Sophos report finds nearly half of companies in the UAE opt to pay the ransom

Sophos report finds nearly half of companies in the UAE opt to pay the ransom

Sophos, a global leader of innovative security solutions for defeating cyberattacks, has released its sixth annual State of Ransomware report, a vendor-agnostic survey of IT and cybersecurity leaders across 17 countries that studies the impact of ransomware attacks on businesses. This year’s survey found that nearly 50% of companies globally paid the ransom to get their data back – the second highest rate of ransom payment for ransom demands in six years.

While 43% of organisations in the UAE that had data encrypted paid the ransom, 30% of them paid less than the original demand. Globally, in 71% of cases where the companies paid less, they did so through negotiation – either through their own negotiations or with help from a third party. In fact, while the median global ransom demand dropped by a third between 2024 and 2025, the median global ransom payment dropped by 50%, illustrating how companies are becoming more successful at minimising the impact of ransomware.

Overall, the median ransom payment in the UAE was US$1.33 million, although the initial demand varied significantly depending on organisation size and revenue. Across the globe, the median ransom demand for companies with over US$1 billion in revenue was US$5 million while organisations with US$250 million revenue or less saw median ransom demands of less than US$350,000.

Exploited vulnerabilities were the number one technical root cause of attacks in the UAE while 49% of ransomware victims said adversaries took advantage of a security gap that they were not aware of – highlighting organisations’ ongoing struggle to see and secure their attack surface.

Overall, 54% of UAE organisations said resourcing issues were a factor in them falling victim to the attack, with one third citing a lack of expertise and 30% reporting a shortage of resources.

Additionally, the report reveals that the impact of ransomware attacks on data in the UAE remains significant. In 55% of the attacks, data was successfully encrypted, surpassing the global average (50%). In 43% of those cases, data was also stolen, much higher than the 28% global rate. Despite this, 98% of affected organisations recovered their data, with 68% using backups and 43% opting to pay the ransom, highlighting both strong recovery strategies and ongoing challenges.

“For many organisations, the chance of being compromised by ransomware actors is just a part of doing business in 2025. The good news is that, thanks to this increased awareness, many companies are arming themselves with resources to limit damage. This includes hiring incident responders who can not only lower ransom payments but also speed up recovery and even stop attacks in progress,” said Chester Wisniewski, Director, Field CISO, Sophos.

“Of course, ransomware can still be ‘cured’ by tackling the root causes of attacks: exploited vulnerabilities, lack of visibility into the attack surface and too few resources. We’re seeing more companies recognise they need help and moving to Managed Detection and Response (MDR) services for defence. MDR coupled with proactive security strategies such as multifactor authentication and patching can go a long way in preventing ransomware from the start.”

Browse our latest issue

Intelligent CISO

View Magazine Archive