London Daily

Focus on the big picture.
Thursday, Feb 26, 2026

Ransomware criminals' demands rise as aggressive tactics pay off

Ransomware criminals' demands rise as aggressive tactics pay off

Average ransomware demands and payments are up as criminal enterprises pour money into the profitable operations

Ransomware gangs are getting greedier as aggressive tactics pay off.

The ransomware crisis just keeps getting worse as criminal enterprises pour money into highly profitable ransomware operations, according to a report from Palo Alto Networks’ Unit 42 security consulting group.

The average ransomware payment climbed 82% to a record $570,000 in the first half of 2021 from $312,000 in 2020.


And criminal gangs are upping demands. The average ransom demand so far this year is $5.3 million, surging 518% from 2020 when the average demand was $847,000. That’s because too often it works.

"Ransomware attacks have prevented us from accessing work computers, pushed up meat prices, led to gasoline shortages, shut down schools, delayed legal cases, prevented some of us from getting our cars inspected and caused some hospitals to turn away patients," the report said.

For a single victim, the largest ransom demand seen by Unit 42 consultants rose to $50 million in the first half of 2021 from $30 million last year.

Ransomware gangs are getting greedier as aggressive tactics pay off.


Larger demands and ransoms mean gangs are getting creative, as the July Kaseya VSA attack shows.

REvil, a notorious ransomware-as-a-service criminal business enterprise, offered a "universal decryption key" to all of the organizations hit by the attack in return for a $70 million payment.

"Though it quickly dropped the asking price to $50 million. Kaseya eventually obtained a universal decryption key, but it’s unclear what payment was made, if any," Unit 42 said.

This year, the largest confirmed payment was the $11 million that JBS SA said it paid after an attack in June.

Quadruple extortion


The rise of "quadruple extortion" is one of the most ominous trends, said Unit 42, whose consultants handled "dozens" of ransomware cases in the first half of 2021.

"While it’s rare for one organization to be the victim of all four techniques, this year we have increasingly seen ransomware gangs engage in additional approaches when victims don’t pay up after encryption and data theft," Unit 42 said.

These four tactics are:

Encryption:


Victims pay to regain access to computer systems after key files get encrypted. This is classic ransomware.

Data theft:


Hackers release sensitive information if a ransom is not paid. This tactic took hold in 2020.

Denial of service (DoS):


Ransomware gangs launch denial of service attacks that bring down a victim’s public websites.

Harassment:


"Cybercriminals contact customers, business partners, employees and media to tell them the organization was hacked," the report said.

And as ransomware enterprises mature, the sophistication of attacks grows.

For instance, Unit 42 is starting to see ransomware gangs target a type of software known as a hypervisor.

Also expect to see more targeting of so-called managed service providers (MSPs) and their customers after the Kaseya attack, which spread to clients of MSPs, Unit 42 said.

Some gangs, however, will continue to focus on the "low end of the market...regularly targeting small businesses that lack resources to invest heavily in cybersecurity," the report said. Those ransom payments typically range from $10,000 to $50,000.

Newsletter

Related Articles

0:00
0:00
Close
US Lawmakers Seek Briefing from UK Over Reported Encryption Order Directed at Apple
UK Business Secretary Calls on EU to Remove Trade Barriers Hindering Growth
Legal Pathways for Removing Prince Andrew from Britain’s Line of Succession Examined
PM Netanyahu welcome India PM Narendra Modi to Israel
Shadow Diplomacy: How Harry and Meghan’s Jordan Trip Undermines the Monarchy
Sir Jim Ratcliffe, co-owner of Manchester United, comments on immigration in the UK.
Bill Gates, the UN and the WEF are attempting to construct "a giant digital gulag for all of humanity" via digital ID, CBDCs and vaccine passport infrastructure.
Britain’s Channel Crisis: Paying Billions While the Boats Keep Coming
Downing Street’s Veteran Deception Scandal
UK HealthCare Expands ‘Food as Health’ Initiative Statewide to Tackle Chronic Illness in Kentucky
Leonardo Chief Says UK Set to Decide on New Medium Helicopter Programme
UK Slows Chagos Islands Agreement After Concerns Raised in Washington
European and UK Stock Markets Reach Fresh Highs as Banks and Miners Lead Rally
UK Government Insists Chagos Islands Negotiations Continue After Minister’s ‘Pause’ Remark
No Confirmed Deal for Engie to Acquire UK Power Networks Amid Market Speculation
UK Reaffirms Updated Entry Requirements for Travellers as of February 25, 2026
General Atlantic to sell equity stake in ByteDance, valuing the company at $550 billion
German Chancellor Friedrich Merz Secures Pledge from China for Greater Imports of Quality Goods
Lord Mandelson Condemns Arrest as Driven by ‘Baseless Suggestion’ He Would Flee Abroad
Former UK Ambassador Released on Bail Following Arrest in Epstein-Linked Investigation
UK Parliament Orders Release of Former Prince Andrew’s Government Vetting Files
Reddit Fined £14 Million by UK Regulator Over Failures in Age Verification Controls
UK Moves to Tighten Regulation of Netflix, Disney+ and Prime Video Under New Media Rules
British Woman Who Reported Rape in Hong Kong Faces Possible Prosecution
'Christianity is the religion that has made this country great.'
Man Receives Parking Ticket 38 Years After Offense: ‘City Officials Said It’s Legitimate’
Woman Receives Gift Card for Christmas – Discovers It Is ‘Worth’ 63,000,000,000,000,000 Pounds
UK Sanctions New Zealand Insurer Maritime Mutual Following Allegations Over Russian Oil Cover
Reform MP Danny Kruger Condemns UK’s ‘Unregulated Sexual Economy’ in Call for Tougher Controls
The Show Must Go On: Prince William and Kate Middleton Shine at the BAFTAs Amid Andrew’s Arrest
UK Sanctions Russian ‘Illicit Oil Traders’ After Email Blunder Exposes Sanctions Evasion Network
Russia Amplifies Baseless Claims That UK and France Plan to Arm Ukraine with Nuclear Weapons
UK Imposes Sanctions on Two Georgian Television Channels Over Alleged Russian Disinformation
United States National Parks See Noticeable Drop in Visitors from Canada, U.K. and Australia
UK, Australia, Canada and New Zealand Escalate Sanctions on Russia as Ukraine War Marks Four Years
I Gave Andrew a Nude Massage Inside Buckingham Palace
UK Economy Faces Acute Strain as Trump’s Global Tariff Reshapes Trade Landscape
UK Signals Retaliation Is Possible as New US Tariff Policy Threatens Trade Stability
British Police Arrest Former Ambassador Peter Mandelson in Epstein-Related Misconduct Probe
Australia Officially Supports Proposal to Remove Andrew Mountbatten-Windsor from Royal Succession
Victorian Premier Jacinta Allan remains silent on ISIS brides' resettlement plans in Melbourne
Former UK Ambassador Peter Mandelson Arrested in Connection with Jeffrey Epstein
Jacob Rees Mogg afraid to talk about Peter Mandelson arrest on “suspicion of misconduct in a public office” (Pedophilia, corruption, etc.)
United Nations Calls for Global Action Against Disinformation and Hate Speech Online
Tucker Carlson warns of an inevitable clash in Western societies over mass migration
President Trump warns countries against abandoning recent trade deals with the US
Diverging Polls Show Mixed Signals on UK Economic Revival as Confidence Remains Fragile
Spotify Expands AI-Driven ‘Prompted Playlists’ Feature to the United Kingdom and Other Markets
Greens and Reform UK Surge in Manchester By-Election, Threatening Labour’s Historic Stronghold
UK Businesses Push for Closer European Trade Links Amid Renewed US Tariff Uncertainty
×