← Field Notes · Threats
Inside the Ransomware Economy
What began as a niche extortion tactic became a business model with suppliers, affiliates, and customer support.
On May 12, 2017, a piece of ransomware called WannaCry began spreading across the internet using a stolen and leaked National Security Agency exploit targeting a flaw in Microsoft Windows file-sharing. Within a day it had infected an estimated 200,000 computers across roughly 150 countries, disrupting Britain's National Health Service badly enough that some hospitals diverted ambulances and canceled surgeries. It was, at the time, one of the largest cyberattacks in history, and it demonstrated something the criminal underworld had suspected for years: encrypting a victim's files and demanding payment to unlock them scaled.
Six weeks later, a second worm, NotPetya, spread through a compromised software update for a Ukrainian tax-accounting program and went on to cause an estimated ten billion dollars in damage worldwide, hitting the shipping giant Maersk, the pharmaceutical company Merck, and the delivery service FedEx's European subsidiary hard enough that some of them spent months on recovery. NotPetya is widely believed by Western governments to have been a Russian state operation disguised as ransomware, but the disguise itself was telling: by 2017, ransomware had become a convincing enough cover story that state actors used it.
What followed was the professionalization of the crime. Ransomware-as-a-service platforms emerged, letting the people who write the encryption malware lease it to affiliates who handle the actual breach and deployment, splitting the ransom by an agreed percentage. Some groups run leak sites that publish stolen data from victims who refuse to pay, adding extortion on top of encryption. Others have published slickly written negotiation portals and, in more than one documented case, offered victims a discount for paying quickly, in language that reads uncomfortably close to a legitimate business's customer communications.
The 2021 attack on Colonial Pipeline, which briefly shut down the largest fuel pipeline in the United States and led to gas shortages across the Southeast, was carried out by an affiliate using ransomware built by a group called DarkSide, and it illustrated how the affiliate model diffuses responsibility: DarkSide's operators publicly claimed they had not intended to cause the disruption their software caused, a claim that is easier to make when the software's author and its operator are two different people with two different incentives.
None of this is solved by any single defensive tool, and no serious vendor should claim otherwise. But the ransomware economy's specific structure, small teams of developers, larger networks of affiliates, and widespread reuse of the same underlying encryption toolkits across many unrelated attacks, is exactly the pattern that makes maintained hash databases genuinely useful: the same ransomware binary, or a close variant of it, tends to show up again and again across victims who never had contact with each other, because the affiliate model runs on reuse.