The Colonial Pipeline attack of May 2021, which shut down the largest fuel pipeline in the United States for five days and triggered a $4.4 million ransom payment, was a wake-up call for a public that had largely tuned out cybersecurity news. But the attack was notable for another reason: it was not carried out by a nation-state or a sophisticated criminal syndicate operating in-house. It was enabled by ransomware-as-a-service — a business model in which malware developers licence their ransomware to affiliate attackers in exchange for a share of the profits. The ransomware industry has professionalised, and it is now one of the fastest-growing sectors of the global criminal economy.

The Economics of RaaS

Ransomware-as-a-service works like a perverse franchise operation. The developer — the “operator” — builds and maintains the ransomware software, creates the negotiation infrastructure and collects the ransoms. Affiliates — who may have no technical expertise — gain access to victim networks through phishing, compromised credentials or unpatched vulnerabilities, deploy the ransomware and share 20-30% of any ransom paid. The operator handles the rest: hosting the negotiation portal, providing customer support to victims and laundering the cryptocurrency payments. Some RaaS operations even offer affiliate dashboards with real-time statistics, support ticketing systems and performance bonuses for high-value targets.

The scale is staggering. Chainalysis reported that ransomware payments totalled $1.1 billion in 2023 — a record — and while 2024 saw a modest decline to approximately $950 million, the number of attacks increased significantly, reflecting a shift toward smaller ransoms from a larger volume of victims. The median ransom demand fell from roughly $400,000 in 2021 to approximately $200,000 in 2024, as attackers shifted from targeting large enterprises with dedicated security teams to targeting mid-market companies, local governments and healthcare providers that are less likely to have robust defences. The healthcare sector has been particularly hard hit: a 2024 report from the US Department of Health and Human Services tracked over 500 ransomware incidents affecting healthcare organisations in a single year, disrupting patient care, exposing sensitive medical data and, in at least one documented case, contributing to a patient death when a hospital’s systems were offline during a critical care episode.

The Major RaaS Players

LockBit was, until February 2024, the most prolific ransomware group in the world, responsible for an estimated 25% of all ransomware attacks globally. The group’s takedown by an international law enforcement operation — led by the UK’s National Crime Agency with support from the FBI and Europol — was the most significant disruption of ransomware infrastructure in history. Law enforcement seized LockBit’s servers, took control of its affiliate portal and released decryption keys for thousands of victims. But within months, LockBit affiliates had migrated to other RaaS platforms, and the ecosystem quickly adapted.

ALPHV (also known as BlackCat) operated the second-largest RaaS platform until its apparent exit scam in March 2024, when the operators disappeared with a $22 million ransom payment from Change Healthcare, a subsidiary of UnitedHealth Group, stiffing the affiliate who had conducted the attack. The Change Healthcare breach was one of the most consequential cyberattacks of the decade: the company processes approximately 15 billion healthcare transactions annually, and the outage disrupted pharmacy claims processing, provider payments and patient care across the US healthcare system for weeks. UnitedHealth Group ultimately paid a $22 million ransom, and the incident’s total financial impact — including lost revenue, remediation costs and regulatory penalties — is estimated to exceed $2 billion.

Defences That Work

The technical defences against ransomware are mature and well understood: multi-factor authentication (which blocks the credential theft that enables most initial access), network segmentation (which limits lateral movement), endpoint detection and response (EDR) platforms (which catch ransomware deployment before encryption begins) and offline, immutable backups (which enable recovery without paying the ransom). The challenge is not technological — it is operational. These measures are inconsistently deployed, particularly in mid-market organisations and public-sector entities with limited IT budgets and cybersecurity expertise.

The policy response has accelerated. The US Cybersecurity and Infrastructure Security Agency (CISA) now mandates ransomware incident reporting for critical infrastructure operators with significant financial penalties for non-compliance. The Office of Foreign Assets Control (OFAC) has designated several cryptocurrency exchanges used by ransomware operators for sanctions, making it illegal for US persons to transact with them. And the international law enforcement collaboration that took down LockBit — involving agencies from 11 countries — suggests that governments are finally treating ransomware as the transnational crime problem it is, rather than as a series of isolated incidents. Whether these measures will be enough to stem the tide is an open question. The RaaS business model is resilient precisely because it is decentralised — take down one platform and the affiliates migrate to another. The fight against ransomware, like the fight against the drug trade, is likely to be a permanent campaign rather than a winnable war.

Leave a Reply

Your email address will not be published. Required fields are marked *