Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

BEC vs ransomware: which is more profitable per attack in 2026?

Ransomnews Research TeamBy Ransomnews Research TeamMay 2, 2026No Comments3 Mins Read834 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
A balanced scale comparing a wire-transfer envelope icon against a ransomware lock icon with floating dollar signs
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ransomware gets the headlines. BEC gets the money. The IC3 numbers have been showing this for years, but the gap is wider in 2026 than it was at any point in the last decade. Here’s the per-attack comparison that explains why BEC keeps growing while ransomware operators are scrambling.

Per-attack revenue

Average BEC incident loss in 2025: roughly $137,000 (FBI IC3). Average ransomware payment in 2025 (when paid): roughly $400,000-$500,000 depending on whose dataset you read. So ransomware wins on per-incident revenue.

But the conversion rate between attacks attempted and money received is hugely different. The BEC success rate, measured as “the wire actually went through”, sits around 4-7% depending on industry. The ransomware success rate, measured as “the victim actually paid”, has fallen below 30% and is still dropping. So while the ransomware payment is bigger, the operator has to wait through more failed attempts to get one.

Per-attack cost

BEC operations are cheap. A list of compromised credentials from a stealer log, a compromised email account at a target, a few days of patient observation, a well-timed wire-instruction substitution. Total operator cost per attack: low hundreds of dollars at most.

Ransomware operations are expensive. The encryptor itself costs tens of thousands to develop or license. Initial-access purchases run hundreds to thousands per environment. Affiliates take 70-80% of the take. Infrastructure, leak-site hosting, and negotiation overhead consume the rest. Operators are running thinner margins than people think.

Risk profile

BEC operators face less heat. The crime is less newsworthy, the international cooperation less urgent, the operators less centralised. Ransomware operators face concentrated FBI attention, OFAC sanctions, and the periodic infrastructure takedown. Per attack, the BEC operator is significantly less likely to be inside law enforcement’s frame than a ransomware affiliate.

// Free tool

How does your own site score?

Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

That asymmetry is shaping the migration we’ve documented over 2025-2026: experienced ransomware affiliates increasingly add BEC capability to their toolkits. The same access that enables ransomware enables BEC, and BEC pays more reliably with less risk.

Defender implications

Most enterprise security programmes are sized for ransomware risk. Few are sized for BEC risk specifically. The controls that catch BEC are different from the controls that catch ransomware, and the gap is real.

BEC controls that work: out-of-band verification of every wire transfer above a threshold, mailbox audit logging with rules that flag inbox forwarding rule changes, conditional-access policies that flag impossible-travel logins, and a finance-team training programme that focuses on “verify before sending” as a culture, not a slide.

Ransomware defence, backups, EDR, segmentation, covers a different threat. Most organisations should be running both. The mistake is assuming ransomware defence accidentally covers BEC. It doesn’t.

Bottom line

Per attack, ransomware pays more when it pays. Across the portfolio of attempts, BEC pays more reliably, more often, with less heat. The smart attackers know this. The smart defenders should plan accordingly.

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleThe pivot from encryption to data theft: pure-extortion gangs in 2026
Next Article Why hospital ransomware attacks keep getting worse
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

The Town 2025 ticketing data sold as a Ticketmaster breach

September 3, 2026

Micro-Comm hack is separate from the US water attacks

September 1, 2026

Love Electric driver data for sale: NI, licence numbers

August 28, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,520 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.