The Business Model That Shouldn’t Exist
Ransomware has evolved from a crude extortion scheme into a sophisticated criminal enterprise with professional-grade software, customer support, affiliate programs, and revenue sharing. The “ransomware-as-a-service” (RaaS) model — where developers create and maintain ransomware toolkits and license them to “affiliates” who carry out attacks — has industrialized cybercrime. The numbers are staggering and getting worse.
The Scale of the Problem
Chainalysis, the blockchain analytics firm, tracked approximately $1.1 billion in ransomware payments in 2023 — and that’s just what’s visible on public blockchains. The true figure is almost certainly higher, as many payments occur through intermediaries or go unreported. The FBI’s Internet Crime Complaint Center (IC3) received 2,825 ransomware complaints in 2023, with reported losses exceeding $500 million. Both numbers understate the problem dramatically — many victims pay quietly and never report.
The most notorious groups have become household names in cybersecurity circles:
- LockBit: The most prolific RaaS operation, responsible for roughly 25% of all ransomware attacks in 2023-2024. LockBit 3.0 (also called LockBit Black) includes a bug bounty program — yes, the criminals pay researchers to find vulnerabilities in their ransomware. The FBI and international partners disrupted LockBit’s infrastructure in February 2024, but the group rebuilt and continued operations within months.
- ALPHV/BlackCat: Responsible for the September 2023 attack on MGM Resorts that shut down casino operations across Las Vegas for days, costing the company an estimated $100 million in lost revenue and recovery costs. ALPHV’s affiliates also breached Change Healthcare in February 2024, causing massive disruption to US healthcare payments. The group received a reported $22 million ransom from Change Healthcare’s parent company UnitedHealth.
- Clop: Specialized in exploiting vulnerabilities in file transfer software (Accellion FTA in 2021, GoAnywhere MFT in 2023, MOVEit Transfer in 2023). The MOVEit attack alone affected over 2,600 organizations and 90+ million individuals, according to Emsisoft.
How RaaS Actually Works
The RaaS model mirrors legitimate software businesses with disturbing fidelity. Core developers build and maintain the ransomware code, manage the payment infrastructure (typically cryptocurrency), host leak sites where stolen data is published if victims don’t pay, and provide support to affiliates. Affiliates handle the actual attacks — gaining initial access, moving laterally through networks, exfiltrating data, and deploying the ransomware.
Revenue splits typically range from 70-80% to the affiliate, 20-30% to the developer. Some groups charge a flat fee for access to the ransomware. Others operate on a pure commission basis. Marketing happens on dark web forums with professional-looking ads and “customer reviews.” Some groups even offer “ransomware negotiation services” — negotiating with victims on behalf of affiliates.
The barriers to entry have dropped to nearly zero. An aspiring cybercriminal with no technical skills can purchase an off-the-shelf ransomware kit, rent access to already-compromised corporate networks (sold by “initial access brokers”), and launch an attack for a few thousand dollars. The industrialization of cybercrime means the number of capable attackers has expanded from a small group of sophisticated hackers to basically anyone with Bitcoin and criminal intent.
Double and Triple Extortion
Modern ransomware attacks don’t just encrypt data — they steal it first. This “double extortion” tactic means victims face two threats: pay to get your data decrypted, and pay to prevent your data from being published. Even organizations with good backups can’t ignore the data leak threat.
Triple extortion adds a third layer: attackers contact the victim’s customers, partners, or patients and demand payment directly from them, threatening to leak their data. It’s extortion layered on extortion, and it’s devastatingly effective. The average ransom payment in 2024 was estimated at $400,000-600,000, but the total cost of a ransomware attack — including downtime, recovery, reputational damage, and regulatory fines — averages $4-5 million according to IBM’s Cost of a Data Breach Report.
Government Response
The international response has escalated but remains reactive rather than preventative. The US government’s Joint Ransomware Task Force (established 2022) coordinates between CISA, FBI, and international partners. The International Counter Ransomware Initiative, launched in 2021, now includes over 50 countries committed to sharing intelligence and disrupting ransomware infrastructure. “We will not pay ransoms” policies adopted by many governments aim to reduce the incentive, but private companies — facing existential operational disruption — keep paying.
The most effective countermeasure has been offensive disruption. In 2023-2024, law enforcement operations dismantled the Hive ransomware group’s infrastructure (FBI infiltrated their network and provided decryption keys to 1,300+ victims), disrupted ALPHV/BlackCat (FBI developed a decryption tool and seized their leak site), and took down LockBit infrastructure (though the group quickly rebuilt). These operations raise complex legal questions — FBI hacking criminal infrastructure without explicit warrants sits in a legal gray zone — but they’re the most effective tool available.
What Actually Works for Defense
The uncomfortable truth: most ransomware attacks succeed because of basic security failures. The top initial access vectors, according to CISA, are unpatched vulnerabilities, phishing, and remote desktop protocol (RDP) exposed to the internet — all problems with known solutions that organizations fail to implement.
Defending against ransomware requires multi-factor authentication everywhere, patching vulnerabilities within 48 hours (not weeks or months), offline backups that are tested regularly, network segmentation to limit lateral movement, endpoint detection and response (EDR), and — most importantly — phishing-resistant authentication. These aren’t cutting-edge techniques. They’re security basics that organizations have been told to implement for decades and still, somehow, haven’t.
Ransomware in 2025 is a multi-billion dollar criminal enterprise that operates like a Fortune 500 company, targets organizations of all sizes, and shows no signs of slowing. The technology to stop most attacks exists. The will to implement it consistently is what’s missing.

