increase psychological pressure on victims and raise the likelihood of payment.
Jenny Davey, co-head of crisis management at FGS Global, described artificial intelligence as a double-edged sword for modern businesses. While AI can improve efficiency and productivity across corporate operations, she warned that it also creates new vulnerabilities that cybercriminals are quick to exploit. As companies integrate more advanced technologies into their systems, experts say the battle between cybersecurity defenses and increasingly intelligent cyber threats is likely to intensify.

