Cybersecurity

Ransomware-as-a-Service: How Cybercrime Franchised and What It Costs

Not long ago, ransomware was the work of lone attackers or small crews: opportunistic infections, noisy Bitcoin demands, and sometimes no way to decrypt even if a victim paid. Today it is a professional industry with division of labour, affiliate networks, customer support, and even public-relations arms. The transformation has a name: ransomware-as-a-service, or RaaS. And it has reshaped both cybercrime and corporate defence.

How the Franchise Model Works

Under RaaS, a core group of developers builds and maintains the ransomware itself — the malware that encrypts a victim’s files and the infrastructure to manage extortion. Instead of deploying it themselves, they “license” it to affiliates. The affiliate is responsible for actually breaching organisations: finding targets, exploiting vulnerabilities, buying stolen credentials, and deploying the ransomware. When a victim pays, the proceeds are split, typically 70-80% to the affiliate and 20-30% to the developer, though split varies.

This division of labour is intentional and efficient. Developers get scale, specialised marketing, and a cut of many victims without doing the risky work of gaining access. Affiliates get a working, battle-tested product without needing to build it. The model mirrors legitimate software franchising — and some RaaS operations even offer SLAs, documentation, and technical support.

Double Extortion

A second change amplified the damage. Modern ransomware groups typically deploy “double extortion”: they first encrypt data, then also exfiltrate it and threaten to publish it if the ransom is not paid. This means victims cannot rely solely on backups — even if they can restore systems, they face the reputational and regulatory consequences of a data breach. Some groups have added “triple extortion,” pressuring customers, partners, or patients of the victim, or launching distributed denial-of-service attacks to force payment.

The Numbers

According to Chainalysis, ransomware payments tracked on-chain peaked in 2021 at around $983 million, then fell in 2022 and 2023 as some victims refused to pay and law enforcement tightened pressure. The 2023 figure was approximately $1.1 billion, and 2024 saw a notable decline to roughly $813 million, even as attack frequency remained high. The drop reflected several factors: improved incident response, better backups, law enforcement disruption, and growing reluctance to fund criminals — though the numbers are minima, since they only capture payments visible on-chain.

The true economic cost is far higher. Downtime, recovery, legal fees, notification costs, regulatory fines, lost business, and rising cyber insurance premiums vastly exceed ransom payments. Estimates of total ransomware damages run into the tens of billions of dollars annually.

Who Are the Actors?

Several groups dominate the RaaS landscape. LockBit was for a time the most prolific, responsible for a large share of published attacks, before a series of law enforcement operations in 2024 disrupted its infrastructure and arrested alleged operators. ALPHV (BlackCat) was another major player, known for targeting healthcare. Cl0p exploited a series of zero-day vulnerabilities in file-transfer products, including the 2023 MOVEit campaign that affected thousands of organisations and tens of millions of individuals worldwide.

Many of these groups operate with impunity from jurisdictions where extradition is difficult, notably Russia. Some have loose ties to state interests; others operate as purely criminal enterprises. Attribution is hard, and disruption is often temporary — groups rebrand, rebuild, and resume operations.

Who Gets Hit

No sector is immune, but several are disproportionately targeted. Healthcare has suffered intensely, with hospitals forced to divert patients and delay care. In 2024, the Change Healthcare incident — attributed to ALPHV — disrupted claims processing across the U.S. healthcare system for weeks, affecting providers and patients nationwide. Education, local government, manufacturing, and critical infrastructure are also frequent targets.

Small and mid-sized organisations are disproportionately hit, because they often lack the defences of large enterprises but still have money and data. The multi-million-dollar ransoms that make headlines are the exception; most attacks demand amounts in the tens of thousands to low hundreds of thousands of dollars — calibrated to what the victim can pay.

The Policy Response

The international response has evolved. The U.S. created a counter-ransomware task force and, in 2023, convened the International Counter Ransomware Initiative, a coalition of dozens of countries. Law enforcement has shifted from purely reactive investigation to proactive disruption — seizing infrastructure, doxxing operators, and indicting individuals. In 2024, “Operation Cronos,” led by the UK and supported by partners, seized LockBit’s infrastructure and published extensive internal data, dealing the group a significant blow.

Policy debates continue over whether to ban ransom payments. Proponents argue a ban would eliminate the incentive; opponents argue it would harm victims, drive payments underground, and punish organisations with no alternative. Several countries have restricted payments to sanctioned entities, and insurers increasingly require robust security controls as a condition of coverage.

What Organisations Can Do

The defence playbook is reasonably well understood: offline, tested backups (the most reliable mitigation); multifactor authentication; patching and vulnerability management; network segmentation; least-privilege access; endpoint detection and response; and an incident response plan. Cyber insurance, once an afterthought, has become a standard part of risk management, though it is increasingly expensive and conditional.

Supply Chain and Patching Vulnerability

Ransomware does not only hit directly. Increasingly, attackers target managed service providers and software vendors, whose compromise gives them access to hundreds of downstream clients. The 2021 Kaseya VSA incident, in which REvil exploited a vulnerability in a widely used IT management tool, affected more than a thousand businesses at once. The lesson is stark: your security posture is only as strong as the weakest vendor you depend on, and a single third-party failure can propagate quickly. Supply chain risk management has therefore become a standard part of enterprise security programmes, though one that is easier to mandate than to execute.

Cyber Insurance’s Evolving Role

The cyber insurance market has matured dramatically in response to ransomware. Premiums rose sharply in 2021-2022 before stabilising, and insurers increasingly require specific security controls as a condition of coverage: multifactor authentication, endpoint detection, offline backups, and incident-response retainers. Some policies now require the insured to exhaust other options — including law enforcement engagement and negotiation guidance from specialist firms — before paying a ransom, or they exclude ransom payments entirely. This shift has made insurance a driver of better security practices, not merely a financial backstop. For organisations that cannot get coverage — or cannot afford it — the exposure gap is growing.

Notification, Reputation, and the Legal Fallout

A ransomware incident triggers a cascade of obligations. In Canada, mandatory breach notification applies under PIPEDA and provincial laws when the breach poses real risk of significant harm. In the U.S., dozens of state laws, sectoral regulations, and the SEC’s cybersecurity disclosure rule (effective 2023) require notification. The regulatory and reputational cost of a breach often exceeds the ransom itself, particularly when the attack involves personal or health data. Lawsuits — including class actions and derivative shareholder suits — are common after major incidents, alleging inadequate disclosure or cybersecurity governance failures.

Disruption vs Deterrence

Law enforcement’s approach has shifted from investigation to disruption. Operations like Cronos (against LockBit) and the takedowns of ALPHV infrastructure represent a more aggressive posture. Seizures, indictments, and sanctions make life harder for attackers — but they rarely end the threat. Groups rebrand, rebuild, and rehire. Attackers in non-extradition jurisdictions face limited personal risk. Deterrence through prosecution is difficult when most perpetrators cannot be reached. The more realistic goal is to raise the cost and friction of operating, making ransomware less profitable and more exhausting.

The Ransomware Diplomacy Dimension

Because ransomware groups operate across borders with state tacitly facilitating their existence, the problem has become a diplomatic one. The International Counter Ransomware Initiative has expanded to dozens of countries, and bilateral pressure is applied on governments that harbour cybercriminals to increase enforcement. Results are mixed. Russia’s government occasionally arrests high-profile criminals, but only when politically useful. North Korea’s state-directed ransomware operation (notably the Lazarus Group) is largely insulated from diplomatic pressure. The international response is a patchwork, not a cohesive framework, and the safe havens persist.

Geopolitics of the Ransomware Economy

Ransomware is inseparable from geopolitics. The overwhelming majority of high-profile groups operate from Russia and adjacent jurisdictions, where they enjoy substantial tolerance as long as their depredations fall on foreign victims. Cryptographic payments flow through exchanges and mixers, some of which are themselves sanctioned or targeted by authorities. The U.S. Treasury has sanctioned ransomware-linked exchanges, and the disruption of programs like Hydra and Garantex has complicated the money laundering pipeline. But the fundamental dynamic — criminals shielded by state tolerance, victims spread globally, and payments crossing borders instantly — makes ransomware a problem that cannot be solved by any single country’s law enforcement. It requires sustained international cooperation, and such cooperation is intermittent at best.

Conclusion

Ransomware-as-a-service has professionalised extortion, lowering the barriers to entry and multiplying the pool of attackers. The result is a persistent, adaptive threat that targets the most vulnerable and disrupts critical services. The fight against it is partly technical — better defences, better backups — and partly structural: disrupting the payment flows, the infrastructure, and the safe havens that make the model profitable. Both fronts are active, and neither is close to winning decisively. For now, the dominant reality is that ransomware remains the single most disruptive cyber threat most organisations face, and preparation is the difference between inconvenience and catastrophe.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button