Sophos has released its fifth annual State of Ransomware in Retail report, a vendor-agnostic survey of IT and cybersecurity leaders across 16 countries.
This year’s report reveals that nearly half (46%) of retail ransomware incidents were traced to an unknown security gap, underscoring ongoing visibility challenges across the retail attack surface. Among organizations that had data encrypted, 58% paid the ransom to get their data back – the second-highest payment rate in five years.
Other key findings from the report include:
- 30% of attacks exploited known vulnerabilities (top technical root cause, third year running).
- 48% of attacks resulted in encryption (five-year low).
- Median ransom demand doubled to $2 million from 2024, while the average payment increased 5% to $1 million.
- Looking closely at demands vs. payments, only 29% of retailers said their payment matched the initial demand; 59% paid less than the initial ask, while 11% paid more.
- Limited in-house expertise was the second-most common operational driver of compromise (45%), followed by gaps in protection coverage (44%).
- 62% of retailers who experienced attacks restored their data using backups – the lowest rate in four years.
- Encouragingly, the average (mean) cost of recovering from a ransomware attack, excluding any ransom payment, has dropped by 40% over the past year to $1.65 million, its lowest point in three years.
- Almost half (47%) of retail IT/cybersecurity teams reported increased pressure after experiencing data encryption, while one quarter of cases (26%) saw leadership teams replaced as a result.
Sophos recommends the following best practices to help businesses stay ahead of ransomware and other cyberthreats:
Eliminate root causes: take proactive steps to address common technical and operational weaknesses, such as exploited vulnerabilities, that adversaries frequently target. Solutions like Sophos Managed Risk can help organizations assess their exposure and reduce risk across their environments.
Defend every endpoint: ensure all endpoints, including servers, are protected with dedicated anti-ransomware defences to prevent attacks from gaining a foothold.
Plan and prepare: establish and routinely test a comprehensive incident response plan. Maintain reliable backups, and practise data restoration regularly to minimise downtime in the event of an attack.
Monitor around the clock: continuous visibility is essential. Organizations without in-house resources can strengthen their resilience by partnering with a trusted Managed Detection and Response (MDR) provider for 24/7 threat monitoring and expert response.
Methodology
Data for the State of Ransomware in Retail 2025 report comes from a vendor-agnostic survey of 361 retail IT and cybersecurity leaders in organizations with 100–5,000 employees across 16 countries, conducted January–March 2025. All respondents experienced ransomware in the previous 12 months.






