* [Blog](https://www2.paloaltonetworks.com/blog) * [Palo Alto Networks](https://www2.paloaltonetworks.com/blog/corporate/) * [Threat Intelligence](https://www2.paloaltonetworks.com/blog/category/threat-intelligence/?lang=zh-hant) * 從勒索到營收損失 # 從勒索到營收損失 [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2F2025%2F12%2Ffrom-extortion-to-loss%2F%3Flang%3Dzh-hant) [](https://twitter.com/share?text=%E5%BE%9E%E5%8B%92%E7%B4%A2%E5%88%B0%E7%87%9F%E6%94%B6%E6%90%8D%E5%A4%B1&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2F2025%2F12%2Ffrom-extortion-to-loss%2F%3Flang%3Dzh-hant) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2F2025%2F12%2Ffrom-extortion-to-loss%2F%3Flang%3Dzh-hant&title=%E5%BE%9E%E5%8B%92%E7%B4%A2%E5%88%B0%E7%87%9F%E6%94%B6%E6%90%8D%E5%A4%B1&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www2.paloaltonetworks.com/blog/2025/12/from-extortion-to-loss/?lang=zh-hant&ts=markdown) [](mailto:?subject=從勒索到營收損失) Link copied By [Dan O'Day](https://www.paloaltonetworks.com/blog/author/dan-oday/?lang=zh-hant&ts=markdown "Posts by Dan O'Day") Dec 15, 2025 1 minutes [Threat Intelligence](https://www.paloaltonetworks.com/blog/category/threat-intelligence/?lang=zh-hant&ts=markdown) **網路攻擊如何直接衝擊企業獲利** 勒索軟體攻擊的成本正持續攀升,嚴重程度已足以引起財務單位的高度關注,成為企業面臨的核心經營挑戰之一。當營運遭受全面中斷時,資安議題已不僅是技術問題,而是攸關品牌信任、營運穩定與營收損失的策略性風險。這類攻擊的實際後果遠不止於贖金支付,更會直接侵蝕企業的利潤。 隨著企業面臨長時間停擺、合作夥伴與客戶關係緊張,以及營收受損等壓力,攻擊者也藉由更具破壞性的手法獲得更高的籌碼,並提出更高額的勒索要求。根據[《2025 Palo Alto Networks 威脅情報小組Unit 42 全球事件應變報告》](https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report),勒索攻擊的中位數初始贖金要求從 2023 年的 69.5 萬美元激增近 80%,至 2024 年的 125 萬美元。近日,勒索軟體集團Devman在一天內聲稱攻擊了4家台灣醫療、軟體等企業,並索取達100萬至600萬美元(約1.8億台幣)不等的贖金,甚至在暗網公開出售竊取的企業資料,對台灣企業造成嚴重資安威脅與財務風險。 但贖金並非唯一代價。企業在系統恢復與修復過程中所需投入的成本,加上信任受損、商機流失、合規罰款與其他間接損失,總額可能高達數十億美元。隨著攻擊手法日益精密、導致更嚴重的營運中斷,這些事件反而迫使企業加速數位轉型並強化資安防禦,意外地成為推動營運韌性與創新的催化劑。 我們將從損益的角度檢視[勒索軟體攻擊](https://www.paloaltonetworks.com/cyberpedia/ransomware-common-attack-methods),並探討如何調整復原策略以確保業務持續運作。 **我們對勒索軟體要求的最新觀察** 贖金的初始要求通常落在企業「預估年度營收」(PAR, Perceived Annual Revenue)的 0.05% 至 5% 之間。根據我們的研究,2024 年的贖金中位數要求約為 PAR 的 2%,攻擊者多半透過 ZoomInfo 等公開資料來源來評估企業規模與財務狀況。 **真正的問題是:你該付嗎?** 答案因情況、客戶與攻擊者而異,但「付贖金」確實是某些情境下可考慮的選項。2024 年,約有 48% 的勒索軟體受害者選擇支付贖金。多數勒索組織傾向履行承諾,因為若失信於人,將削弱其威脅的可信度,也會讓未來受害者失去付款動機。在雙方都信守承諾的前提下,對於那些缺乏經驗豐富的災難復原計畫、或備份系統在攻擊中遭到破壞的組織而言,支付贖金往往是最快恢復營運的途徑。 在專業團隊協助下,贖金金額其實有相當的協商空間,而且往往幅度不小。以 Unit 42 的經驗而言,我們通常能成功將贖金要求降至年營收預估值(PAR)的中位數 0.6%。整體而言,經 Unit 42 協商後實際支付的贖金金額,平均可降低約 53%。或許正因如此,2023 年至 2024 年間,勒索軟體案件的中位數實際支付金額僅增加約 3 萬美元。 這是好消息;但壞消息是,攻擊者正不斷尋找新的手段來取得更大的籌碼。他們越來越常採用具破壞性的策略,使關鍵營運系統停擺,導致復原與修復成本,以及其他相關支出的大幅攀升。根據我們 2024 年的案例數據顯示,86% 的事件都造成了嚴重的業務中斷,包括營運停機、品牌聲譽受損,或兩者兼具。 **破壞時代下的勒索軟體** 過去的勒索軟體案例相對單純:攻擊者入侵企業系統、加密關鍵檔案,然後要求以加密貨幣支付贖金以解鎖檔案。但隨著時間推進,企業在資料備份上的能力大幅提升。如今,許多組織能夠透過備份資料來還原系統、持續營運,而不必支付贖金。 如果說加密是勒索軟體的第一波浪潮,那麼第二波則以資料外洩與騷擾為特徵。攻擊者不再只是鎖住檔案,而是開始竊取敏感資料並威脅其公開,有時還透過暗網市場拍賣被竊的資料,甚至建立「洩露網站」來抹黑目標,並透過惡意訊息騷擾員工。 如今,隨著資料外洩事件頻繁登上新聞版面,消費者對此已逐漸麻木,對資料被竊的警覺性下降。資料外洩疲勞削弱了暗網上被盜資料的價值,也減弱了攻擊者在勒索中的槓桿力。為了重新掌控局勢,攻擊者開始對企業系統施加更大破壞,第三波勒索軟體浪潮因此以「破壞」為核心。 需要釐清的是,攻擊者在資料外洩與騷擾之上增加了破壞手段。我們觀察到,資料外洩與騷擾的發生率比以往更高。對攻擊者而言,目標就是最大化槓桿效應。 同時,企業也愈來愈多採取備份策略來減緩攻擊影響。2024 年,近一半受影響的勒索軟體受害者能透過備份恢復系統,約為 2022 年的五倍。 **保護你的組織** 除了精進備份策略外,組織還應採取主動方式,加強任何組織標準安全支柱: * **網路** * **身分識別** * **終端設備** * **雲端與應用程式** * **安全運營** 採用零信任(Zero Trust)變得更加重要。從根本上說,零信任可限制勒索軟體攻擊者橫向移動、提升權限、存取關鍵系統以及掌控敏感資料的能力。 阻止存取並保護靜態資料,可以防止資料被加密或外洩。透過分段(Segmentation)可限制攻擊路徑,降低勒索軟體威脅的影響範圍,這對於無法修補或升級的舊有系統尤為重要。[多重因素驗證](https://www.paloaltonetworks.com/cyberpedia/what-is-multi-factor-authentication)(MFA)可以防禦憑證被盜用的風險,而持續監控可偵測與勒索軟體相關的行為,加速偵測與回應,包括要求在存取關鍵內部系統時進行橫向移動的多因素驗證。 零信任(Zero Trust)看似艱難,但並非不可能,也不是全有或全無。採取漸進式方法有助於穩步實現零信任。 **搶先因應下一波威脅** 勒索軟體已經成為常態,其風險只會持續升高。將安全與勒索風險與財務策略對齊,能幫助你的組織規劃並減輕勒索攻擊的影響。Unit 42 隨時準備提供協助 * **AI** **安全評估**:我們的專家協助你全面掌握現況,並制定策略以促進安全的 AI 使用與開發。我們業界領先的威脅情報與 AI 專業知識,可提供針對你 AI 足跡的量身化最佳實務,降低相關風險。 * **SOC** **評估**:我們將提供可執行的框架,將你的 SOC 轉型為高度效率、主動偵測與回應的領導者,結合 AI 與自動化技術。你的 SOC 將從被動的緊急應對,轉變為與組織業務目標對齊的主動型網路韌性。 * **雲端安全評估**:透過將安全計畫與現代雲端環境的動態與分散特性對齊,提升對雲端的信心,確保從開發到部署都能得到有效防護。 *** ** * ** *** ## Related Blogs ### [Threat Intelligence](https://www.paloaltonetworks.com/blog/category/threat-intelligence/?lang=zh-hant&ts=markdown) [#### 社交工程攻擊日益猖獗](https://www2.paloaltonetworks.com/blog/2025/09/social-engineering-attacks-increasing/?lang=zh-hant) ### Subscribe to the Blog! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www2.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} ## Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) ## Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) ## Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language