- How it starts
- Valid or replayed VPN, RDP, SaaS, SSO, token, API, connected-app, or administrative access.
- Attacker outcome
- Legitimate-looking persistence, privilege escalation, lateral movement, exfiltration, and impact.
- What to monitor
- New devices or geographies, stale accounts, impossible travel, unusual admin sessions, token use, delegated access, and dormant-account activation.
Coveware Ransomware Rolling Intelligence Card
AI-generated, AI-updated weekly, AI quality-checked, and source-cited, this one-year Rolling Intelligence Card turns Coveware by Veeam’s first-hand ransomware casework into executive intelligence on payment decisions, threat-actor communications, access methods, extortion economics, victimology, decryption reliability, and recovery risk. Coveware controls Coveware-specific claims; peer incident-response research is retained only as clearly labeled supplemental context.
Research Framing
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Decision Question / User Topic | The totality of Coveware’s public ransomware intelligence during the active rolling one-year window, with priority given to quarterly casework reports, threat-actor communications, payment and nonpayment outcomes, initial access, victimology, malware reliability, recovery, and executive decision implications. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | What is Coveware seeing in cases it directly handles? Which ransomware and extortion actors are communicating with victims, what leverage are they using, how often are organizations paying, and what do average and median payments actually mean? Which access paths, sectors, company sizes, malware defects, and recovery assumptions should change an organization’s preparedness or live-incident decisions? Where do peer sources corroborate or diverge without being mistaken for Coveware data? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | Coveware’s Q3 2025 quarterly ransomware report, “Insider Threats Loom while Ransom Payment Rates Plummet,” reported a record-low 23% overall payment rate. Its Q4 2025 report, “Why Zero-Day Downstream Mass Data Extortion Campaigns are Losing Their Bite,” reported a $591,988 average and $325,000 median payment. Its Q1 2026 report, “Patch management goes from hard, to ludicrous in the agentic AI era,” reported a $680,081 average, $300,750 median, and 23% payment rate. Read together, the three reports show identity-backed remote access becoming the dominant entry class, business interruption remaining the strongest payment driver, and data-theft-only extortion converting poorly even when victim reach is large. Coveware’s named Obscura and Nitrogen technical blogs separately show why payment is not synonymous with recovery: Obscura can corrupt large files, and Nitrogen’s ESXi encryptor can make decryption impossible even for the attacker.[1][2][3][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
Complete Tier 0–8 counts are shown here. The 9 retained sources and their claim treatment are identified in Citations. Planned integrations are not counted as checked or selected. |
Reporting-Period Statistics
Rolling 1-Year Intelligence Snapshot
At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.
Period Coverage
Sep 13, 2025–Sep 12, 2026
365 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.
23%[5]
Q1 2026 payment rate
Cited in Coveware’s Q1 2026 quarterly ransomware report; Coveware-managed cases only.Evidence dated Apr 30, 2026
$680,081[5]
Q1 average payment
Cited in Coveware’s Q1 2026 quarterly ransomware report; up 15% from Q4 and skewed by large settlements.Evidence dated Apr 30, 2026
$300,750[5]
Q1 median payment
Cited in Coveware’s Q1 2026 quarterly ransomware report; down 7% from Q4.Evidence dated Apr 30, 2026
79%[5]
Q1 lateral movement
Cited in Coveware’s Q1 2026 quarterly ransomware report as its most frequently observed Q1 tactic.Evidence dated Apr 30, 2026
73%[5]
Q1 exfiltration
Cited in Coveware’s Q1 2026 quarterly ransomware report across encryption and extortion cases.Evidence dated Apr 30, 2026
⅔[5]
SMB/mid-market concentration
Cited in Coveware’s Q1 2026 quarterly ransomware report for the 11–100 and 101–1,000 employee bands.Evidence dated Apr 30, 2026
Evidence-Prioritized Access Paths
Top Initial Access & Account-Takeover Vectors
Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly ransomware reports do not publish a complete percentage table for every entry path in the rendered text. The order below is an evidence-ranked operational assessment, not a fabricated frequency ranking.
- How it starts
- Impersonation, vishing, MFA reset, password reset, new enrollment, or support-assisted access.
- Attacker outcome
- A provisioned or recovered account that appears legitimate.
- What to monitor
- Reset reason, caller validation, new MFA factor, privileged role change, unusual support tickets, and follow-on data access.
- How it starts
- Exploitation of internet-facing appliances, management planes, enterprise applications, or residual migration exposure.
- Attacker outcome
- Fast access to data theft, lightweight encryption, or privileged control.
- What to monitor
- Externally reachable assets, patch lag, known exploitation, leftover accounts, incomplete migrations, and management-plane telemetry.
- How it starts
- Malicious consent, stolen refresh token, delegated trust, or compromised integration.
- Attacker outcome
- Durable platform-native access with limited endpoint indicators.
- What to monitor
- New grants, scope expansion, rare application IDs, token replay, admin consent, and access after password reset.
- How it starts
- Compromised vendor identity, integration, service account, or shared administration path.
- Attacker outcome
- Access across organizational boundaries and downstream customer environments.
- What to monitor
- Vendor sessions, service-account changes, delegated privileges, cross-tenant access, and emergency access paths.
| Vector / Evidence | How It Starts | Attacker Outcome | What to Monitor |
|---|---|---|---|
| Valid or replayed VPN, RDP, SaaS, SSO, token, API, connected-app, or administrative access. | Legitimate-looking persistence, privilege escalation, lateral movement, exfiltration, and impact. | New devices or geographies, stale accounts, impossible travel, unusual admin sessions, token use, delegated access, and dormant-account activation. | |
| Impersonation, vishing, MFA reset, password reset, new enrollment, or support-assisted access. | A provisioned or recovered account that appears legitimate. | Reset reason, caller validation, new MFA factor, privileged role change, unusual support tickets, and follow-on data access. | |
| Exploitation of internet-facing appliances, management planes, enterprise applications, or residual migration exposure. | Fast access to data theft, lightweight encryption, or privileged control. | Externally reachable assets, patch lag, known exploitation, leftover accounts, incomplete migrations, and management-plane telemetry. | |
| Malicious consent, stolen refresh token, delegated trust, or compromised integration. | Durable platform-native access with limited endpoint indicators. | New grants, scope expansion, rare application IDs, token replay, admin consent, and access after password reset. | |
| Compromised vendor identity, integration, service account, or shared administration path. | Access across organizational boundaries and downstream customer environments. | Vendor sessions, service-account changes, delegated privileges, cross-tenant access, and emergency access paths. |
Intended Reader and Decision Context
Persona / Audience
Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.
| Audience Field | Assessment |
|---|---|
| Audience fieldPrimary audience | AssessmentExecutives, boards, CISOs, CIOs, incident commanders, breach counsel, cyber insurers, finance leaders, recovery owners, and ransom-decision teams. |
| Audience fieldOrganization profile | AssessmentU.S.-oriented but globally relevant; useful to SMB, mid-market, enterprise, healthcare, consumer services, professional services, financial services, public-sector, managed-service, and data-rich organizations. |
| Audience fieldDecision use | AssessmentPreparedness, identity and remote-access control, patch prioritization, business-continuity design, threat-actor engagement, payment exception analysis, sanctions and legal coordination, decryption validation, and recovery planning. |
| Audience fieldReading standard | AssessmentPlain English for executives, with enough technical specificity for responders. Statistics remain bounded to Coveware-managed cases and peer evidence is explicitly marked supplemental. |
Chronology and Decision Milestones
Timeline of Notable Activity
Coveware publication dates, underlying case quarters, threat-actor communications, payment decisions, technical analyses, and recovery observations are separated. Peer reports remain supplemental and methodologically distinct.
Q3 2025 quarterly ransomware report
Q3 payment rates reach a record low
Coveware’s Q3 2025 report, “Insider Threats Loom while Ransom Payment Rates Plummet,” reported a 23% overall payment rate and 19% for data-theft-only incidents. Average payment fell to $376,941, median to $140,000, and Akira represented 34% of Coveware-observed variants.[1]
Coveware technical blog
Obscura proves a valid decryptor may still be useless
Coveware’s “Obscura Ransomware: A Case Study in Ransomware Data Loss” blog reported that Obscura fails to write required key material to files larger than 1 GB, making those files permanently unrecoverable even after payment.[2]
Coveware technical blog
Nitrogen’s ESXi flaw creates irreversible corruption
Coveware’s “Nitrogen Ransomware: ESXi malware has a bug!” blog reported that the ESXi encryptor uses the wrong public key, so the actor cannot provide a working recovery key.[3]
Q4 2025 quarterly ransomware report
Q4 report finds mass data-extortion economics weakening
Coveware’s Q4 2025 report, “Why Zero-Day Downstream Mass Data Extortion Campaigns are Losing Their Bite,” reported that large downstream campaigns produced little payment leverage, while average and median payments rose to $591,988 and $325,000 because isolated severe business-interruption cases skewed the distribution.[4]
Supplemental market context
GuidePoint reports elevated but stable ransomware volume
GRIT reported roughly 150–200 victim posts per week in Q1 2026. This is supplemental public-ecosystem context, not Coveware casework.[6]
Q1 2026 quarterly ransomware report
Q1 report centers identity, business interruption, and compressed patch windows
Coveware’s Q1 2026 report, “Patch management goes from hard, to ludicrous in the agentic AI era,” reported a 23% payment rate, $680,081 average payment, $300,750 median, remote-access and identity-backed entry, 79% lateral movement, 73% exfiltration, and a two-thirds concentration in organizations with 11–1,000 employees.[5]
Supplemental market context
GuidePoint Q2 confirms high external victim-post volume
GRIT counted 2,279 reported ransomware victims in Q2 2026, up 7% quarter over quarter and 43% year over year. It is retained only as a supplemental external-volume comparator.[7]
IntelliOS publication
Coveware monitor consolidated into a weekly Rolling Intelligence Card
The former quarterly email-only monitor was deprecated. Its subscriber identity was retained, while publication, weekly monitoring, change history, and Page Alerts now live on this rolling one-year product.[1][2][3][4][5]
Bottom Line Up Front
BLUF
Nonpayment is now the baseline, not an exceptional outcome: Coveware’s Q3 2025 and Q1 2026 quarterly ransomware reports each reported a 23% overall payment rate, with data-theft-only payment rates structurally lower. Executives should treat payment as an exception requiring a documented, evidence-based business case.[1][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
The average ransom payment is a poor stand-alone planning number: Coveware’s Q1 2026 quarterly ransomware report cited a $680,081 average and $300,750 median. The gap reflects a small number of large settlements and should not be used as a simple expected-loss assumption.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026
Business interruption—not a promise to delete stolen data—still creates the strongest payment pressure: Coveware’s Q4 2025 and Q1 2026 quarterly ransomware reports say encryption-led groups convert more payments because outages create immediate operational leverage, while data-theft-only promises are unverifiable and vulnerable to re-extortion.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026
Identity is the primary intrusion surface: Across Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly reports, remote access includes SaaS administration, OAuth grants, SSO, connected apps, tokens, help-desk resets, VPN, RDP, and inherited trust—not merely a perimeter device.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
Payment cannot guarantee recovery: Coveware’s named Obscura and Nitrogen technical blogs demonstrate that defective ransomware can destroy data in ways no decryptor can reverse. Variant-aware validation must precede any recovery or payment decision.[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026
Decision Context
Executive Summary
This Rolling Intelligence Card monitors Coveware because its public reports are based on first-hand ransomware and extortion cases, including threat-actor engagement, payment decisions, decryption, recovery, access, tactics, and victim characteristics. That makes the corpus especially valuable for management questions that leak-site counts alone cannot answer. It does not make the data a census of the full market; Coveware repeatedly limits its statistics to cases it handled.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
The central economic finding is a durable shift toward nonpayment. Coveware’s Q3 2025 quarterly ransomware report, “Insider Threats Loom while Ransom Payment Rates Plummet,” reported a historical-low 23% overall payment rate and 19% for data-theft-only cases. Its Q1 2026 quarterly report, “Patch management goes from hard, to ludicrous in the agentic AI era,” reported a 23% overall rate again. The implication is not that ransomware is harmless. It is that organizations increasingly resist payment when they can restore operations, understand what was taken, and accept that paying for an unverifiable deletion promise rarely eliminates notification, litigation, regulatory, or re-extortion risk.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
Payment amounts remain volatile. Coveware’s Q3 2025 report cited a $376,941 average and $140,000 median; its Q4 2025 report cited a $591,988 average and $325,000 median; and its Q1 2026 report cited a $680,081 average and $300,750 median. The rising average alongside a declining median in Q1 is a warning against simplistic budgeting: a handful of severe enterprise events can pull the average upward while the more typical paid case is materially lower.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
Threat actors are splitting between high-volume Ransomware-as-a-Service attacks against smaller and mid-market firms and more targeted, expensive operations against large enterprises. Coveware’s Q1 2026 quarterly ransomware report stated that the 11–100 and 101–1,000 employee bands accounted for two-thirds of attacks, while only 5% of victims had more than 100,000 employees. Ransomware therefore remains a broad operating risk, not a problem confined to globally prominent companies.[1][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
Across Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly ransomware reports, initial access is increasingly identity-backed. A modern “remote access compromise” can mean a valid VPN login, SaaS administrator session, OAuth grant, SSO token, connected application, delegated trust path, or help-desk-assisted reset. Phishing and social engineering still matter, but the successful outcome may be logged as remote access because the attacker ultimately operates through a legitimate identity and stays persistent.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
Coveware’s Q1 2026 quarterly ransomware report identified business interruption as the strongest payment pressure and cited lateral movement in 79% of cases, exfiltration in 73%, impact in 58%, command and control in 58%, and defense evasion in 52%. These are not abstract ATT&CK labels: together they describe an operator moving through legitimate administration paths, stealing data, disrupting operations, and degrading the evidence defenders need to make decisions.[5]Evidence dated Apr 30, 2026
Coveware’s “Obscura Ransomware: A Case Study in Ransomware Data Loss” and “Nitrogen Ransomware: ESXi malware has a bug!” technical blogs show why threat-actor assurances are not technical evidence. The Obscura analysis says the malware fails to preserve keys needed to decrypt files larger than 1 GB. The Nitrogen analysis says its ESXi encryptor used an incompatible key and could irreversibly corrupt virtual-machine data. A small “proof of life” file can therefore create false confidence; responders need variant-aware testing across representative file sizes, formats, workloads, and virtualization systems.[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026
The management response is a combination of identity governance, rapid patching of externally reachable and management-plane systems, resilient and tested recovery, fast containment of lateral movement, legal and insurer coordination, and a preapproved payment-exception process. Payment, if ever considered, should follow independent validation of recoverability and actor claims—not precede it.[1][2][3][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
Executive Briefing Priorities
Top 10 Briefing Points
- 1
Q1 2026 payment rate held at 23% — Coveware’s Q1 2026 quarterly ransomware report cited a 23% payment rate, showing that low conversion persists even though ransomware remains operationally damaging.[5]Evidence dated Apr 30, 2026
- 2
Q1 average rose while the median fell — Coveware’s Q1 2026 quarterly ransomware report cited a $680,081 average versus a $300,750 median—a skewed distribution driven by large outliers.[5]Evidence dated Apr 30, 2026
- 3
Identity-backed remote access dominates — Coveware’s Q4 2025 and Q1 2026 quarterly ransomware reports treat SaaS, OAuth, SSO, connected apps, admin sessions, tokens, VPN, and RDP as one converging access problem.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026
- 4
Lateral movement appeared in 79% of Q1 cases — Coveware’s Q1 2026 quarterly ransomware report cited the 79% rate; containment speed and east-west visibility directly preserve recovery options.[5]Evidence dated Apr 30, 2026
- 5
Exfiltration appeared in 73% of Q1 cases — Coveware’s Q1 2026 quarterly ransomware report cited the 73% rate. Data theft remains an executive legal, regulatory, contractual, and reputational issue even when encryption is limited.[5]Evidence dated Apr 30, 2026
- 6
Two-thirds of Q1 victims had 11–1,000 employees — Coveware’s Q1 2026 quarterly ransomware report cited this concentration, making the case mix directly relevant to SMB and mid-market organizations.[5]Evidence dated Apr 30, 2026
- 7
Encryption-led groups retain stronger leverage — Coveware’s Q4 2025 and Q1 2026 quarterly ransomware reports show that INC, Akira, and Qilin can create operational pressure that data-theft-only actors often cannot.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026
- 8
Mass downstream data extortion is converting poorly — Coveware’s Q4 2025 quarterly ransomware report cited sharply declining payment outcomes across MOVEit, Cleo, Oracle EBS, and similar campaigns.[4]Evidence dated Feb 3, 2026
- 9
Decryption must be independently validated — Coveware’s Obscura and Nitrogen technical blogs show that even the attacker may be technically unable to restore data.[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026
- 10
Peer leak-site volume remains elevated — GuidePoint GRIT’s Q2 2026 ransomware report provides supplemental evidence that low payment conversion does not equal low attack volume.[7]Evidence dated Jul 9, 2026
Source-Bound Exposure and Targeting
Victimology Matrix
This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.
| Victim / exposure population | Sectors | Geography | Confirmation status | How companies should use it |
|---|---|---|---|---|
| Victim / exposure populationOrganizations with 11–100 employees[5]Evidence dated Apr 30, 2026 | SectorsCross-industry | GeographyCoveware Q1 2026 quarterly-report case mix; not a global census | Confirmation statusCoveware’s Q1 2026 report says this tier, combined with the 101–1,000 tier, represented two-thirds of attacks. | How companies should use itSmall organizations need tested recovery, identity controls, and ransom decision authority; they are not below attacker interest. |
| Victim / exposure populationOrganizations with 101–1,000 employees[5]Evidence dated Apr 30, 2026 | SectorsCross-industry mid-market | GeographyCoveware Q1 2026 quarterly-report case mix | Confirmation statusCoveware’s Q1 2026 report places this tier inside the two-thirds concentration across organizations with 11–1,000 employees. | How companies should use itPrioritize VPN/SaaS identity, remote administration, lateral-movement detection, backup isolation, and executive rehearsal. |
| Victim / exposure populationHealthcare[5]Evidence dated Apr 30, 2026 | SectorsHealthcare | GeographyCoveware Q1 2026 quarterly-report case mix | Confirmation statusCoveware’s Q1 2026 report cited 17.6% of impact, the largest named sector share. | How companies should use itPlan for patient-care continuity, regulated-data exposure, high downtime pressure, and public-facing disruption. |
| Victim / exposure populationConsumer services[5]Evidence dated Apr 30, 2026 | SectorsConsumer services | GeographyCoveware Q1 2026 quarterly-report case mix | Confirmation statusCoveware’s Q1 2026 report cited 15.3% of impact. | How companies should use itProtect customer data, identity and payment workflows, and high-volume operational services. |
| Victim / exposure populationProfessional and financial services[5]Evidence dated Apr 30, 2026 | SectorsProfessional services; financial services | GeographyCoveware Q1 2026 quarterly-report case mix | Confirmation statusCoveware’s Q1 2026 report cited 11.8% and 9.4% of impact respectively. | How companies should use itTreat client records, financial statements, privileged files, and trusted SaaS access as extortion leverage. |
| Victim / exposure populationPublic-sector and must-operate organizations[5]Evidence dated Apr 30, 2026 | SectorsPublic sector and critical services | GeographyCoveware Q1 2026 quarterly-report case mix | Confirmation statusCoveware’s Q1 2026 report cited a 7.1% public-sector share; service interruption can create immediate public pressure. | How companies should use itDefine shutdown, isolation, emergency communication, manual operation, and recovery authority before an incident. |
Distinct Operational Records
Coveware-Observed Threat Actor Communications & Operations
High-volume Akira and Qilin RaaS operations
Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly reports describe a volume-oriented model against mid-market organizations: lower demands, lower attacker cost, and comparatively higher payment propensity.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
CL0P downstream zero-day extortion
Coveware’s Q4 2025 quarterly ransomware report uses the Accellion, GoAnywhere, MOVEit, Cleo, and Oracle EBS sequence to show declining payment leverage as organizations improve scoping and reject unverifiable suppression promises.[4]Evidence dated Feb 3, 2026
ShinyHunters and Lone Wolf data-theft pressure
Coveware’s Q4 2025 and Q1 2026 quarterly reports say these labels represented meaningful case share, but data-theft-only models converted less reliably than encryption-led operations.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026
Insider-recruitment and access-broker pressure
Coveware’s Q3 2025 quarterly ransomware report warned that lower actor profitability increases incentives to bribe or recruit insiders and exploit trusted workflows.[1]Evidence dated Oct 24, 2025
Source-Bound Actor Context
Threat Actors & Negotiation Behaviors
INC Ransom
Coveware’s Q1 2026 quarterly ransomware report placed INC Ransom in a tie for the largest case share at 13% and categorized it as encryption-focused, where business interruption can sustain payment leverage.[5]Evidence dated Apr 30, 2026
Akira
Coveware’s Q3 2025 report placed Akira at 34% of case share; its Q1 2026 report kept Akira among the top encryption-focused groups at 12%.[1][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
Qilin
Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly reports retained Qilin in the top tier and describe encryption plus exfiltration as compounding operational and data pressure.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
CL0P
Coveware’s Q4 2025 quarterly ransomware report describes CL0P as a downstream mass-data-theft specialist whose broad victim reach has not translated into durable payment conversion.[4]Evidence dated Feb 3, 2026
ShinyHunters
Coveware’s Q1 2026 quarterly ransomware report associated ShinyHunters with data-exfiltration-oriented campaigns and 8% of Coveware-observed cases; payment leverage remains weaker without operational disruption.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026
Nitrogen and Obscura
Coveware’s named Nitrogen and Obscura technical blogs show that malware family and build quality can determine whether recovery is possible, independent of negotiation.[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026
Enterprise Exposure
Access Vectors, Malware & Recovery-Critical Technologies
SaaS, SSO, OAuth, APIs, and connected applications
Coveware’s Q4 2025 and Q1 2026 quarterly reports place these systems inside the remote-access attack surface, where they can provide durable identity-backed access with few endpoint signals.[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026
VPN, RDP, SSH, and administrative management paths
Coveware’s three quarterly reports retain legacy remote access as relevant, especially where stale credentials, incomplete migrations, or weak lifecycle controls persist.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
ESXi and virtualized workloads
Coveware’s Nitrogen technical blog shows that a defective encryptor can permanently corrupt this recovery-critical layer; its Q4 2025 report explains why virtualization concentrates business interruption.[3][4]First cited source Feb 2, 2026 · Latest cited source Feb 3, 2026
Internet-facing appliances and management planes
Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly reports treat exploitation as less common than identity compromise but high consequence when patching, migration hygiene, or residual credentials fail.[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
Large files, backups, and decryption tooling
Coveware’s Obscura and Nitrogen technical blogs show why representative validation must include large and critical file types; a small proof-of-life sample cannot establish recoverability.[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026
Current Carry-Forward Watchlist
Top 10 Specific Threats to Monitor
Prioritized Coveware-observed payment, actor-communication, identity, exploitation, recovery, victimology, and market signals that require a named monitoring owner.
| # | Threat / Category | Why It Matters | What to Monitor | IntelliOS Coverage |
|---|---|---|---|---|
| 1 | Threat / Category Economics Overall and data-theft-only payment rates[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026 | Why it mattersCoveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly reports show why payment propensity changes the actor economy and the defensibility of engagement advice. | What to monitorEach new Coveware quarterly rate, impact scenario, historical revision, methodology, and denominator. | IntelliOS coverage |
| 2 | Threat / Category Economics Average and median payment divergence[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026 | Why it mattersCoveware’s three quarterly reports show that large outliers can make the average unsuitable for budgets or expected-loss models. | What to monitorAverage, median, quarter-over-quarter movement, paid-case mix, enterprise outliers, and business-interruption driver. | IntelliOS coverage |
| 3 | Threat / Category Actor communications Deletion promises, re-extortion, harassment, and deadlines[4][5]First cited source Feb 3, 2026 · Latest cited source Apr 30, 2026 | Why it mattersCoveware’s Q4 2025 and Q1 2026 quarterly reports treat actor statements as negotiation pressure, not verified outcomes. | What to monitorProof offered, contradictions, re-extortion, third-party contact, executive harassment, swatting threats, and data-release evidence. | IntelliOS coverage |
| 4 | Threat / Category Identity Remote access and support-assisted compromise[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026 | Why it mattersCoveware’s three quarterly reports show that valid-looking access can persist after a password change. | What to monitorOAuth grants, tokens, SSO, new MFA factors, help-desk resets, rare devices, VPN/RDP, connected apps, and service identities. | IntelliOS coverage |
| 5 | Threat / Category Exploitation Externally reachable appliances and management planes[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026 | Why it mattersCoveware’s quarterly reporting shows that lower frequency does not mean lower consequence. | What to monitorPatch latency, KEV status, exposure, residual accounts, partial migrations, admin interfaces, and exploit telemetry. | IntelliOS coverage |
| 6 | Threat / Category Movement Lateral movement and privileged administration[5]Evidence dated Apr 30, 2026 | Why it mattersCoveware’s Q1 2026 quarterly ransomware report cited a 79% observation rate, making east-west containment a leading recovery control. | What to monitorRDP, SSH, PsExec, admin shares, remote management, privilege changes, service creation, and cross-segment access. | IntelliOS coverage |
| 7 | Threat / Category Recovery Variant-specific encryption and decryptor reliability[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026 | Why it mattersCoveware’s Obscura and Nitrogen technical blogs show that a payment decision is indefensible if the needed data cannot be technically restored. | What to monitorMalware build, footer/key integrity, representative file sizes, ESXi impact, corrupted backups, and decryptor tests. | IntelliOS coverage |
| 8 | Threat / Category Victimology SMB and mid-market concentration[5]Evidence dated Apr 30, 2026 | Why it mattersCoveware’s Q1 2026 quarterly ransomware report cited two-thirds of victims in the 11–1,000 employee bands. | What to monitorCompany size, sector, downtime tolerance, identity maturity, backup independence, and decision authority. | IntelliOS coverage |
| 9 | Threat / Category Market Encryption-led versus data-theft-only group share[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026 | Why it mattersCoveware’s Q3 2025, Q4 2025, and Q1 2026 reports distinguish pressure models that require different containment and decision priorities. | What to monitorVariant ranking, encryption use, exfiltration, actor branding, affiliate behavior, and paid-case concentration. | IntelliOS coverage |
| 10 | Threat / Category Supplemental External victim-post volume[6][7]First cited source Apr 15, 2026 · Latest cited source Jul 9, 2026 | Why it mattersGuidePoint GRIT’s Q1 and Q2 2026 reports show that public leak-site activity can remain high while Coveware-observed payment conversion falls. | What to monitorGuidePoint quarterly victim posts, group count, sector shift, methodology, duplicates, and divergence from Coveware casework. | IntelliOS coverage |
Operational Standards from the Evidence
Best Practices and Lessons Learned
The practices below convert Coveware’s first-hand casework and technical analyses into repeatable ransomware preparedness, payment-decision, validation, containment, and recovery standards.
- 1
Best Practice
Make nonpayment the prepared baseline[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
Lesson Learned
Coveware’s Q3 2025, Q4 2025, and Q1 2026 quarterly reports show that low payment rates and weak data-deletion utility make payment a poor default incident plan.
Minimum Operating Standard
Require a documented exception approved by legal, executive, insurer, sanctions, recovery, and business owners after alternatives are independently tested.
- 2
Best Practice
Validate recoverability before negotiation economics[2][3]First cited source Nov 19, 2025 · Latest cited source Feb 2, 2026
Lesson Learned
Coveware’s Obscura and Nitrogen technical blogs show that the actor may be unable to restore data.
Minimum Operating Standard
Test representative file types, sizes, virtualization workloads, key/footer integrity, backups, and rebuild options with variant-aware expertise.
- 3
Best Practice
Treat identity as the control plane[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
Lesson Learned
Coveware’s three quarterly reports show remote access spanning SaaS, OAuth, SSO, support workflows, tokens, VPN, RDP, and third-party trust.
Minimum Operating Standard
Maintain lifecycle governance, phishing-resistant MFA for privileged paths, token visibility, help-desk verification, connected-app review, and emergency revocation.
- 4
Best Practice
Contain lateral movement before impact[5]Evidence dated Apr 30, 2026
Lesson Learned
Coveware’s Q1 2026 quarterly ransomware report cited lateral movement in 79% of cases, a condition that determines whether the attacker reaches recovery-critical systems.
Minimum Operating Standard
Segment administration, detect east-west movement, restrict remote tooling, isolate quickly, and preauthorize disruptive containment.
- 5
Best Practice
Report averages with medians and denominators[1][4][5]First cited source Oct 24, 2025 · Latest cited source Apr 30, 2026
Lesson Learned
Coveware’s three quarterly reports demonstrate how averages can be dominated by a small number of extreme payments.
Minimum Operating Standard
Every executive statistic identifies the case population, quarter, mean, median, payment rate, impact scenario, and source methodology.
- 6
Best Practice
Preserve evidence through virtualization recovery[3][4][5]First cited source Feb 2, 2026 · Latest cited source Apr 30, 2026
Lesson Learned
Coveware’s Nitrogen technical blog and Q4 2025/Q1 2026 reports show how rebuilds and administrative lockouts can erase impact telemetry.
Minimum Operating Standard
Capture identity, hypervisor, network, EDR, cloud, backup, and management-plane evidence before destructive recovery where safety permits.
Automation Transparency
AI Agent Run Status
| Agent | Coveware Ransomware Rolling Intelligence Card Publisher |
|---|---|
| Status | Active · rolling one-year automation |
| Cadence | Weekly on Monday at 1:00 PM ET |
| Previous run | 24 Jul 2026 · initial consolidation · Run coveware-activity-2026-07-24-initial |
| Previous result | Published the initial one-year product and deprecated the separate quarterly email-only monitor. |
| What the previous run found |
|
| Next run | 27 Jul 2026 · 1:00 PM ET |
| Sources monitored |
|
| Publication and alert policy | Check weekly. Publish and alert only for a new Coveware report or a material source-backed change to threat-actor communications, payments, nonpayment, access, victimology, malware behavior, decryption, recovery, or executive decisions. Supplemental sources must remain labeled and no-change emails are suppressed. |
Related Intelligence and CARDS Records
Other IntelliOS Products
Rolling Intelligence
Global Ransomware Landscape
Broader rolling ransomware ecosystem, victimology, initial access, and operator momentum.
Open productRolling Intelligence
Cyber Insurance Claims, Coverage & Underwriting
Claims severity, payment, recovery expense, underwriting, and coverage context adjacent to Coveware casework.
Open productCARDS Hub
Threat Actor Cards
Canonical actor intelligence for INC Ransom, Akira, Qilin, CL0P, ShinyHunters, and related groups.
Open productPublication History
Version Change Log
| Version | Date | Change | Monitoring |
|---|---|---|---|
| Versionv5 | Date24 Jul 2026 | ChangeRewrote the narrative cards so the prose explicitly names the controlling Coveware publication and reporting quarter—Q3 2025, Q4 2025, Q1 2026, the Obscura technical blog, or the Nitrogen technical blog—rather than relying on numbered citations alone. | MonitoringWeekly Monday material-change review; next run 27 Jul 2026 at 1:00 PM ET. |
| Versionv4 | Date24 Jul 2026 | ChangeAdded Coveware’s authoritative ransomware-blog and quarterly-report collection URLs as explicit retained corpus-index citations. Individual Coveware articles remain the controlling citations for factual claims, while the two indexes document how the complete first-party corpus is enumerated and monitored. | MonitoringWeekly Monday material-change review; next run 27 Jul 2026 at 1:00 PM ET. |
| Versionv3 | Date24 Jul 2026 | ChangeAdded a PETRA report-database reconciliation to the one-year Tier 6 source audit and weekly monitor. PETRA returned two Coveware matches, both duplicates of direct Coveware publications already retained as sources 4 and 5; the database records are documented as candidate hits but not counted as independent evidence. | MonitoringWeekly Monday material-change review; next run 27 Jul 2026 at 1:00 PM ET. |
| Versionv2 | Date24 Jul 2026 | ChangeRebuilt Research Framing source coverage as a complete Tier 0–Tier 8 audit, separating five controlling Coveware publications, two selected GuidePoint supplemental reports, and eight official, peer-research, and legacy-monitor sources checked but not used. | MonitoringWeekly Monday material-change review; next run 27 Jul 2026 at 1:00 PM ET. |
| Versionv1 | Date24 Jul 2026 | ChangeCreated the Coveware one-year Rolling Intelligence Card; consolidated and deprecated the independent quarterly Coveware email agent; retained subscriber continuity; added Research Framing, Timeline, locked BLUF and Executive Summary, statistics, access vectors, victimology, actors, campaigns, technology, monitoring, practices, products, agent status, and citations. | MonitoringWeekly Monday material-change review; next run 27 Jul 2026 at 1:00 PM ET. |
Citations
Retained Sources and Claim Treatment
| # | Publisher | Published | Publication / Evidence | Why Used / Claim Treatment | Source |
|---|---|---|---|---|---|
| Source1 | PublisherCoveware by Veeam | Published2025-10-24 | Publication / evidenceSource indexincident response | Why used / claim treatmentPrimary Coveware Q3 2025 casework report. Statistics describe Coveware-managed cases and are not a global incident census. | SourceQ3 2025 Quarterly Ransomware Report — Insider Threats Loom while Ransom Payment Rates Plummet https://coveware.com/2025/10/insider-threats-loom-while-ransom-payment-rates-plummet/ |
| Source2 | PublisherCoveware by Veeam | Published2025-11-19 | Publication / evidenceSource indexincident response | Why used / claim treatmentPrimary Coveware malware reverse-engineering and recovery analysis. | SourceCoveware Technical Blog — Obscura Ransomware: A Case Study in Ransomware Data Loss https://www.coveware.com/blog/2025/11/18/obscura-ransomware-data-loss-validation |
| Source3 | PublisherCoveware by Veeam | Published2026-02-02 | Publication / evidenceSource indexincident response | Why used / claim treatmentPrimary Coveware technical analysis of an ESXi encryptor defect and recovery consequence. | SourceCoveware Technical Blog — Nitrogen Ransomware: ESXi malware has a bug! https://coveware.com/2026/02/nitrogen-ransomware-esxi-malware-has-a-bug/ |
| Source4 | PublisherCoveware by Veeam | Published2026-02-03 | Publication / evidenceSource indexincident response | Why used / claim treatmentPrimary Coveware Q4 2025 report and historical casework comparison. Statistics are limited to cases Coveware handled. | SourceQ4 2025 Quarterly Ransomware Report — Why Zero-Day Downstream Mass Data Extortion Campaigns are Losing Their Bite https://coveware.com/2026/02/why-zero-day-downstream-mass-data-extortion-campaigns-are-losing-their-bite/ |
| Source5 | PublisherCoveware by Veeam | Published2026-04-30 | Publication / evidenceSource indexincident response | Why used / claim treatmentPrimary Coveware Q1 2026 casework report plus forward-looking patch-management analysis. Observed statistics and forecasts remain separate. | SourceQ1 2026 Quarterly Ransomware Report — Patch management goes from hard, to ludicrous in the agentic AI era https://coveware.com/2026/04/patch-management-goes-from-hard-to-ludicrous-in-the-agentic-ai-era/ |
| Source6 | PublisherGuidePoint Security GRIT | Published2026-04-15 | Publication / evidenceSource indexprimary research | Why used / claim treatmentSupplemental peer context using public, vendor, incident-response, OSINT, forum, and marketplace evidence. It does not control Coveware-specific claims. | SourceRansomware Insights from Q1 2026 https://www.guidepointsecurity.com/blog/ransomware-insights-q1-2026/ |
| Source7 | PublisherGuidePoint Security GRIT | Published2026-07-09 | Publication / evidenceSource indexprimary research | Why used / claim treatmentSupplemental external victim-post and ecosystem context. Leak-site reporting is not equivalent to confirmed incidents or Coveware-managed casework. | SourceGRIT Q2 2026 Ransomware & Cyber Threat Insights Report https://www.guidepointsecurity.com/resources/grit-q2-2026-ransomware-cyber-threat-insights-report/ |
| Source8 | PublisherCoveware by Veeam | PublishedNot available | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentAuthoritative first-party corpus index used to enumerate and monitor Coveware’s complete ransomware-blog publication stream. This index documents source coverage; individual articles remain the controlling citations for factual claims. | SourceCoveware Ransomware Recovery Blog https://coveware.com/ransomware-blog/ |
| Source9 | PublisherCoveware by Veeam | PublishedNot available | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentAuthoritative first-party quarterly-report index used to identify every in-window Coveware quarterly publication. This index documents source coverage; each quarterly report is cited separately for statistics and conclusions. | SourceCoveware Ransomware Quarterly Reports https://coveware.com/category/quarterly-report/ |
