Crime as a Subscription Service: The Ransomware Economy That Is Costing America Billions
Photo: ransomware cyber attack computer lock screen hacker dark, via as2.ftcdn.net
Imagine leasing a fully operational criminal enterprise for a percentage of the proceeds — no upfront infrastructure costs, no need to write a single line of code, and a dedicated support team standing by to help you negotiate with your victims. It sounds like a dark parody of Silicon Valley's subscription economy. It is, in fact, a precise description of how a significant portion of ransomware attacks against American businesses and institutions are organized today.
The model is called Ransomware-as-a-Service, or RaaS, and its emergence represents one of the most consequential structural shifts in the history of cybercrime. What began as a cottage industry of individual hackers has matured into a layered, hierarchical ecosystem — one that security researchers at firms like Mandiant, CrowdStrike, and Recorded Future now describe in the same organizational language used to analyze Fortune 500 companies.
From Solo Operator to Criminal Franchise
The earliest ransomware attacks, dating back to the late 1980s and resurging in the early 2010s, were largely the work of individual actors or small, tightly knit groups. They wrote their own malware, identified their own targets, and handled their own ransom collections — a vertically integrated operation that was labor-intensive and limited in scale.
The RaaS model disaggregated those functions. Today, a typical operation is divided between core developers — who build and maintain the malware, the encryption algorithms, and the victim-facing payment portals — and affiliates, who license access to that infrastructure in exchange for surrendering a percentage of every ransom collected, typically between 20 and 30 percent. The developers function as silent franchisor; the affiliates do the dirty work of breaching networks and deploying the payload.
This division of labor has had a predictable effect on scale. Because affiliates need no technical expertise beyond the ability to purchase access to compromised networks — a commodity sold openly in criminal marketplaces — the pool of potential attackers has expanded dramatically. A criminal who lacks the skill to write malware but possesses the social engineering ability to compromise a corporate VPN credential can, in theory, become a ransomware operator within days.
The Organizational Chart of a RaaS Operation
The internal structure of mature RaaS groups bears a striking resemblance to a legitimate technology company, a fact that has not been lost on the security researchers who have reverse-engineered their internal communications following law enforcement seizures.
At the top sits the core development team, responsible for maintaining the malware and updating it to evade detection by antivirus software and endpoint security platforms. Below them, dedicated negotiation specialists handle communications with victims — often working in multiple languages, maintaining a professional tone, and even offering "discounts" to organizations that pay quickly. Separate teams manage cryptocurrency laundering, converting ransom payments into cash through a series of mixing services, privacy coins, and over-the-counter brokers in jurisdictions with limited regulatory oversight.
When the Conti ransomware group's internal chat logs were leaked in February 2022 — by a Ukrainian researcher retaliating against the group's public support for Russia's invasion — the files revealed an organization with dedicated HR functions, salary disputes, performance reviews, and debates about vacation policy. Conti, at its peak, was believed to have extorted more than $180 million from victims in a single year, including attacks on Ireland's national health service and multiple US school districts.
Notable Operations: Rise and Fall
The RaaS landscape has been defined by a succession of dominant groups, many of which have been disrupted, rebranded, or splintered following law enforcement action.
REvil, also known as Sodinokibi, was responsible for two of the most disruptive attacks in recent American history: the May 2021 assault on JBS Foods, the world's largest meat processor, which resulted in a $11 million ransom payment, and the July 2021 attack on Kaseya VSA, which cascaded through managed service providers to affect an estimated 1,500 businesses simultaneously. Following intense pressure from the Biden administration on the Russian government, REvil's infrastructure went dark in July 2021. Several alleged members were subsequently arrested in Russia in early 2022, though the prosecutions stalled after the Ukraine invasion.
DarkSide achieved notoriety in May 2021 when its affiliate-executed attack on Colonial Pipeline forced the temporary shutdown of a fuel distribution system serving much of the US East Coast and triggered panic buying at gas stations from Georgia to New Jersey. The company paid a $4.4 million ransom. The Department of Justice subsequently recovered approximately $2.3 million of that payment by seizing the private key to a Bitcoin wallet — a landmark operation that demonstrated law enforcement's growing capability to claw back cryptocurrency ransoms.
LockBit, which emerged as arguably the most prolific RaaS operation of the mid-2020s, was the subject of a sweeping international takedown in February 2024. Operation Cronos, coordinated by the UK's National Crime Agency, the FBI, Europol, and law enforcement agencies across nine countries, seized LockBit's infrastructure, arrested multiple alleged members, and — in a pointed act of psychological warfare — repurposed the group's own leak site to publish information about the operation and its administrators.
The Economics of Extortion
Understanding why RaaS has proven so durable requires understanding the economic logic that sustains it. Ransom demands are not arbitrary; they are calibrated. Groups routinely conduct what amounts to financial due diligence on their victims — examining stolen financial documents, insurance policies, and revenue figures to set a demand that is painful enough to motivate payment but not so large that it forces the victim into bankruptcy or guarantees a refusal.
Cyber insurance has, paradoxically, contributed to the problem. As more organizations purchased coverage that included ransomware payments, attackers began specifically targeting policyholders, confident that an insurance company's rational calculus — pay the ransom versus absorb the cost of extended downtime — would facilitate payment. Several major insurers have since moved to limit or exclude ransomware coverage, and the insurance industry is increasingly coordinating with law enforcement on payment disclosures.
The US government has taken a harder line on payments as well. The Treasury Department's Office of Foreign Assets Control has warned that ransom payments to sanctioned entities — including several RaaS groups — may expose paying organizations to civil penalties, a development that has complicated the decision-making of corporate legal teams and incident response firms.
How the Defense Is Evolving
Law enforcement's approach to RaaS has matured considerably beyond the seizure of servers and the occasional arrest. The FBI and the Cybersecurity and Infrastructure Security Agency now routinely publish joint advisories detailing the tactics, techniques, and procedures of active RaaS groups, giving defenders actionable intelligence in near real time. The FBI's Internet Crime Complaint Center maintains a ransomware reporting portal that feeds into broader attribution efforts.
Private sector threat intelligence firms have proven equally consequential. Mandiant's attribution of UNC groups, CrowdStrike's naming conventions for adversary clusters, and Recorded Future's dark web monitoring have collectively built a body of knowledge that enables faster attribution, sanctions designations, and prosecutorial support.
Perhaps most importantly, the security community has invested in decryption tools. The No More Ransom project, a public-private partnership involving Europol, the Dutch National Police, and dozens of cybersecurity companies, has made free decryption keys available for hundreds of ransomware variants — allowing victims to recover their data without paying a cent to their attackers.
What Organizations Can Do
For American businesses and institutions, the RaaS threat landscape demands a posture of assumed breach. The question is no longer whether an organization might be targeted, but how quickly it can detect, contain, and recover from an intrusion.
Immutable, offline backups remain the single most effective countermeasure against ransomware. Network segmentation limits the blast radius of a successful deployment. Multi-factor authentication on all remote access points — particularly VPNs and remote desktop services — closes the most commonly exploited entry vectors. And regular tabletop exercises, in which leadership teams simulate a ransomware incident, build the organizational muscle memory that determines whether a company pays millions or recovers in hours.
The franchise model of cybercrime is unlikely to disappear. But it is not invincible. Every takedown, every recovered key, and every arrested affiliate chips away at the ecosystem's credibility with potential recruits. In the end, RaaS is a business — and like any business, it depends on a reliable return on investment. Raising the cost and lowering the reward of ransomware attacks is the strategic logic that drives every element of the defense.