ExtraHop Study Finds 49% of Ransomware Victims Detect Intrusion Only After Data Loss
A new ExtraHop Global Threat Landscape Report based on a survey of more than 1,800 security leaders shows that 49% of organizations hit by ransomware only discover the breach after data has been stolen, up from 31% a year earlier. The average dwell time before detection is 2.5 weeks, and 14% of victims remain unaware of the attack until they receive a ransom demand, compared with 6% previously.
While the average ransom payment fell to $2.8 million from $3.6 million, the proportion of victims who pay rose sharply to 83% from 70% last year. Respondents reported roughly 30 hours of downtime per incident. The report highlights that AI‑related infrastructure is now the top perceived cybersecurity risk, with 55% of respondents naming AI agents, generative AI applications, and related services as their biggest exposure. Threat groups LockBit and RansomHub were the most frequently detected, whereas detections of APT41 fell by half.
Despite rising AI adoption, security operations centers still rely heavily on manual processes: 42% of respondents said detection still required manual effort, and similar levels of manual work were reported for alert triage, investigation and response. Factors prolonging dwell time include encrypted channels (41%), legitimate‑looking activity (38%), use of high‑privilege credentials (34%) and alert fatigue (30%).