The largest open dataset of ransomware payments — Ransomwhere — has tracked just over $1.02 billion in on-chain ransoms across its entire history. That number is smaller than most people expect, and it’s the most instructive thing about it: it is a documented floor, not a total. Here’s who tops the leaderboard, and why the real figure is many times higher — a distinction that matters enormously if you’re trying to size your own cyber risk.

The leaderboard: who has been paid the most

Aggregating the public Ransomwhere export by family, these are the highest-earning named ransomware operations by tracked, crypto-visible payments (with the number of tracked victim wallets alongside):

Tracked on-chain payments · all time

Conti
$102m
Cuba
$60m
NetWalker
$27m
BlackSuit
$25m
BlackCat / ALPHV
$22m
Locky
$14m
REvil
$12m
RagnarLocker
$11m
DarkSide
$9m

Conti leads at roughly $101.6M (≈€93M) across ~103 wallets — the most-documented enterprise-scale operation in the set. DarkSide (the Colonial Pipeline crew) and REvil sit mid-table. The outlier is Locky: $14M spread across 7,037 wallets — the commodity “spray-and-pray” era, tiny per-victim demands at massive scale. Conti and Cuba are the opposite: few victims, huge cheques.

Why the real number is far higher

The all-time total sounds almost modest for a decade of global ransomware. It isn’t the true figure — it’s the slice that is provable on-chain and attributed. Four gaps sit underneath it:

Better yardsticks: Chainalysis and Coveware

Ransomwhere is the open, crowdsourced view — valuable for per-family transparency, but an undercount by design. Two commercial sources are more authoritative for the questions they answer:

The market has shifted decisively: attacks up, payments down. Chainalysis put 2025 payments at ~$820M with only ~28% of victims paying (a historic low), even as leak-site victims hit a record — NCC Group counted 7,874 in 2025, up ~50% year on year. Fewer companies pay; the criminals compensate with volume and bigger data-theft demands.

Together these sources bracket the picture: Chainalysis for the ecosystem total, Coveware for the per-incident reality, and Ransomwhere for open, per-family detail. None of them, though, tells you what an incident would cost your organisation.

The CFO takeaway

Attacker revenue is the wrong compass for your risk. A leaderboard of what crews have been paid tells you nothing about what an incident would cost you — and, as the numbers show, it dramatically undercounts even the attacker side. This is the same trap as modelling exposure on insurance-claims data: a capped, backward-looking view that hides the majority of true loss. The defensible move is to model yourown Expected Annual Loss from your live exposure — not to extrapolate from someone else’s ransom cheque.

What to do with this

Use the payment data for what it’s good at — showing that ransomware is a real, industrial economy — and don’t use it for what it can’t do: sizing your exposure. For that, start from your own attack surface. Confirm whether NIS2 applies to you, watch the live EU picture on the EU Ransomware Tracker, then run a free CRQ simulation to turn your exposure into a projected annual loss in euros — a number you can defend to a board, unlike a leak-site revenue guess.

Sources & references

All figures are tracked, crypto-visible payments — a documented floor, not the true total. Family attribution for on-chain payments is inherently incomplete; treat the leaderboard as directional.