Inside the Ransomware Economy: How a $20 Billion Criminal Industry Actually Works

Ransomware is no longer a cottage industry of lone hackers sending mass phishing emails. It has evolved into a sophisticated, industrialized criminal ecosystem with its own supply chains, customer support desks, and revenue-sharing models. The ransomware-as-a-service (RaaS) model, in which developers create ransomware toolkits and lease them to affiliates who carry out attacks, has driven the global cost of ransomware to an estimated $20 billion annually. Understanding how this underground economy operates is essential for any organization serious about defending against it.

Google · Preferred Sources

Don't miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

The Business Model

A RaaS operation functions remarkably like a legitimate software-as-a-service business. At the top sits the development team, which builds and maintains the ransomware payload, the encryption routines, the command-and-control infrastructure, and the payment processing systems. These developers typically do not carry out attacks themselves. Instead, they recruit affiliates, independent operators who use the toolkit to breach targets, deploy the ransomware, and negotiate ransoms.

Revenue splits vary by operation but typically follow a 70/30 or 80/20 model, with the affiliate receiving the larger share. Some RaaS groups charge a flat monthly subscription fee plus a per-attack commission. The most successful operations, including LockBit, BlackCat (ALPHV), and their successors, have generated hundreds of millions of dollars in cryptocurrency payments, with individual ransom demands ranging from tens of thousands of dollars for small businesses to tens of millions for critical infrastructure targets.

Inside the Supply Chain

The RaaS ecosystem extends well beyond the ransomware developers and their affiliates. Initial access brokers (IABs) form a critical upstream market, selling compromised credentials, VPN access, and Remote Desktop Protocol (RDP) sessions on dark web marketplaces. Prices range from $10 for basic credentials to $100,000 for administrative access to large enterprise networks. Affiliates purchase this access and use it as their entry point, dramatically reducing the technical skill required to launch an attack.

Bulletproof hosting providers offer infrastructure that resists law enforcement takedowns, while cryptocurrency mixing services and privacy coins launder ransom payments. Negotiation specialists, sometimes employed directly by the RaaS group, manage victim communications, set payment deadlines, and apply psychological pressure to maximize payouts. Some groups have even established call centers that phone victims directly to escalate urgency.

Evolving Tactics: Double and Triple Extortion

Traditional ransomware simply encrypted files and demanded payment for the decryption key. Modern RaaS operations employ multi-layered extortion strategies. In double extortion, attackers exfiltrate sensitive data before encrypting systems and threaten to publish the stolen information on leak sites if the ransom is not paid. This tactic is effective even against organizations with robust backup strategies, because restoring from backups does not prevent data exposure.

Triple extortion adds a third pressure vector: attacking the victim’s customers, partners, or patients directly. Healthcare organizations have seen ransomware groups contact individual patients with threats to release their medical records. the FinOps discipline institutions have faced threats of notifying regulators about breached data. Each layer of extortion increases the probability and size of payment, making the economics overwhelmingly favorable for attackers.

Law Enforcement Response

International law enforcement has intensified operations against RaaS groups. The FBI and Europol-led takedowns of Hive, LockBit infrastructure, and the seizure of BlackCat’s leak sites have disrupted operations and eroded trust within the criminal ecosystem. However, the decentralized nature of RaaS means that disrupted groups frequently reconstitute under new names. LockBit’s operation resumed within weeks of its February 2024 disruption, and former BlackCat affiliates migrated to competing platforms with minimal downtime.

Sanctions against cryptocurrency addresses associated with ransomware payments have introduced friction into the payment chain, but the ecosystem adapts quickly. Cross-chain bridges, decentralized exchanges, and privacy-focused cryptocurrencies like Monero provide alternatives that are significantly harder to trace and seize.

Defending Against the Machine

Defending against industrialized ransomware requires an equally systematic approach. The fundamentals remain critical: patching known vulnerabilities, enforcing multi-factor Zero Trust architecture on all remote access, segmenting networks to limit lateral movement, and maintaining offline backups that are tested regularly. Beyond the basics, organizations are increasingly adopting extended detection and response (XDR) platforms that correlate signals across endpoints, network traffic, and cloud environments to detect the multi-stage attack chains that precede ransomware deployment.

Threat intelligence sharing through organizations like the Ransomware Task Force and sector-specific ISACs provides early warning of new TTPs and indicators of compromise. Tabletop exercises that simulate ransomware incidents help leadership teams make faster, more informed decisions when real attacks occur, reducing downtime and the temptation to pay.

The ransomware-as-a-service economy will not be dismantled overnight. Its profitability ensures a continuous supply of new operators, and its modular structure makes it resilient to disruption. For defenders, the imperative is clear: treat ransomware not as a technology problem but as a business threat that demands executive attention, sustained investment, and cross-functional collaboration.

2025-2026 Ransomware Statistics: Verified Data

The ransomware economy continues to grow despite intensified law enforcement action. Based on verified data from Chainalysis, Sophos, and Verizon’s DBIR 2025:

  • Total ransomware payments (2024): $1.1 billion in tracked cryptocurrency payments, down from the $1.2 billion record in 2023, according to Chainalysis. The actual economic cost including downtime, remediation, and lost business is estimated at $20+ billion (Cybersecurity Ventures)
  • Average ransom demand: $2.73 million (Sophos State of Ransomware 2025), up from $1.54 million in 2023
  • Median ransom payment: $400,000 — reflecting that most victims negotiate down significantly from initial demands
  • Payment rate: 29% of ransomware victims paid the ransom in 2024, down from 34% in 2023, as organizations improve backup strategies
  • Average recovery time: 24 days of operational disruption per incident (Coveware Q4 2024)
  • Top attack vectors: Exploited vulnerabilities (32%), compromised credentials (29%), phishing emails (24%)

Notable 2024-2025 incidents include the Change Healthcare breach (UnitedHealth paid a $22 million ransom; total cost estimated at $2.5 billion, with 193 million individuals affected by mid-2025), the Synnovis NHS attack in London (disrupted blood services for weeks), NASCAR attacked by the Medusa gang in April 2025 ($4 million ransom demand, 1+ TB stolen), DaVita kidney care hit by the Interlock group (2.7 million individuals’ data exposed), and the LockBit infrastructure takedown by Operation Cronos (February 2024), which seized 34 servers but failed to permanently disable the group. Global ransomware damage costs reached an estimated $57 billion annually in 2025, or $156 million per day. The FBI’s IC3 received over 2,825 ransomware complaints in 2024, with healthcare and critical infrastructure the most-targeted sectors.

Related Reading

Elias Virtanen

Elias Virtanen

Cybersecurity Analyst

Elias Virtanen is the Cybersecurity Analyst at Tech Insider, bringing hands-on expertise from his background in penetration testing and security consulting. He previously worked as a security researcher at F-Secure in Helsinki, where he focused on threat intelligence and vulnerability disclosure. Elias covers ransomware trends, zero-trust architecture, and the evolving regulatory landscape including NIS2 and the EU Cyber Resilience Act. He holds a CISSP certification and an MSc in Information Security from Aalto University.

View all articles