Copied


Ransomware Payments Drop as Victim Resilience Increases in 2024

Peter Zhang   Feb 05, 2025 06:00 0 Min Read


The ransomware landscape witnessed notable changes in 2024, with total ransom payments decreasing by 35.82% year-over-year (YoY), according to a report by Chainalysis. This decline, marking the first drop in ransomware revenues since 2022, is attributed to intensified law enforcement actions, improved international cooperation, and an increased refusal by victims to pay.

Adapting to New Threats

Despite the decline in overall payments, the ransomware ecosystem has become more dynamic, with attackers adopting new tactics. These include the emergence of new ransomware strains from rebranded or purchased code, reflecting a more agile threat environment. Attackers now range from nation-state actors to ransomware-as-a-service (RaaS) operations and lone operators.

Significant Payment Declines

In 2024, ransomware attackers received approximately $813.55 million in payments, a sharp decrease from the $1.25 billion recorded in 2023. The decline in payments was particularly pronounced in the second half of the year, similar to trends seen in other types of crypto-related crime, such as stolen funds.

Law Enforcement and Victim Resilience

Law enforcement efforts played a crucial role in disrupting major ransomware operations. For instance, the UK’s National Crime Agency and the US FBI’s actions against LockBit resulted in a 79% decrease in payments to the group. Moreover, victims are increasingly resisting ransom demands, with many opting to restore data from backups instead of paying.

Ransomware Laundering Methods

The report also highlights changes in how ransomware funds are laundered. There is a decline in the use of mixers, with attackers increasingly relying on centralized exchanges, personal wallets, and cross-chain bridges. This shift is partly due to sanctions and law enforcement actions against mixing services.

Case Studies and Notable Arrests

The arrest of Rostislav Panev, an Israeli-Russian dual citizen, marked a significant blow to LockBit’s operations. Panev is accused of developing tools for the group and is currently awaiting extradition to the United States.

Conclusion

As ransomware actors continue to adapt to increased scrutiny, the need for sustained collaboration between law enforcement, incident response firms, and blockchain experts remains critical. The progress made in 2024 demonstrates the effectiveness of these efforts in reducing ransomware profitability and increasing victim resilience.

For more details, visit the Chainalysis blog.


Read More