Skip to main content

Incident archive

Past major attacks: who was asked to pay, who paid, and what it cost

For each incident we record the ransom demand, whether it was paid, the operational downtime that followed, and the estimated revenue impact — so you can weigh prevention against consequence.

Showing 14 of 14 incidents

14

Incidents shown

10.7

Avg. downtime (days)

US$2462m

Est. revenue lost

21%

Paid the ransom

Disclosed ransom payments in this selection total US$37.4m.

Case-by-case

Ransom demands, payment decisions and business impact

Estimates are drawn from public disclosures, regulator statements and company reporting.

A.P. Moller-Maersk

Shipping · Denmark · 2017 · NotPetya (Sandworm)

Malware
Ransom refused

Destructive wiper malware spread through a compromised Ukrainian tax software update and destroyed 49,000 laptops and 4,000 servers.

Ransom demanded
US$300
Ransom paid
No
Downtime
10 days
Est. revenue lost
US$300m

Downtime and revenue-loss figures are estimates compiled from public disclosures, regulator statements and company reporting. Where a company did not disclose specifics, the figure is modelled from comparable incidents in the same sector and attack class. Treat these numbers as planning guidance for risk conversations, not as audited financials.

Plan for the incident you hope never happens

We build detection, response and recovery cover so a ransom demand is never your only option.