Episode 2: $813 Million Paid to Ransomware Groups in 2024.
In February 2024, international law enforcement executed one of the most publicized cybercriminal takedowns in history. Operation Cronos —…
Episode 2: $813 Million Paid to Ransomware Groups in 2024. Law Enforcement Shut Them Down. They Came Back Stronger.
In February 2024, international law enforcement executed one of the most publicized cybercriminal takedowns in history. Operation Cronos — a coordinated effort involving the FBI, Europol, the UK’s National Crime Agency, and agencies from nine other countries — seized LockBit’s infrastructure, took down their dark web leak site, arrested affiliates in Poland and Ukraine, and unmasked the group’s alleged administrator, Dmitry Yuryevich Khoroshev, placing him on an international sanctions list. For a brief window, it looked like the ransomware industry had taken a serious blow.
Hi Everyone, this is Isha Singh Malik — the face behind the Mirage Insights and I write to make you aware and give you technical knowledge in simple plain language — whether you are a Common people or you are a techie. My aim is to reach you for as much information as I can. And, I welcome you onto the second episode of the BreachBrief Podcast Journey. Let’s Get on.
By December 2024, LockBit announced LockBit 4.0. Their promotional message read: “Want a Lamborghini, Ferrari and lots of girls? Sign up and start your pentester billionaire journey in 5 minutes with us.” The ransomware business was open again.
What Actually Happened in 2024?
To understand 2024’s ransomware story, you need to hold two contradictory facts at the same time. Total ransomware payments fell to $813 million — a 35% drop from 2023’s record of 1.25 billion. That sound like progress. But the number of successful ransomware attacks reached its highest point ever, with over 5,260 confirmed incidents and 56 new data leak sites created — more than double the number from the year before.
How do both of those things happen simultaneously? Because ransomware economics changed dramatically in 2024.
LockBit’s takedown and the collapse of ALPHV/BlackCat — the second largest ransomware group, which imploded after pocketing a $22 million ransom from the Change Healthcare attack without paying its own affiliates — fractured the ecosystem. The large, efficient syndicates that ran hundreds of attacks a month broke apart. Their skilled affiliates scattered into smaller groups and independent operations. These smaller actors tend to target mid-sized organizations and demand lower ransoms, which is why the payment total fell even as the attack count rose.
Meanwhile, the groups that survived went the opposite direction. The average ransom demand in 2024 climbed to $2.73 million — nearly $1 million higher than 2023. The largest single demand on record came from the Dark Angels Group, which demanded $75 million from an unnamed Fortune 50 company. Change Healthcare paid $22 million to ALPHV/BlackCat — and then watched ALPHV exit-scam their own affiliate who conducted the attack, keeping the money. CDK Global, whose software runs car dealerships across the US, paid $25 million after an attack paralyzed their operations. The average ransom demand per attack in H1 2024 exceed $5.2 million.
The median ransom payment told an equally stark story: it jumped from under $199,000 at the start of 2023 to $1.5 million by June 2024.
How Ransom-as-a-Service Actually Works?
The reason ransomware is so resilient to law enforcement action is because of how it is structured. Ransomware-as-a-Service is not a single criminal organization. It is a franchise model.
At the top sits the core developer group — the people who write and maintain the ransomware code and the supporting infrastructure (leak sites, negotiation portals, victim dashboards). Groups like LockBit’s and ALPHV played this role. They do not actually run most of the attacks themselves. Instead, they recruit affiliates — skilled cybercriminals who pay to use the platform and conduct their own attacks. When a victim pays, the ransom is split: typically 70–80% goes to the affiliate, 20–30% to the core group.
This structure means that shutting down the core group — which is what Operation Cronos did to LockBit — does not eliminate the affiliates. Those people are still out there, skilled and operational. They simply move to another platform. After LockBit’s takedown, a newer group called RansomHub rapidly absorbed displaced affiliates from both LockBit and ALPHV/BlackCat. RansomHub, which only launched in February 2024, ended the year as the most prolific ransomware group by victim count. Law Enforcement played Whack-a-Mole with the groups and the groups simply relocated.
The technical execution of most ransomware attacks follows a consistent pattern. Initial access typically comes through one of the three vectors: credential compromise (stolen usernames and passwords bought on the dark web markets or obtained through phishing), exploitation of unpatched remote access services like RDP or VPN appliances, or supply chain compromise via a third-party software provider. Once inside, the attacker spends days to weeks moving laterally through the network — identifying domain controllers, backup systems, and high-value data stores. They exfiltrate sensitive data first. Then they deploy the ransomware encryption payload across many systems as possible simultaneously. By the time the victim sees the ransom note, the attacker has already completed their leverage: pay or we publish what we took.
In 2024, data exfiltration was involved in 93% of all ransomware attacks. The encryption is almost secondary — it is the threat public data release that drives payment decisions.
Why Companies Still Pay?
Despite Everything — the law enforcement operations, the public messaging about not paying ransoms, the growing evidence that payment does not guarantee data deletion — organizations still paid. The numbers reveal a complicated picture.
Only 28% of victims who received a ransom demand actually paid in early 2024, down from 85% in 2019. That decline represents genuine progress in backup and recovery capabilities. But those who did pay faced catastrophic amounts. Recovery times have also worsened: only 22% of victims fully recovered within a week in 2024, compared to 47% in 2023. The Change Healthcare attack cost UnitedHealth Group between $2.3 billion and $2.45 billion in total response costs — for a single ransomware incident.
The decision to pay is rarely simple. When a hospital cannot access patient records or a car dealership cannot process any transactions, the daily operational loss can exceed the ransom demand within days. The calculus — pay $25 million now or lose $30 million per week in revenue — is why ransomware groups are deliberately targeting critical operational systems rather than just data.
What Actually Reduces Your Risk?
Backups are not optional — they are your primary defense. Offline, immutable backups that ransomware cannot reach or encrypt are the single most effective mitigation. But backups alone do not prevent data exfiltration, which means the double-extortion threat remains even if you can recover your system without paying. Network segmentation limits how far an attacker can move once inside. Multi-factor Authentication on every remote access point eliminates the largest class of initial access — compromised credentials. And patching remote access services and VPN appliances on a short cycle closes the vulnerability exploitation vector that initiates almost half of all attacks.
The uncomfortable truth is that no technical control eliminates ransomware risk entirely. What Changes the calculation is making your organization a harder target than the one next door. Ransomware affiliates, particularly smaller groups operating post — LockBit, conduct attacks at scale and move on when resistance appears. They are running a business. Make the cost of attacking you outweigh the expected return, and they will find the easier victim.
I broke this down in full on BreachBrief — go and check it out there and don’t forget to subscribe for more such interesting episode breakdowns.
Sources: Chainalysis Crypto Crime Report 2025 · IBM Cost of Data Breach 2024 · Cyberint Ransomware Annual Report 2024 · HIPAA Journal 2024 Ransomware Statistics · Rapid7 2024 Ransomware Landscape · Bleeping Computer LockBit 4.0 · Help Net Security Ransomware Statistics
All stats sourced from primary industry reports. If you liked it please do let me know in the comment and we will discuss more about it.
Hope you understand it and might be it helped you to gain insights.
Thanks for reading and watching the video. Happy Learning ✨✨.
메타데이터
- post_id
- c5ded87afa4d
- slug
- episode-2-813-million-paid-to-ransomware-groups-in-2024-c5ded87afa4d
- url
- https://medium.com/@mirageinsghts/episode-2-813-million-paid-to-ransomware-groups-in-2024-c5ded87afa4d
- canonical_url
- https://medium.com/@mirageinsghts/episode-2-813-million-paid-to-ransomware-groups-in-2024-c5ded87afa4d
- author_url
- https://medium.com/@mirageinsghts
- status
- ok
- fetched_at
- 2026-06-09 15:37:30