• Latest
  • Trending
58% of retail businesses hit by ransomware paid ransom to recover data

58% of retail businesses hit by ransomware paid ransom to recover data

November 5, 2025
Wema Bank Hackaholics 7.0

Wema Bank Opens Hackaholics 7.0 for African Startups and Innovators

July 16, 2026
Civic Hive Invites Activists, Tech Innovators, Others to West Africa CivicTech Conference 2026

Civic Hive Invites Activists, Tech Innovators, Others to West Africa CivicTech Conference 2026

July 16, 2026
SANSA Opens 2027 STEM Bursaries for Postgraduate Students

SANSA Opens 2027 STEM Bursaries for Postgraduate Students

July 16, 2026
African blockchain VC funding defies global trend, drops 26.6% in 2025

African blockchain VC funding defies global trend, drops 26.6% in 2025

July 16, 2026
AI-powered 5G network digital twin

Tech Mahindra, Microsoft unveil AI-powered 5G network digital twin

July 9, 2026
Best crypto exchanges in South Africa (2026 Edition)

Best crypto exchanges in South Africa (2026 Edition)

July 9, 2026
Best Crypto Payment Gateways in Kenya for Businesses

Best Crypto Payment Gateways in Kenya for Businesses

July 9, 2026
Luno enters SEC regulatory sandbox as first admitted global crypto exchange in Nigeria

Luno enters SEC regulatory sandbox as first admitted global crypto exchange in Nigeria

July 9, 2026
VALR launches Africa's first centralised exchange perpetuals on Hyperliquid blockchain

VALR launches Africa’s first centralised exchange perpetuals on Hyperliquid blockchain

July 9, 2026
SEC Nigeria enforces crypto law with seven new firms

SEC Nigeria enforces crypto law with seven new firms

July 9, 2026
Visa, M-Pesa, Onafriq test stablecoin pilot in DR Congo

Visa, M-Pesa, Onafriq test stablecoin pilot in DR Congo

July 9, 2026
IBM AI Builders

IBM Opens Applications for Quantum Developer Conference 2026

July 9, 2026
Techpression
Advertisement
  • Tech News
    • Africa Tech
    • Global Tech
    • Tech with Pelumy
    • Tech TV
    • General News
    • How To
    • Reviews
  • Tech Careers
  • Cryptocurrency
  • Fintech
  • Startups
  • Ai
July 26, 2026
No Result
View All Result
  • Tech News
    • Africa Tech
    • Global Tech
    • Tech with Pelumy
    • Tech TV
    • General News
    • How To
    • Reviews
  • Tech Careers
  • Cryptocurrency
  • Fintech
  • Startups
  • Ai
No Result
View All Result
Techpression
No Result
View All Result
Home Tech News

58% of retail businesses hit by ransomware paid ransom to recover data

Oluwatosin Adeyemi by Oluwatosin Adeyemi
November 5, 2025
in Tech News
7 0
0
58% of retail businesses hit by ransomware paid ransom to recover data
0
SHARES
Share on FacebookShare on TwitterWhatsAppTelegram

In its fifth annual State of Ransomware in Retail report, a vendor-neutral survey of IT and cybersecurity leaders in 16 countries, cybersecurity leader Sophos found that an unidentified security flaw was responsible for almost half (46 per cent) of retail ransomware incidents.

⚡Quick Brief
  • In its fifth annual State of Ransomware in Retail report, a vendor-neutral survey of IT and cybersecurity leaders in 16...
  • This highlights the continuous visibility issues across the retail attack surface.
  • Ransomware was the most frequent incident against retailers, followed by account compromise.
  • According to Sophos, the percentage of attacks that were stopped before encryption hit a five-year high, suggesting that retail organisations...

Keep reading for the full breakdown on cybersecurity — everything you need to know is covered below.

This highlights the continuous visibility issues across the retail attack surface.

58 per cent of organisations paid the ransom to recover their encrypted data, the second-highest payment rate in five years.

RelatedPosts

OPay Emergency Lock

OPay Launches Emergency Lock and Safety PIN for Security

June 29, 2026
WhatsApp

WhatsApp Adds Pre-Chat Trust Warnings to Protect Users from Impersonation Scams

June 26, 2026

Digital PayExpo 2026 bets on AI to power Africa’s next payments chapter

June 11, 2026

Global Summit Tackles AI-Driven Gender Violence

June 9, 2026
Load More

Cybercriminals exploit known vulnerabilities

Thirty per cent of these attacks exploited known vulnerabilities (top technical root cause, third year running), whereas forty-six per cent of attacks started with an unknown security gap (top operational factor).

Sophos said the average ransom payment rose five per cent to $1 million, while the median ransom demand doubled to $2 million from 2024.

Sophos X-Ops has seen almost 90 threat groups use ransomware or extortion against one or more retailers across leak sites in the last 12 months. Based on incident response and MDR cases, Sophos has identified Akira, Cl0p, Qilin, PLAY, and Lynx as the most active groups.

Ransomware was the most frequent incident against retailers, followed by account compromise. The third most frequent incident type, business email compromise (BEC) groups, frequently target the retail industry in an attempt to divert payments, just like they do in many other industries.

Director, Global Field CISO, Sophos, Chester Wisniewski, said: “Retailers globally are facing a more complex threat landscape where adversaries are constantly on the lookout for and exploiting existing vulnerabilities, most frequently in remote access and Internet-facing networking equipment. With ransom demands reaching new highs, the need to implement comprehensive security strategies is even more apparent. Without this, retailers risk ongoing operational disruption and lasting reputational damage that could take years to repair. Encouragingly, many are beginning to recognise this and respond by investing in their cyber defences, enabling them to stop attacks before they escalate and recover faster.”

Furthermore, according to Sophos, gaps in protection coverage (44 per cent) and a lack of in-house expertise (45 per cent) were the two most frequent operational drivers of compromise. It emphasised that retailers find it challenging to identify and stop attacks without the proper knowledge and protection.

Cybersecurity improvement

In addition to these difficulties, there are indications of advancement. According to Sophos, the percentage of attacks that were stopped before encryption hit a five-year high, suggesting that retail organisations are getting better at quickly identifying and thwarting attacks. With only 48 per cent of attacks now resulting in data encryption, the rate of data encryption is at its lowest point in five years.

The average ransom payment is half of the average ransom demand, despite a 5 per cent increase in the average retail ransom payment ($1 million in 2025 compared to $950k in 2024).

This suggests that retail organisations are growing more resilient to inflated ransom demands and may be seeking professional guidance to deal with ransomware attacks.

“In the end, successful security programmes are focused on risk management. To assess and manage those risks, retailers must have visibility into the threats they face as well as their assets and their security posture. Organisations that combine strong asset management and patching with Managed Detection and Response services and managed risk services prevent more and recover faster, taking a proactive approach in their cyber defences,” Sophos stated.

Additionally, it stated that while data encryption rates were at their lowest point in five years, adversaries were adjusting as the percentage of retailers affected by extortion-only attacks tripled, from 2 per cent in 2023 to 6 per cent in 2025.

According to Sophos, backup rates are declining. For the first time in four years, 62 per cent of retailers who were attacked used backups to restore their data.

According to the report, retailers are bucking ransom demands. Only 29 per cent of retailers reported that their payment matched the initial demand, according to a study that closely examines demands against payments. Eleven per cent paid more than the original amount, while fifty-nine per cent paid less.

Best practices to combat ransomware

Sophos suggested a few best practices to help companies stay ahead of ransomware and other cyberthreats based on its experience safeguarding retail organisations across the globe.

Businesses and individuals were advised by the firm to take proactive measures to address common operational and technical weaknesses, such as exploited vulnerabilities, that adversaries often target.

Sophos advised safeguarding all endpoints, including servers, with specialised anti-ransomware defences to prevent attacks from gaining a foothold.

Tags: cybersecurityexploited vulnerabilitiesransomware in retailretail securitySophos reportunknown security flaws
Oluwatosin Adeyemi

Oluwatosin Adeyemi

Oluwatosin Adeyemi is a seasoned writer with 5+ years of experience. He holds a degree in Animal Science from Olabisi Onabanjo University. A hardworking and creative individual with a passion for teamwork and self-improvement.

ADVERTISEMENT
Techpression

© 2026 Techpression

Quick Links

  • Home
  • About
  • Contact Us
  • Advert Rate
  • SiteMap
  • T & C

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

We are using cookies to give you the best experience on our website.

You can find out more about which cookies we are using or switch them off in .

No Result
View All Result
  • Tech News
  • Artificial Intelligence
  • Cryptocurrency
  • Fintech
  • Startups
  • Business
  • How to
  • Feature

© 2026 Techpression

techpression.com
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

3rd Party Cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.