Close Menu
TechBrunchTechBrunch
  • Home
  • AI
  • Apps
  • Crypto
  • Security
  • Startups
  • TechCrunch
  • Venture

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

CISA confirms that hackers are actively taking advantage of the critical “Citrix Bleed 2” bug

July 11, 2025

Bitcoin surpasses $118K at the second highest high in 24 hours

July 11, 2025

AI chatbot's simple “123456” password was at risk of revealing personal data from millions of McDonald's job seekers

July 11, 2025
Facebook X (Twitter) Instagram
TechBrunchTechBrunch
  • Home
  • AI

    OpenAI seeks to extend human lifespans with the help of longevity startups

    January 17, 2025

    Farewell to the $200 million woolly mammoth and TikTok

    January 17, 2025

    Nord Security founder launches Nexos.ai to help enterprises move AI projects from pilot to production

    January 17, 2025

    Data proves it remains difficult for startups to raise capital, even though VCs invested $75 billion in the fourth quarter

    January 16, 2025

    Apple suspends AI notification summaries for news after generating false alerts

    January 16, 2025
  • Apps

    Belkin will no longer support most WEMO devices and their WEMO apps

    July 10, 2025

    Mockly has actually created a fake DM generator that is user-friendly

    July 10, 2025

    YouTube removes its trending pages and now trend list

    July 10, 2025

    As X loses CEO, daily use is decreasing and competition is growing

    July 10, 2025

    Google adds inter-image generation capabilities to VEO 3

    July 10, 2025
  • Crypto

    Bitcoin surpasses $118K at the second highest high in 24 hours

    July 11, 2025

    Vitalik Buterin reserves for Sam Altman's global project

    June 28, 2025

    Calci will close a $185 million round as rival Polymeruk reportedly seeks $200 million

    June 25, 2025

    Stablecoin Evangelist: Katie Haun's Battle of Digital Dollars

    June 22, 2025

    Hackers steal and destroy millions of Iran's biggest crypto exchanges

    June 18, 2025
  • Security

    CISA confirms that hackers are actively taking advantage of the critical “Citrix Bleed 2” bug

    July 11, 2025

    AI chatbot's simple “123456” password was at risk of revealing personal data from millions of McDonald's job seekers

    July 11, 2025

    French police arrest Russian basketball player accused of ransomware: Report

    July 10, 2025

    Authorities arrest four hackers related to UK retail hacking

    July 10, 2025

    Jack Dorsey says his “safe” new bitchat app hasn't been tested for security

    July 9, 2025
  • Startups

    7 days left: Founders and VCs save over $300 on all stage passes

    March 24, 2025

    AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

    March 24, 2025

    20 Hottest Open Source Startups of 2024

    March 22, 2025

    Andrill may build a weapons factory in the UK

    March 21, 2025

    Startup Weekly: Wiz bets paid off at M&A Rich Week

    March 21, 2025
  • TechCrunch

    OpenSea takes a long-term view with a focus on UX despite NFT sales remaining low

    February 8, 2024

    AI will save software companies' growth dreams

    February 8, 2024

    B2B and B2C are not about who buys, but how you sell

    February 5, 2024

    It's time for venture capital to break away from fast fashion

    February 3, 2024

    a16z's Chris Dixon believes it's time to focus on blockchain use cases rather than speculation

    February 2, 2024
  • Venture

    All stages in Boston and 4 days until lowest ticket prices disappear

    July 11, 2025

    Learn how to raise seed rounds from top VCS in 2025

    July 10, 2025

    Save up to $475 for 5 days to all stages before prices rise

    July 10, 2025

    David George on the Future to be released in 2025

    July 9, 2025

    Edo Liberty explores missed links for Enterprise AI in 2025

    July 9, 2025
TechBrunchTechBrunch

Why are ransomware gangs making so much money?

TechBrunchBy TechBrunchFebruary 17, 20246 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Telegram Email


for many organizations 2023 was a tough year economically, with some companies struggling to raise funds and cutting staff to survive. Meanwhile, ransomware and extortion gangs had a record year of revenue, according to recent reports.

If you look at the current state of ransomware, that's not surprising. Over the past year, hackers have continued to evolve their tactics to become more sneaky and extreme in an attempt to pressure victims into paying increasingly exorbitant ransom demands. This escalation of tactics, and the fact that governments stopped short of banning ransom payments, made 2023 the most lucrative year for ransomware gangs yet.

Multi-billion dollar cybercrime business

Known ransomware payouts will nearly double to more than $1 billion in 2023, according to new data from crypto forensics startup Chaineries, calling the year “the great ransomware comeback.”

This is the highest number ever observed and nearly doubles the amount of known ransom payments tracked in 2022. However, Chainalysis said the actual number is likely much higher than the $1.1 billion in ransom payments confirmed so far.

However, there is some positive news. While 2023 was a bumper year for ransomware gangs overall, other hacker watchers observed a decline in payouts towards the end of the year.

This decline is due to improved cyber defenses and resilience, as well as a growing sentiment that most victim organizations do not trust hackers to keep their promises or delete stolen data as claimed. This is the result. According to ransomware remediation company Coveware, “This has resulted in better victim guidance and reduced intangible guarantee payments.”

Record-breaking ransom

While a growing number of ransomware victims refuse to line the hackers' pockets, ransomware gangs are compensating for this loss in revenue by increasing the number of victims they target.

Try the MOVEit campaign. In this massive hack, the prolific Russia-linked Clop ransomware gang exploited a slew of never-before-seen vulnerabilities in the widely used MOVEit Transfer software, resulting in over 2,700 victim organizations being compromised. Data was stolen from the system. Many of the victims are known to have paid money to hacker groups to prevent the release of sensitive data.

It's impossible to know exactly how much the ransomware group benefited from this mass hack, but Chainalysis said in a report that Klopp's MOVEit campaign resulted in more than $100 million in ransom payments. It said it accounted for almost half of the total ransomware received in June and July. 2023 is the peak of this mass hacking.

MOVEit wasn't the only campaign that made money in 2023.

Casino entertainment giant Caesars paid hackers about $15 million in September to prevent them from releasing customer data stolen in an August cyberattack.

This multi-million dollar payout probably shows why ransomware attackers continue to make huge profits. While the attack on Caesars made little news, the subsequent attack on hotel giant MGM Resorts (which has cost the company $100 million to recover so far) dominated headlines for weeks. After MGM refused to pay the ransom, the hacker leaked his MGM customer's sensitive data, including his name, social security number, and passport details. Caesars appeared largely unscathed, at least on the surface, even if, by its own admission, it could not guarantee that the ransomware gang would delete the company's stolen data.

escalating threat

For many organizations like Caesars, paying the ransom demand seems like the easiest option to avoid a public relations nightmare. But as ransom money dries up, ransomware and extortion gangs are raising the amount, resorting to escalating tactics and extreme threats.

In December, for example, hackers reportedly tried to coerce a cancer hospital into paying a ransom demand by threatening to “smash” patients. Swatting incidents rely on malicious callers faking fake real-world life threats, prompting armed police response.

We also saw the notorious Alphv (also known as BlackCat) ransomware gang weaponize the US government's new data breach disclosure rules against MeridianLink, one of the gang's many victims. did. Alphv accused MeridianLink of what the gang called a “serious breach of customer data and business information” and for allegedly not disclosing what it claimed was the gang's accomplishments.

Payment of ransom is not prohibited

Another reason why ransomware continues to be profitable for hackers is that, although it is discouraged, there is nothing stopping organizations from paying unless hackers are sanctioned.

To pay or not to pay a ransom is a controversial topic. Ransomware remediation firm Coveware believes that if ransom payment bans are imposed in the U.S. and other hard-hit countries, companies will stop reporting these incidents to authorities, and existing relationships between victims and law enforcement will be strengthened. This suggests that the cooperative relationship is likely to be reversed. The company also predicts that if ransom payments are banned, a large illegal market will form overnight to facilitate ransomware payments.

But some believe an outright ban is the only way to ensure ransomware hackers can't continue lining their own pockets, at least in the short term.

Allan Liska, a threat intelligence analyst at Recorded Future, has long opposed bans on ransom payments, but now as long as ransom payments are legal, cybercriminals will use any means necessary to collect the money. I think we will take the following steps.

“I've resisted the idea of ​​a blanket ban on ransom payments for years, but I think that has to change,” Liska told TechCrunch. “Ransomware is getting worse, not just in terms of the number of attacks, but also the aggressiveness of the attacks and the groups behind them.”

“While banning ransom payments is painful and will likely lead to a short-term increase in ransomware attacks if history is any guide, it is the only way we can have long-term success on this issue. “The solution seems to be the “point,'' Liska said.

While more victims are realizing that paying hackers doesn't guarantee the safety of their data, it's clear that financially motivated cybercriminals aren't giving up their lavish lifestyles anytime soon. . Until then, ransomware attacks will continue to be a major money-making avenue for the hackers behind them.

Read more on TechCrunch:



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

CISA confirms that hackers are actively taking advantage of the critical “Citrix Bleed 2” bug

July 11, 2025

AI chatbot's simple “123456” password was at risk of revealing personal data from millions of McDonald's job seekers

July 11, 2025

French police arrest Russian basketball player accused of ransomware: Report

July 10, 2025

Authorities arrest four hackers related to UK retail hacking

July 10, 2025

Jack Dorsey says his “safe” new bitchat app hasn't been tested for security

July 9, 2025

Get the exhibition tables on TechCrunch Confuse 2025

July 9, 2025

Leave A Reply Cancel Reply

Top Reviews
Editors Picks

7 days left: Founders and VCs save over $300 on all stage passes

March 24, 2025

AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

March 24, 2025

20 Hottest Open Source Startups of 2024

March 22, 2025

Andrill may build a weapons factory in the UK

March 21, 2025
About Us
About Us

Welcome to Tech Brunch, your go-to destination for cutting-edge insights, news, and analysis in the fields of Artificial Intelligence (AI), Cryptocurrency, Technology, and Startups. At Tech Brunch, we are passionate about exploring the latest trends, innovations, and developments shaping the future of these dynamic industries.

Our Picks

CISA confirms that hackers are actively taking advantage of the critical “Citrix Bleed 2” bug

July 11, 2025

Bitcoin surpasses $118K at the second highest high in 24 hours

July 11, 2025

AI chatbot's simple “123456” password was at risk of revealing personal data from millions of McDonald's job seekers

July 11, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

© 2025 TechBrunch. Designed by TechBrunch.
  • Home
  • About Tech Brunch
  • Advertise with Tech Brunch
  • Contact us
  • DMCA Notice
  • Privacy Policy
  • Terms of Use

Type above and press Enter to search. Press Esc to cancel.