๐ŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
All posts

How Ransomware Crews Get Paid: Inside the Ransom Economy

ransomwarecryptocurrencythreat-intelligencecybercrimeransomware-as-a-servicecyber-insurancecisoincident-response
September 10, 2026 ยท PlayCISO
Two hosts discuss this article โ€” generated on demand.

Ransomware is not a hacking problem with a payment attached. It is a business with a payment problem, and the payment is the whole point. Follow the money and the crews stop looking like shadowy geniuses and start looking like what they are: a franchise, its contractors, and a laundering supply chain that law enforcement and blockchain analysts increasingly read like an open ledger.

The franchise: ransomware-as-a-service

Modern ransomware runs on a ransomware-as-a-service (RaaS) model that mirrors legitimate software licensing. A core operator maintains the malware, the leak site, the negotiation portal and the affiliate program. Affiliates do the intrusions and deployment, and split the proceeds with the operator. Reported ranges from vendor research and leaked chats put the affiliate cut at roughly 70-80 percent, with the operator taking the remainder as a platform fee for the tooling and infrastructure.

A third role sits upstream: the initial access broker (IAB). IABs specialize in gaining and selling footholds -- valid VPN credentials, exposed RDP, unpatched edge devices -- so an affiliate can buy a way in rather than earn one. This division of labor is why the ecosystem is resilient. Taking down one affiliate does not touch the operator; sanctioning one operator does not retire the affiliates, who simply re-brand and re-affiliate elsewhere.

We know these economics in unusual detail because of the 2022 Conti leaks, when an insider dumped years of internal chats. They revealed salaried developers, HR-style complaints, performance management and revenue targets -- an organization, not a gang. Treat that as the analytical baseline: you are up against a company.

Sizing and negotiating the demand

Ransom demands are not plucked from the air. Affiliates reconnoiter victims before encryption, reading financial statements, cyber-insurance policies and revenue figures to calibrate a number that hurts but looks payable. Double extortion -- encrypting data and threatening to leak stolen copies -- lets them demand payment even from victims with good backups, because restoration does not un-steal the data.

Negotiation is a scripted process. Victims (or the incident-response and negotiation firms they hire) enter a chat portal and haggle; discounts of a large fraction off the opening ask are common because the opener is a bargaining anchor, not an expectation. Some crews run affiliate-facing escrow and support so disputes over splits get arbitrated internally. None of this changes the defensive posture: negotiation firms exist to buy time, assess the actor's credibility and manage sanctions exposure, not to guarantee a good outcome.

The rails: Bitcoin, Monero, and why

Most demands are still denominated in Bitcoin, for the same reason most commerce is denominated in dollars: liquidity and convertibility. But Bitcoin's public ledger is a permanent, global record of every transaction, which is exactly what investigators exploit. That is why many crews prefer or surcharge for Monero, a privacy coin that obscures amounts and parties by design. The trade-off is friction -- Monero is harder to acquire and cash out at scale, so Bitcoin remains the default despite its transparency.

The core misconception boards should unlearn is that cryptocurrency is anonymous. It is pseudonymous. Addresses are not names, but the flow of funds between them is public forever, and every point where crypto touches the traditional financial system is a potential identification.

How the money moves -- and how it is followed

At an analytical level, laundering ransomware proceeds means putting distance between the ransom address and a bank account: funds are split across many wallets, routed through mixing or coin-swap services, hopped across chains, and finally exchanged for cash through crypto exchanges or over-the-counter brokers. This blog does not provide an operational guide to any of that -- and it does not need to, because the more useful story for defenders is how each step is detected and disrupted.

Blockchain-analytics firms such as Chainalysis and TRM Labs cluster addresses, tag known criminal and service wallets, and trace flows across the very mixers meant to break them. The published record shows this working repeatedly:

  • Colonial Pipeline (2021). After the DarkSide attack, the U.S. Department of Justice traced and clawed back a majority of the Bitcoin ransom -- proof that paying is not a one-way door once investigators are on the chain.
  • Mixer takedowns. OFAC sanctioned the Tornado Cash mixing service, and law enforcement seized ChipMixer, signaling that the laundering infrastructure itself is now a target, not just the crews using it.
  • Exchange choke points. Know-Your-Customer (KYC) rules at regulated exchanges are where pseudonymous coins meet real identities. Sanctioned exchanges and off-ramps that specialized in criminal cash-out have been designated and cut off from correspondent banking.

The Chainalysis Crypto Crime reports, described in general terms, show ransomware revenue as large but volatile year to year, and a shrinking share of victims paying over time -- consistent with better backups, stronger legal caution and the deterrent effect of seizures.

The sanctions and insurance overlay

Paying a ransom can itself be illegal. OFAC advisories warn that if the actor or their infrastructure is on a sanctions list, paying -- or facilitating a payment as an insurer, negotiator or bank -- can violate U.S. sanctions on a strict-liability basis. This is why attribution matters before any payment decision, and why counsel and law enforcement must be in the room. Cyber-insurance underwriters have responded by tightening controls requirements, scrutinizing payment decisions and, in some cases, excluding sanctioned-actor payments outright.

What this means for defenders and boards

The strategic reframe is this: ransomware is a business, so disrupt its economics.

  • Remove the leverage. Tested, offline or immutable backups plus network segmentation turn a company-ending event into a bad week. If you can restore, encryption loses its power; segmentation limits how much an affiliate can reach and steal in the first place.
  • Treat payment as a legal and sanctions decision, not a technical one. Involve incident response, legal and law enforcement early; check OFAC exposure before engaging; and accept that paying never guarantees recovery and may fund sanctioned or terror-linked actors.
  • Manage the insurance relationship before the incident. Know what your policy requires, what it covers, and what it excludes -- underwriting now assumes MFA, backups and segmentation are already in place.
  • Bank on transparency. The same public ledgers the crews depend on are what let investigators claw funds back. Boards should fund the controls that make an attack unprofitable rather than betting on a quiet payout.

The crews get paid through a professional supply chain of operators, affiliates, brokers and launderers. That professionalism is also their exposure: every handoff is a record, and the defenders who win are the ones who make the whole enterprise not worth the effort.

Frequently asked questions

Is paying a ransom illegal? It can be. If the attacker or their infrastructure is subject to OFAC sanctions, paying -- or facilitating payment -- may violate U.S. sanctions on a strict-liability basis, which is why attribution, legal counsel and law enforcement must be engaged before any decision.

Is cryptocurrency actually anonymous? No. It is pseudonymous. Public blockchains record every transaction permanently, and firms like Chainalysis and TRM Labs cluster and tag addresses to follow funds -- especially wherever crypto is exchanged for cash at KYC-regulated services.

Why do some crews demand Monero instead of Bitcoin? Monero is a privacy coin engineered to hide amounts and parties, making tracing harder. Bitcoin's ledger is fully public, so crews trade off Monero's privacy against Bitcoin's superior liquidity and easier cash-out, which keeps Bitcoin the default.

Can seized ransom payments ever be recovered? Sometimes. In the Colonial Pipeline case, the Department of Justice traced and clawed back a majority of the Bitcoin ransom, and mixer seizures like ChipMixer show the laundering infrastructure itself is now a target.

What is the single best defense against the ransom economy? Remove the attacker's leverage: tested offline or immutable backups plus network segmentation. If you can restore and limit lateral spread, encryption and data theft lose much of their coercive power.

Ready to practise the decisions these articles describe?

Run a free War Room โ†’
How Ransomware Crews Get Paid: Inside the Ransom Economy | PlayCISO Blog ยท PlayCISO