London Daily

Focus on the big picture.
Sunday, Dec 21, 2025

Ransomware criminals' demands rise as aggressive tactics pay off

Ransomware criminals' demands rise as aggressive tactics pay off

Average ransomware demands and payments are up as criminal enterprises pour money into the profitable operations

Ransomware gangs are getting greedier as aggressive tactics pay off.

The ransomware crisis just keeps getting worse as criminal enterprises pour money into highly profitable ransomware operations, according to a report from Palo Alto Networks’ Unit 42 security consulting group.

The average ransomware payment climbed 82% to a record $570,000 in the first half of 2021 from $312,000 in 2020.


And criminal gangs are upping demands. The average ransom demand so far this year is $5.3 million, surging 518% from 2020 when the average demand was $847,000. That’s because too often it works.

"Ransomware attacks have prevented us from accessing work computers, pushed up meat prices, led to gasoline shortages, shut down schools, delayed legal cases, prevented some of us from getting our cars inspected and caused some hospitals to turn away patients," the report said.

For a single victim, the largest ransom demand seen by Unit 42 consultants rose to $50 million in the first half of 2021 from $30 million last year.

Ransomware gangs are getting greedier as aggressive tactics pay off.


Larger demands and ransoms mean gangs are getting creative, as the July Kaseya VSA attack shows.

REvil, a notorious ransomware-as-a-service criminal business enterprise, offered a "universal decryption key" to all of the organizations hit by the attack in return for a $70 million payment.

"Though it quickly dropped the asking price to $50 million. Kaseya eventually obtained a universal decryption key, but it’s unclear what payment was made, if any," Unit 42 said.

This year, the largest confirmed payment was the $11 million that JBS SA said it paid after an attack in June.

Quadruple extortion


The rise of "quadruple extortion" is one of the most ominous trends, said Unit 42, whose consultants handled "dozens" of ransomware cases in the first half of 2021.

"While it’s rare for one organization to be the victim of all four techniques, this year we have increasingly seen ransomware gangs engage in additional approaches when victims don’t pay up after encryption and data theft," Unit 42 said.

These four tactics are:

Encryption:


Victims pay to regain access to computer systems after key files get encrypted. This is classic ransomware.

Data theft:


Hackers release sensitive information if a ransom is not paid. This tactic took hold in 2020.

Denial of service (DoS):


Ransomware gangs launch denial of service attacks that bring down a victim’s public websites.

Harassment:


"Cybercriminals contact customers, business partners, employees and media to tell them the organization was hacked," the report said.

And as ransomware enterprises mature, the sophistication of attacks grows.

For instance, Unit 42 is starting to see ransomware gangs target a type of software known as a hypervisor.

Also expect to see more targeting of so-called managed service providers (MSPs) and their customers after the Kaseya attack, which spread to clients of MSPs, Unit 42 said.

Some gangs, however, will continue to focus on the "low end of the market...regularly targeting small businesses that lack resources to invest heavily in cybersecurity," the report said. Those ransom payments typically range from $10,000 to $50,000.

Newsletter

Related Articles

0:00
0:00
Close
UK Fashion Label LK Bennett Pursues Accelerated Sale Amid Financial Struggles
U.S. Government Warns UK Over Free Speech in Pro-Life Campaigner Prosecution
Newly Released Files Shed Light on Jeffrey Epstein’s Extensive Links to the United Kingdom
Prince William and Prince George Volunteer Together at UK Homelessness Charity
UK Police Arrest Protesters Chanting ‘Globalise the Intifada’ as Authorities Recalibrate Free Speech Enforcement
Scambodia: The World Owes Thailand’s Military a Profound Debt of Gratitude
Women in Partial Nudity — and Bill Clinton in a Dress and Heels: The Images Revealed in the “Epstein Files”
US Envoy Witkoff to Convene Security Advisers from Ukraine, UK, France and Germany in Miami as Peace Efforts Intensify
UK Retailers Report Sharp Pre-Christmas Sales Decline and Weak Outlook, CBI Survey Shows
UK Government Rejects Use of Frozen Russian Assets to Fund Aid for Ukraine
UK Financial Conduct Authority Opens Formal Investigation into WH Smith After Accounting Errors
UK Issues Final Ultimatum to Roman Abramovich Over £2.5bn Chelsea Sale Funds for Ukraine
Rare Pink Fog Sweeps Across Parts of the UK as Met Office Warns of Poor Visibility
UK Police Pledge ‘More Assertive’ Enforcement to Tackle Antisemitism at Protests
UK Police Warn They Will Arrest Protesters Chanting ‘Globalise the Intifada’
Trump Files $10 Billion Defamation Lawsuit Against BBC as Broadcaster Pledges Legal Defence
UK Says U.S. Tech Deal Talks Still Active Despite Washington’s Suspension of Prosperity Pact
UK Mortgage Rules to Give Greater Flexibility to Borrowers With Irregular Incomes
UK Treasury Moves to Position Britain as Leading Global Hub for Crypto Firms
U.S. Freezes £31 Billion Tech Prosperity Deal With Britain Amid Trade Dispute
Prince Harry and Meghan’s Potential UK Return Gains New Momentum Amid Security Review and Royal Dialogue
Zelensky Opens High-Stakes Peace Talks in Berlin with Trump Envoy and European Leaders
Historical Reflections on Press Freedom Emerge Amid Debate Over Trump’s Media Policies
UK Boosts Protection for Jewish Communities After Sydney Hanukkah Attack
UK Government Declines to Comment After ICC Prosecutor Alleges Britain Threatened to Defund Court Over Israel Arrest Warrant
Apple Shutters All Retail Stores in the United Kingdom Under New National COVID-19 Lockdown
US–UK Technology Partnership Strains as Key Trade Disagreements Emerge
UK Police Confirm No Further Action Over Allegation That Andrew Asked Bodyguard to Investigate Virginia Giuffre
Giuffre Family Expresses Deep Disappointment as UK Police Decline New Inquiry Into Andrew Mountbatten-Windsor Claims
Transatlantic Trade Ambitions Hit a Snag as UK–US Deal Faces Emerging Challenges
Ex-ICC Prosecutor Alleges UK Threatened to Withdraw Funding Over Netanyahu Arrest Warrant Bid
UK Disciplinary Tribunal Clears Carter-Ruck Lawyer of Misconduct in OneCoin Case
‘Pink Ladies’ Emerge as Prominent Face of UK Anti-Immigration Protests
Nigel Farage Says Reform UK Has Become Britain’s Largest Party as Labour Membership Falls Sharply
Google DeepMind and UK Government Launch First Automated AI Lab to Accelerate Scientific Discovery
UK Economy Falters Ahead of Budget as Growth Contracts and Confidence Wanes
Australia Approves Increased Foreign Stake in Strategic Defence Shipbuilder
Former UK Prime Minister Boris Johnson proclaims, “For Ukraine, surrendering their land would be a nightmare.”
Microsoft Challenges £2.1 Billion UK Cloud Licensing Lawsuit at Competition Tribunal
Fake Doctor in Uttar Pradesh Accused of Killing Woman After Performing YouTube-Based Surgery
Hackers Are Hiding Malware in Open-Source Tools and IDE Extensions
Traveling to USA? Homeland Security moving toward requiring foreign travelers to share social media history
UK Officials Push Back at Trump Saying European Leaders ‘Talk Too Much’ About Ukraine
UK Warns of Escalating Cyber Assault Linked to Putin’s State-Backed Operations
UK Consumer Spending Falters in November as Households Hold Back Ahead of Budget
UK Orders Fresh Review of Prince Harry’s Security Status After Formal Request
U.S. Authorises Nvidia to Sell H200 AI Chips to China Under Security Controls
Trump in Direct Assault: European Leaders Are Weak, Immigration a Disaster. Russia Is Strong and Big — and Will Win
"App recommendation" or disguised advertisement? ChatGPT Premium users are furious
"The Great Filtering": Australia Blocks Hundreds of Thousands of Minors From Social Networks
×