Google reported paying $17.1 million to 747 security researchers in 2025 through its Vulnerability Reward Program (VRP), bringing total payouts since 2010 to $81.6 million; the highest single reward in 2025 was $250,000. Google also highlighted expansion of bounty coverage into newer areas, including an AI Vulnerability Rewards Program, new Chrome VRP reward categories for AI-related bugs, and a rewards program tied to OSV-SCALIBR for identifying flaws in software dependencies.
Separately, a Chainalysis report cited by KnowBe4 said ransomware attacks increased 50% in 2025 even as observed on-chain ransom payments declined 8% YoY to $820 million (with the caveat that attribution updates could push the total toward or above $900 million). Chainalysis also reported that while fewer victims paid, the average payment among those who did rose 368% YoY to nearly $60,000, and assessed that ransomware operators continued to evolve extortion tactics to increase leverage and impact beyond direct cryptocurrency payments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Google said it paid more than $17 million to 747 security researchers through its Vulnerability Reward Program in 2025, the highest annual total since the program began. The company also said its 2025 efforts included new AI-related reward categories and additional bounty programs, with the top single reward reaching $250,000.
Chainalysis found that ransomware attacks increased by 50% in 2025, while the share of victims paying ransoms dropped to an all-time low. It recorded more than $820 million in on-chain ransomware payments for 2025, down from an updated 2024 estimate of $892 million, while noting the final 2025 total could rise as attribution improves.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.