In its fifth annual State of Ransomware in Retail report, a vendor-neutral survey of IT and cybersecurity leaders in 16 countries, cybersecurity leader Sophos found that an unidentified security flaw was responsible for almost half (46 per cent) of retail ransomware incidents.
- In its fifth annual State of Ransomware in Retail report, a vendor-neutral survey of IT and cybersecurity leaders in 16...
- This highlights the continuous visibility issues across the retail attack surface.
- Ransomware was the most frequent incident against retailers, followed by account compromise.
- According to Sophos, the percentage of attacks that were stopped before encryption hit a five-year high, suggesting that retail organisations...
Keep reading for the full breakdown on cybersecurity — everything you need to know is covered below.
This highlights the continuous visibility issues across the retail attack surface.
58 per cent of organisations paid the ransom to recover their encrypted data, the second-highest payment rate in five years.
Cybercriminals exploit known vulnerabilities
Thirty per cent of these attacks exploited known vulnerabilities (top technical root cause, third year running), whereas forty-six per cent of attacks started with an unknown security gap (top operational factor).
Sophos said the average ransom payment rose five per cent to $1 million, while the median ransom demand doubled to $2 million from 2024.
Sophos X-Ops has seen almost 90 threat groups use ransomware or extortion against one or more retailers across leak sites in the last 12 months. Based on incident response and MDR cases, Sophos has identified Akira, Cl0p, Qilin, PLAY, and Lynx as the most active groups.
Ransomware was the most frequent incident against retailers, followed by account compromise. The third most frequent incident type, business email compromise (BEC) groups, frequently target the retail industry in an attempt to divert payments, just like they do in many other industries.
Director, Global Field CISO, Sophos, Chester Wisniewski, said: “Retailers globally are facing a more complex threat landscape where adversaries are constantly on the lookout for and exploiting existing vulnerabilities, most frequently in remote access and Internet-facing networking equipment. With ransom demands reaching new highs, the need to implement comprehensive security strategies is even more apparent. Without this, retailers risk ongoing operational disruption and lasting reputational damage that could take years to repair. Encouragingly, many are beginning to recognise this and respond by investing in their cyber defences, enabling them to stop attacks before they escalate and recover faster.”
Furthermore, according to Sophos, gaps in protection coverage (44 per cent) and a lack of in-house expertise (45 per cent) were the two most frequent operational drivers of compromise. It emphasised that retailers find it challenging to identify and stop attacks without the proper knowledge and protection.
Cybersecurity improvement
In addition to these difficulties, there are indications of advancement. According to Sophos, the percentage of attacks that were stopped before encryption hit a five-year high, suggesting that retail organisations are getting better at quickly identifying and thwarting attacks. With only 48 per cent of attacks now resulting in data encryption, the rate of data encryption is at its lowest point in five years.
The average ransom payment is half of the average ransom demand, despite a 5 per cent increase in the average retail ransom payment ($1 million in 2025 compared to $950k in 2024).
This suggests that retail organisations are growing more resilient to inflated ransom demands and may be seeking professional guidance to deal with ransomware attacks.
“In the end, successful security programmes are focused on risk management. To assess and manage those risks, retailers must have visibility into the threats they face as well as their assets and their security posture. Organisations that combine strong asset management and patching with Managed Detection and Response services and managed risk services prevent more and recover faster, taking a proactive approach in their cyber defences,” Sophos stated.
Additionally, it stated that while data encryption rates were at their lowest point in five years, adversaries were adjusting as the percentage of retailers affected by extortion-only attacks tripled, from 2 per cent in 2023 to 6 per cent in 2025.
According to Sophos, backup rates are declining. For the first time in four years, 62 per cent of retailers who were attacked used backups to restore their data.
According to the report, retailers are bucking ransom demands. Only 29 per cent of retailers reported that their payment matched the initial demand, according to a study that closely examines demands against payments. Eleven per cent paid more than the original amount, while fifty-nine per cent paid less.
Best practices to combat ransomware
Sophos suggested a few best practices to help companies stay ahead of ransomware and other cyberthreats based on its experience safeguarding retail organisations across the globe.
Businesses and individuals were advised by the firm to take proactive measures to address common operational and technical weaknesses, such as exploited vulnerabilities, that adversaries often target.
Sophos advised safeguarding all endpoints, including servers, with specialised anti-ransomware defences to prevent attacks from gaining a foothold.














