The Economics of Cybercrime and Security
The Ransomware Business Model
How ransomware gangs lock victims' data and demand payment, why they operate like companies, and the debate over whether victims should pay.
Ransomware encrypts a victim’s files and demands payment, usually in cryptocurrency, to unlock them.
Double extortion
Many gangs also steal data and threaten to publish it unless paid, adding pressure.
Run like businesses
- Customer support to help victims pay.
- Affiliates who carry out attacks for a share of ransoms (Ransomware-as-a-Service).
- Negotiators and discounts for quick payment.
Famous attacks
- WannaCry (2017) hit hundreds of thousands of computers globally, including hospitals in the UK.
- Colonial Pipeline (2021) paid about 4.4 million dollars after an attack disrupted fuel supply on the US east coast.
Should victims pay?
- Paying may restore operations quickly.
- But it funds criminals and encourages more attacks, and there’s no guarantee data will be restored.
- Governments generally discourage payment; some consider banning it for public bodies.
The incentive problem
Each victim acting in its own interest by paying makes attacks more profitable for everyone, a negative externality.
A hospital's systems are locked. Paying the ransom may restore them faster and save patients, but it funds the gang to attack other hospitals.
Criminals may not restore data, and payment fuels more attacks.
- Ransomware encrypts files and demands payment.
- Gangs use double extortion and affiliate models.
- WannaCry and Colonial Pipeline were major attacks.
- Paying funds criminals, creating a negative externality.
No recording for this one yet - EconReader can read it aloud for you.