Ransomware attacks reap over $1 billion in watershed year for criminals
Last year has been described as a watershed for ransomware attacks as a new report warns cyber-criminals are “big game hunting”.
Blockchain specialists Chainalysis issued its report into the threats and scale of ransomware in which it warned 2023 saw ransomware actors intensify their operations, targeting high-profile institutions and critical infrastructure, including hospitals, schools, and government agencies.
“2023 marks a major comeback for ransomware, with record-breaking payments and a substantial increase in the scope and complexity of attacks — a significant reversal from the decline observed in 2022, which we forewarned in our Mid-Year Crime Update,” the company said.
The report found ransomware payments in 2023 surpassed the $1 billion mark, the highest number ever observed.
“Although 2022 saw a decline in ransomware payment volume, the overall trend line from 2019 to 2023 indicates that ransomware is an escalating problem,” it stated. “Keep in mind that this number does not capture the economic impact of productivity loss and repair costs associated with attacks.”
It added while entertainment giant MGM did not pay the ransom in its well reported attack, estimated damages cost the business over $100 million.
“The ransomware landscape is not only prolific but continually expanding, making it challenging to monitor every incident or trace all ransom payments made in cryptocurrencies,” the report continued. “It is important to recognise that our figures are conservative estimates, likely to increase as new ransomware addresses are discovered over time.
“For instance, our initial reporting for 2022 in last year’s crime report showed $457 million in ransoms, but this figure has since been revised upward by 24.1%.”
Chainalysis said last year ransomware attacks were carried out by a variety of actors, from large syndicates to smaller groups and individuals — and experts say their numbers are increasing.
The report cited Allan Liska, threat intelligence analyst at cybersecurity firm Recorded Future, who said: “A major thing we’re seeing is the astronomical growth in the number of threat actors carrying out ransomware attacks.” Recorded Future reported 538 new ransomware variants in 2023, pointing to the rise of new, independent groups.
“Overall, big game hunting has become the dominant strategy over the last few years, with a bigger and bigger share of all ransomware payment volume being made up of payments of $1 million or more,” the report explained.
The report warned the growth of initial access brokers (IABs) has made it easier for bad actors to carry out ransomware attacks.
“As their name would suggest, IABs penetrate the networks of potential victims, then sell that access to ransomware attackers for as little as a few hundred dollars,” Chainalysis added. “We found a correlation between inflows to IAB wallets and an upsurge in ransomware payments, suggesting monitoring IABs could provide early warning signs and allow for potential intervention and mitigation of attacks.
“IABs combined with off-the-shelf RaaS (ransomware as a service), means that much less technical skill is required to carry out a successful ransomware attack.
The report concluded: “The ransomware landscape underwent significant changes in 2023, marked by shifts in tactics and affiliations among threat actors, as well as the continued spread of RaaS strains and swifter attack execution, demonstrating a more efficient and aggressive approach.
“The movement of affiliates highlighted the fluidity within the ransomware underworld and the constant search for more lucrative extortion schemes.
Threat actors continue to innovate and adapt to regulatory changes and law enforcement actions, but 2023 also saw significant victories in the fight against ransomware with collaboration between international law enforcement, affected organisations, cybersecurity firms, and blockchain intelligence.”








