Ransomware Payments Fell by 35% in 2024
A recent report from the blockchain analytics firm Chainalysis has revealed ransomware attacks are becoming less profitable. 2024 saw a considerable reduction in payments to ransomware groups, which fell by 35% year-over-year to the second-lowest annual total in the past 5 years. In 2023, $1.25 billion was paid in ransom payments to obtain decryption keys and prevent the publication of stolen data. The total fell to $814 million in 2024.
The analysis of the first half of 2024 suggested the 2023 total would be beaten in 2024; however, the second half of the year saw greater reluctance to give in to ransomware groups’ demands. The ransomware attack on Change Healthcare may have played a part in that. A $22 million ransom was paid to prevent the release of the stolen data; however, the ALPHV/BlackCat ransomware group pulled an exit scam, kept hold of the ransom payment, and did not pay the affiliate who conducted the attack. The affiliate retained a copy of the stolen data and, through the RansomHub group, tried to extort Change Healthcare a second time.
The percentage of victims paying a ransom in the second half of the year reduced by one-third. Chainalysis notes that the decline coincided with a reduction in big game hunting – attacks on large organizations and high-value targets. That reduction was largely due to the law enforcement operation that disrupted the LockBit group and the shutting down of the ALPHV/BlackCat ransomware group – the two most prolific ransomware groups. Since then, the ransomware landscape has become much more fragmented, with more attacks conducted by smaller groups and lone actors. 2024 saw a proliferation of new ransomware groups and an increase in attacks conducted by smaller groups and lone actors.
A report recently released from Coveware similarly shows a continuing fall in the number of victims paying ransoms. Only 25% of victims of the ransomware attacks that Coveware investigated ended up paying the ransom – the lowest percentage of any quarter to date. In the previous quarter, approximately one-third of victims paid to prevent the publication of stolen data and/or to obtain the decryption keys to recover their data. The percentage of victims paying ransoms has reduced but 2024 saw a record ransom paid. Following an attack by the Dark Angels group, a Fortune 50 firm paid a $75 million ransom. The ransom paid by Change Healthcare was also one of the largest.
The law enforcement action against the most prolific ransomware group led to a collapse of LockBit, with many affiliates leaving the group. LockBit made an attempt to show it was still active and relevant by adding a large number of new victims to its data leak site following the law enforcement takedown; however, more than two-thirds of those posts were either old attacks or fabrications. The law enforcement operation against ALPHV/BlackCat contributed to that group’s demise. Usually, when a big ransomware group shouts down, another rapidly moves to take over its market share; however, that hasn’t really happened, although the RansomHub group has been recruiting affiliates of both of those groups and is now the most prolific group, although not conducting attacks in the number of either LockBit or ALPHV/BlackCat. That could well change in 2025.
While payments are down, ransomware attacks increased to the highest number ever seen in 2024. The peak occurred in November 2024, based on additions to ransomware data leak sites. November also saw the lowest number of ransom payments of any month in 2024. The high number of ransomware attacks in 2024 suggests that ransomware groups are responding to falling numbers of victims paying ransoms by conducting more attacks. With $855 million collected in ransom payments last year, ransomware is still proving profitable, so the threat from ransomware will remain for the foreseeable future.
