Navanta Insights 2026 Digital - Flipbook - Page 2
RANSOMWARE
INSIGHTS
36%
36% of threats reported last year
to the Internet Crime Complaint
Center involved ransomware.
Source: FBI’s 2025 Internet
Crime Report
89%
Ransomware attacks can result in a loss of revenue and a disruption to normal
operations. But by implementing a few regular, preventative measures, bank
leaders can ensure their organization is prepared to respond appropriately if
hit by one of these attacks.
89% of bank executives said
their bank had conducted
a tabletop exercise of its
cybersecurity incident response
plan within the prior 12 months.
Source: Bank Director’s 2026
Risk Survey
Ransomware attacks are a significant risk to banks. Could your institution
be caught off guard?
KEY TAKEAWAYS
There are different types of ransomware attacks, but fundamentally, ransomware is a type of malicious software that encrypts its target’s data until a
• Ransomware attacks use a type of
malicious software to extort an individual
or organization into paying a sum of
money, usually via cryptocurrency, to
unencrypt essential data.
• An analysis found that ransomware
payments made over the blockchain hit
an all-time high of $1.23 billion in 2023.
Attackers sometimes ask for smaller
sums of money to evade attention by law
enforcement.
• Regular patching and updating of the
bank’s defense systems, along with a
data loss prevention program, can cut
down on organizational vulnerabilities to
ransomware.
• Directors and senior executives should
also regularly conduct tabletop exercises
of the bank’s incident response plan to
ensure they are prepared in the event of
an attack.
ransom is paid, usually in the form of cryptocurrency. Responding appropriately to such an attack starts long before the bank’s defenses are ever breached.
By understanding what ransomware can look like and practicing the organization’s response, banks can limit expenses, risk and reputational damage.
“Prepare as if these attacks are going to occur, because they are of consequence,” says Patrick Ringsred, chief strategy officer with Navanta, a technology and services partner that provides cybersecurity and other services to
community banks. “It’s not a good thing to develop a plan reactively given the
consequential dynamics of this. It’s a high stress, difficult moment for a bank.”
Reported ransomware payments made over the blockchain hit an all-time
high of $1.23 billion in 2023 then fell to $892 million the following year, according to a study by the blockchain research firm Chainalysis. Chainalysis
found that ransomware actors nabbed $820 million in 2025, but the firm expects that number to grow as it continues to gather data. Financial services,
manufacturing and healthcare were the top three industries targeted in ransomware attacks, according to a December 2025 analysis from the Financial
Crimes Enforcement Network.
A few dynamics are influencing the way ransomware attacks are perpetrated today, according to Stephen Moss, chief operating officer with Navanta.
Federal and international authorities have aggressively pursued some of the
larger threat actors, leaving many others to continue to perpetrate attacks at
a smaller scale. By demanding smaller dollar amounts, the attackers have a
better chance of flying under authorities’ radar, Moss says.
2