The largest open dataset of ransomware payments — Ransomwhere — has tracked just over $1.02 billion in on-chain ransoms across its entire history. That number is smaller than most people expect, and it’s the most instructive thing about it: it is a documented floor, not a total. Here’s who tops the leaderboard, and why the real figure is many times higher — a distinction that matters enormously if you’re trying to size your own cyber risk.
The leaderboard: who has been paid the most
Aggregating the public Ransomwhere export by family, these are the highest-earning named ransomware operations by tracked, crypto-visible payments (with the number of tracked victim wallets alongside):
Tracked on-chain payments · all timewallets
Conti leads at roughly $101.6M (≈€93M) across ~103 wallets — the most-documented enterprise-scale operation in the set. DarkSide (the Colonial Pipeline crew) and REvil sit mid-table. The outlier is Locky: $14M spread across 7,037 wallets — the commodity “spray-and-pray” era, tiny per-victim demands at massive scale. Conti and Cuba are the opposite: few victims, huge cheques.
Why the real number is far higher
The all-time total sounds almost modest for a decade of global ransomware. It isn’t the true figure — it’s the slice that is provable on-chain and attributed. Four gaps sit underneath it:
- Two-thirds is “unlabeled.” Of the ~$1.02B, about $682M (67%) is confirmed ransomware payment but not confidently tied to a family. Named families account for only ~$336M — a third of the tracked money.
- Modern crews are barely counted. The data lags the threat. LockBit — one of the most prolific operations ever — shows only ~$1.2M tracked; Qilin, the single most active group in the EU right now (see our Qilin profile), shows nothing. Akira shows just ~$4M on-chain here — yet the FBI and CISA put Akira’s proceeds at roughly $42M across 250+ victims by early 2024, a tenfold gap. Newer RaaS use fresh, unattributed wallets, so on-chain trackers systematically undercount them.
- Only crypto-visible payments count. Off-ramp obfuscation, mixers, and payments that were never reported or crowd-sourced never enter the dataset.
- The ransom is a fraction of the loss. Even when a payment is captured, it’s a sliver of the true incident cost — downtime, recovery, legal, regulatory and lost business dwarf it (the Qilin attack on Synnovis: a reported $50M demand versus £32M+ of direct cost to one victim).
Better yardsticks: Chainalysis and Coveware
Ransomwhere is the open, crowdsourced view — valuable for per-family transparency, but an undercount by design. Two commercial sources are more authoritative for the questions they answer:
- Chainalysis (annual Crypto Crime Report) uses the same on-chain approach with far better attribution. Its trajectory: ~$1.25B (2023) → ~$892M (2024) → ~$820M (2025) — two straight years of falling payments even as attacks surged. Two details matter. First, Chainalysis’s 2023 figure alone exceeds Ransomwhere’s entire crowdsourced all-time total — the clearest measure of how much open trackers miss. Second, the 2024 number was later revised up from the ~$814M first reported to ~$892M as more wallets were attributed — proof that even the best on-chain source undercounts at first and adjusts later.
- Coveware (by Veeam) is the best read on what a payment actually looks like, from real incident-response negotiations. The pattern into 2026: the share of victims who pay has fallen to a record low, the average is pulled up by a few large data-exfiltration cases, and realized payments land around 8.7% of the initial demand. (Q3 2025: average ~$377k, median $140k.)
The market has shifted decisively: attacks up, payments down. Chainalysis put 2025 payments at ~$820M with only ~28% of victims paying (a historic low), even as leak-site victims hit a record — NCC Group counted 7,874 in 2025, up ~50% year on year. Fewer companies pay; the criminals compensate with volume and bigger data-theft demands.
Together these sources bracket the picture: Chainalysis for the ecosystem total, Coveware for the per-incident reality, and Ransomwhere for open, per-family detail. None of them, though, tells you what an incident would cost your organisation.
The CFO takeaway
Attacker revenue is the wrong compass for your risk. A leaderboard of what crews have been paid tells you nothing about what an incident would cost you — and, as the numbers show, it dramatically undercounts even the attacker side. This is the same trap as modelling exposure on insurance-claims data: a capped, backward-looking view that hides the majority of true loss. The defensible move is to model yourown Expected Annual Loss from your live exposure — not to extrapolate from someone else’s ransom cheque.
What to do with this
Use the payment data for what it’s good at — showing that ransomware is a real, industrial economy — and don’t use it for what it can’t do: sizing your exposure. For that, start from your own attack surface. Confirm whether NIS2 applies to you, watch the live EU picture on the EU Ransomware Tracker, then run a free CRQ simulation to turn your exposure into a projected annual loss in euros — a number you can defend to a board, unlike a leak-site revenue guess.
Sources & references
- Figures: our aggregation of the public Ransomwhere dataset (all-time export; dollar values use the BTC rate on each transaction’s day — an approximate floor). Cite as: Cable, Jack (2024), Ransomwhere: A Crowdsourced Ransomware Payment Dataset, Zenodo, doi.org/10.5281/zenodo.6512122.
- Cable, Gray & McCoy — Showing the Receipts: Understanding the Modern Ransomware Ecosystem (eCrime 2024) — the source of the high-confidence “unlabeled” payments.
- Gray et al. — Money Over Morals: A Business Analysis of Conti Ransomware (eCrime 2023); Oosthoek, Cable & Smaragdakis — A Tale of Two Markets: Investigating the Ransomware Payments Economy (CACM 2022).
- Akira proceeds (~$42M, 250+ victims, as of 1 Jan 2024): CISA/FBI joint advisory AA24-109A — #StopRansomware: Akira Ransomware.
- Ecosystem totals: Chainalysis — 2026 Crypto Crime Report (ransomware) (~$1.25B in 2023, ~$892M in 2024, ~$820M in 2025; 28% pay rate), and the 2025 report (the original $813.55M 2024 figure, since revised up). Per-incident payments: Coveware by Veeam quarterly reports. Leak-site victim volume (7,874 in 2025): NCC Group monthly threat pulse.
All figures are tracked, crypto-visible payments — a documented floor, not the true total. Family attribution for on-chain payments is inherently incomplete; treat the leaderboard as directional.