Ransomware as a Business Model: The $1 Trillion Criminal Enterprise Targeting Critical Infrastructure
Objective
Assess the scale, economics, and evolution of the ransomware ecosystem and evaluate current response strategies.
Methodology
Analysis of ransomware incident data from CISA, FBI IC3, and Chainalysis blockchain forensics. Criminal business model analysis drawing on leaked ransomware group communications and court documents. Policy effectiveness assessment of sanctions, law enforcement operations, and technical countermeasures.
Findings
1T in 2023 (Chainalysis), up from $500M in 2020. Healthcare sector now the primary target — 389 hospital ransomware attacks in 2024, average downtime 18 days. RaaS (Ransomware-as-a-Service) model has industrialised criminal operations — LockBit and ALPHV operated as franchises with developer/affiliate splits.
Law enforcement takedowns (LockBit Feb 2024) disrupt but do not eliminate — groups reconstitute within 3-6 months. The most effective interventions are offline backups and network segmentation — organisations with these rarely pay ransom.
Cryptocurrency remains the payment rail; effective regulation of crypto mixing services would significantly increase law enforcement effectiveness.
Key Assumptions
- •Ransomware payments are significantly underreported; actual figures likely 2-3x disclosed amounts.
Limitations
- •Attribution of attacks to specific criminal groups relies on threat intelligence that may be incomplete or contested.
Share
Evaluation Scores
Data Sources
Chainalysis Crypto Crime Report 2025
industry
Reliability: 88%
FBI Internet Crime Complaint Center Report 2024
government
Reliability: 91%
CISA Healthcare Sector Cybersecurity Assessment 2024
government
Reliability: 92%
