Key findings at a glance
|
We surveyed 1,000 owners and managers of small businesses (50 or fewer employees) nationwide about website security. What we found: 12% have received a ransom demand related to their website, email, or data — and paid it.
Why does this matter?
Small businesses are squarely in attackers’ sights. Verizon’s 2025 Data Breach Investigations Report found ransomware present in 88% of breaches at small and midsize businesses, compared to 39% at larger organizations. Our findings show what that looks like on the ground for everyday business owners, not just large enterprises.
As a web hosting provider that serves thousands of small businesses, DreamHost wanted to understand the real-world impact of these threats and how prepared businesses are to respond. The results point to clear gaps — and actionable solutions — in small business cybersecurity.
Picture a room of a hundred people who run websites: freelancers, store operators, small business owners; folks who just want their site to work. Now count off twelve of them.

Twelve out of every 100 have received a ransom demand tied to their website, email, or data — and paid it. When a cyberattack takes a website offline, the disruption is immediate: inaccessible admin panels, unfulfilled orders, and locked customer data.
For many, paying looks like the fastest way back online. It often isn’t. In a Ponemon Institute report cited by PurpleSec, only 13% of businesses that chose to pay a ransom received all of their data back.
The concern extends beyond those who have paid. 42% of respondents reported being “very concerned” about ransomware attacks targeting websites, reflecting widespread awareness of the threat.
The full survey data reveals why that concern is justified — and what businesses can do about it.
Let’s get into it.
1 in 8 small business owners have paid a ransom

That 12% represents businesses forced to decide how to contain the incident, restore operations, and respond to the demand.
Ransomware attacks are not limited to large enterprises. Small businesses with accessible online infrastructure face the same threats.
A closer look at those who received ransom demands reveals the role preparedness plays in decision-making.
Of the 28.4% who faced a demand, 41.5% paid the ransom. When facing that moment — site down, data locked, revenue frozen — nearly half choose to pay.

On the flip side: 58.5% refused. That’s nearly 6 in 10 businesses that declined to pay. And refusal is becoming the norm beyond our sample, too: per Verizon’s 2025 DBIR, 64% of ransomware victims now refuse to pay, up from 50% two years earlier.
Our survey didn’t ask each business why it refused, but the math of refusal is simple: saying no is far easier when you have a clean, tested backup and a fast way to restore it. Without one, the attacker holds all the leverage.
Nearly half of small business owners are deeply worried about ransomware
42% of respondents in our survey said they’re “very concerned” about the rising threat of ransomware attacks targeting websites. Add in those who are “somewhat concerned,” and 84.6% of respondents see ransomware as a legitimate threat.
The website is the business — the storefront, the pipeline, the hub. Disruption to access can directly impact business operations.

This apprehension reflects a broader shift: ransomware has expanded beyond large enterprises to target small businesses.
High-profile breaches illustrate the scope of the threat.
Take AT&T. After a breach affecting 73 million current and former account holders — whose information, including Social Security numbers and birth dates, was found in a dataset on the dark web — the company reached a $177 million class-action settlement in 2025 covering that incident and a second 2024 breach.
If organizations with dedicated security teams experience breaches of this scale, small businesses face similar vulnerabilities without comparable resources for proactive protection.
The writing’s on the wall: neglect invites exposure.
Our survey data shows that many business owners recognize common security weaknesses: outdated plugins, weak passwords, and neglected CMS updates. Recognizing the weak spots is the first step. Fixing them is the part too many skip.
Nearly half of businesses have experienced a cyberattack
That widespread concern isn’t unfounded. 46% of our respondents have already experienced a cyberattack, resulting in exposed data, encrypted files, or complete site shutdowns.

Separately, 38% of respondents reported that their website had been hacked or infected with malware.
- Compromised logins
- Infected plugins
- SEO spam redirects
- Suspended domains
Each can mean lost revenue from downtime, damaged search rankings, and eroded customer trust — problems that compound quickly for small businesses operating on thin margins.

Malware infections, in particular, can spread quickly through outdated plugins and themes, and for 14% of those who’ve been hacked, it’s not a one-time event — they’ve experienced multiple attacks.
Treat your web host’s built-in security as a foundation, not a full defense. Prevention is still your job: install updates, run security audits, and replace weak credentials. And if you’d rather not hunt for malware yourself, DreamHost’s DreamShield add-on scans a DreamHost-hosted site daily, blocks the malware it detects, and alerts you when something’s wrong.
Yet many website owners still approach cybersecurity reactively rather than proactively — operating with the same vulnerabilities that got them breached in the first place.
1 in 4 small businesses never test their website backups

Even after being hacked or seeing peers experience data loss, many businesses still haven’t verified that their website backups actually work. Nearly one in four respondents (24%) reported they’ve never tested their backup and restore process.
That gap between having a plan and having a plan that works is where minor crises become major business disruptions.
Many owners assume “auto-backup” means “auto-recovery.”
It doesn’t.
Backups can fail silently or become corrupted, and the worst time to find that out is mid-crisis. CISA’s baseline advice applies to businesses of every size: back up data regularly, keep it on a separate device, and store it offline. Then test a restore while nothing is on fire — DreamHost’s web hosting plans include daily automated backups, and DreamPress adds on-demand backups and one-click restores, so a dry run is a small job instead of a rescue mission.
40% would pay for backups to avoid paying hackers
There is a positive trend in the data: 40% of respondents said they’d be most likely to invest in automated website backups if it meant they could avoid paying a ransom.

This represents a shift toward prevention as a financial decision. Nearly a quarter of respondents cited cost or complexity as the barrier keeping them from backup solutions. The numbers say that barrier is worth clearing.
4.6% said they’d never invest in backups at all. These businesses remain vulnerable to ransomware attacks.
According to PurpleSec, small businesses impacted by a data breach can expect to pay $120,000 to $1.24 million to respond and recover.
A clean, tested backup can shorten recovery and reduce pressure to pay. Keep backups separate and offline, test the restore process, and treat backups as one part of a broader security and incident-response plan.
Summary
Nearly half of small businesses have already experienced a cyberattack, and awareness is high: 84.6% of our respondents see ransomware as a legitimate threat. The next step is treating cybersecurity as continuity planning, not just a technical cost.
The path forward is clear. Resilience is built with disciplined preparation: rigorously tested backups, tools that automate defense, and a commitment to digital preparedness.
Quick response and tested recovery capabilities are important parts of a layered ransomware defense.
Businesses that prepare in advance keep the decision in their own hands: restore, don’t pay.
Small business ransomware statistics: FAQs
How many small businesses have paid a ransom?
In DreamHost’s October 2025 survey of 1,000 U.S. small business owners and managers, 12% said they’d received a ransom demand related to their website, email, or data — and paid it. Among just those who received a demand, 41.5% paid.
What percentage of small business breaches involve ransomware?
Verizon’s 2025 Data Breach Investigations Report found ransomware present in 88% of breaches at small and midsize businesses, compared to 39% at larger organizations.
What is the average ransomware demand?
PurpleSec’s 2025 roundup puts the average ransom demand in 2024 at $5.2 million. What victims actually hand over is far smaller: Verizon’s 2025 DBIR reported median ransom payments fell to $115,000, down from $150,000 the year before.
Should a small business pay the ransom?
We recommend against it. CISA notes there’s no guarantee you’ll recover your files even if you pay, and in a Ponemon Institute report cited by PurpleSec, only 13% of businesses that chose to pay received all of their data back. A tested backup lets you restore instead of negotiate.
How much does recovering from a breach cost a small business?
According to PurpleSec, small businesses impacted by a data breach can expect to pay $120,000 to $1.24 million to respond and recover.
Methodology
This article is based on a nationwide survey conducted in October 2025, in which we collected responses from 1,000 Americans to better understand their experiences and concerns related to website security and cyber threats. The survey specifically targeted individuals who own or manage businesses with 50 or fewer employees, ensuring the data reflects the unique challenges and realities faced by small business operators.
Participants represented a diverse cross-section of industries and professional backgrounds, offering a well-rounded snapshot of public sentiment and real-world impacts. Respondents were asked a series of questions about ransomware, website breaches, data protection practices, and incident response, providing valuable insights into the current state of cybersecurity awareness and preparedness among small business owners in the U.S.
Fair Use
Users are welcome to use the insights and findings from this study for non-commercial purposes, such as academic research, educational presentations, and personal reference. When referencing or citing this article, please ensure proper attribution to maintain the integrity of the research. Direct linking to this article is permissible, and access to the original source of information is encouraged.
For commercial use or publication purposes — including but not limited to media outlets, websites, and promotional materials — please contact our Corporate Communications team for permission and licensing details.
We appreciate your respect for intellectual property rights and adherence to ethical citation practices. Thank you for your interest in our research.
![[STUDY] 12% of Small Businesses Say They’ve Paid a Ransom Demand thumbnail](https://www.dreamhost.com/blog/wp-content/uploads/2025/11/1460x1095_blog_hero_12_of_small_businesses_say_they_ve_paid_a_ransom_demand-730x548.webp)
