05

Ransomware as a Financial Asset

Underground economy, ransom markets and insurer pricing: how ransomware became a structured industry whose growth is partly financed by cyber insurance payouts.

CyberRansomwareRaaSInsuranceOFACJune 26, 2026
$813.5M
ransomware payments in cryptocurrencies in 2024, down 35% year-on-year (Chainalysis)
$22M
ransom paid by UnitedHealth to ALPHV/BlackCat in the Change Healthcare attack
25%
share of victims that paid a ransom in Q4 2024, historic low (Coveware)
194
LockBit affiliates identified during Operation Cronos led by the NCA in February 2024

1. The Industrialization of a Criminal Economy

From Opportunistic Attack to Platform Model

For a long time, ransomware resembled a cottage industry conducted by autonomous operators who independently developed, deployed and negotiated their own attacks. From 2019 onward, this configuration gave way to a platform model designated by the acronym RaaS, for ransomware as a service. Under this scheme, a core group of developers maintains proprietary software infrastructure and makes it available to affiliates in exchange for a share of the collected ransom. The Ransomware Task Force report published in 2021 by the Institute for Security and Technology already described this functional specialization as the most structurally significant transformation of the decade for the cybercrime market.1

LockBit, whose infrastructure was partially dismantled by Operation Cronos conducted by the British National Crime Agency in February 2024, illustrates this model in exemplary fashion. The group operated for more than four years relying on a network of 194 affiliates that authorities identified during the seizure of its infrastructure. This seizure encompassed 34 servers spread across the Netherlands, Germany, Finland, France, Switzerland, Australia, the United Kingdom and the United States.2 This transborder logistical network resembles less the structure of a traditional criminal organization than that of a multinational software publisher, except that affiliate compensation is carried out in cryptocurrencies and governance operates on clandestine forums.

The Cybercriminal Value Chain

The ransomware ecosystem has segmented into at least three distinct trades that now function as an integrated network. Initial Access Brokers, commonly designated by the acronym IAB, identify and compromise targets whose access they then resell on specialized forums such as Exploit, XSS or RAMP. Affiliates rent a ransomware strain from a RaaS operator, deploy the attack using access purchased from an IAB, and negotiate the ransom. Professional negotiators, sometimes employed by RaaS operators and sometimes by victims through their insurers, manage the exchange and payment terms.

Analyses published by Flare and Rapid7 on Russian-language cybercrime forums show that the price of initial access ranges from a few hundred dollars for an SME to several tens of thousands of dollars for a Fortune 500 company with domain administrator privileges.3 The median price of an access sale stood around $1,328 in 2023. This radical asymmetry between entry cost and target value constitutes the central economic lever of contemporary ransomware. Attacking an organization with billions in revenue remains economically viable from an initial investment that does not exceed the price of a professional laptop.

IABs as a Wholesale Market IABs have brought about the same transformation for ransomware as wholesale markets did for retail commerce. By outsourcing the most time-consuming phase of the attack, namely the identification and initial compromise of a target, they allow affiliates to concentrate on deployment and negotiation, thereby accelerating the turnover of criminal capital and reducing the marginal cost of an additional attack.

2. The Pricing of the Ransom

The Economics of a Payment Under Constraint

Ransom payment rests on a considerable information asymmetry between the two parties. The victim is unaware of the attacker's real identity, their actual capacity to honor delivery of a functional decryption key, their willingness not to exfiltrate data a second time, and the possible existence of an OFAC sanctions nexus that would compromise the legality of the transfer. The attacker, for their part, does not know the maximum payment threshold the victim can consent to, their effective insurance coverage, or their potential preparedness for resilience through offline backups. This double asymmetry produces a negotiation whose parameters are rarely rational in the classical economic sense.

Data published by Coveware on its own intervention files indicate that in the fourth quarter of 2024, only 25% of consulted victims ultimately paid the ransom, the lowest level ever recorded since monitoring began in 2018.4 This reluctance is paradoxically accompanied by a concentration of payments on large-scale losses. The average payment reached $553,959 over the same period while the median fell to $110,890. The gap between mean and median reflects the bifurcation of the market between mass-market activity targeting SMEs, the majority of which now refuse to pay, and so-called big game hunting activity targeting organizations capable of disbursing several million dollars without difficulty.

The Change Healthcare Case

The attack conducted in February 2024 by the ALPHV/BlackCat group against Change Healthcare, a subsidiary of the UnitedHealth Group conglomerate specializing in healthcare payment processing in the United States, illustrates the pathologies of this market at large scale. UnitedHealth confirmed in April 2024, through its CEO Andrew Witty testifying before the US Congress, the payment of a ransom of approximately $22 million in bitcoin.5 The payment did not prevent a second group, RansomHub, from claiming possession of the same exfiltrated data and demanding an additional ransom, highlighting the absence of contractual guarantees in a criminal transaction.

The final cost of the loss event for UnitedHealth, incorporating remediation, operational losses, liability claims and anticipated regulatory fines, is estimated by the group at more than $1.5 billion according to its own statements filed with the Securities and Exchange Commission.6 The ratio between the ransom paid and total cost therefore stands at around 1.5%, an order of magnitude that illustrates the economically marginal character of the payment relative to the insurable loss, and which justifies, from the insurer's perspective, a payment decision when continuity-of-business alternatives are unavailable.

3. The Financial Infrastructure of Ransomware

Bitcoin as the Reference Currency, Monero as the Premium Option

Bitcoin remains the reference cryptocurrency for ransom payments despite its traceability, which should rationally make it unattractive for criminals. The reason for this persistence is threefold. First, its liquidity surpasses that of any other cryptocurrency, making conversion to fiat currency faster and less conspicuous. Second, the payment ecosystem supports it universally, while many victims simply do not know how to obtain monero within a timeframe compatible with the negotiation window. Third, the network effect of negotiation tools, brokers and clandestine marketplaces rests on bitcoin for reasons of technical and operational inertia.

Monero, the leading representative of so-called privacy coins, nonetheless occupies a growing place in operators' strategy.7 Negotiators at Coalition and Coveware report the frequent appearance, since 2021, of differentiated rate schedules in which the ransom is reduced if the victim pays in monero rather than bitcoin. The DarkSide group applied a 20% surcharge on bitcoin payments compared to monero. This pricing directly reflects the marginal cost borne by the attacker to launder traceable funds, and constitutes in effect an indirect measure of the residual prosecution risk associated with each cryptocurrency.

Chain-hopping, Mixing and Flow Obfuscation

An attacker who receives bitcoin then deploys obfuscation strategies, the most widespread of which is chain-hopping. This technique consists of the successive conversion of funds from one cryptocurrency to another via loosely regulated exchange platforms or non-custodial mixing services.8 Ancillary techniques include peel chains, in which a fraction of funds is successively extracted toward different addresses to break the analysis chain, and routing through decentralized exchange platforms that do not perform identity verification. Chainalysis observes in 2024 a reverse phenomenon: operators who choose to store their proceeds in personal wallets without moving them for months, for fear of being monitored by authorities.9

The Liquidity Paradox The more anonymous a cryptocurrency is, the less liquid it is. Monero offers superior privacy but suffers from lower capitalization and acceptance than bitcoin. Ransomware operators must continuously arbitrate between traceability and payment executability. This arbitrage explains why bitcoin retains its dominant position despite its intrinsic transparency.

4. The OFAC Regulatory Lever and the Attribution Problem

The September 2021 Advisory

The Office of Foreign Assets Control of the US Treasury published on September 21, 2021 an updated Advisory on the sanctions risks associated with facilitating ransom payments.10 The text explicitly targets financial institutions, cyber insurance companies, and incident response firms involved in the execution of a ransom payment. US doctrine holds that any payment made to a sanctioned actor or linked to a jurisdiction under embargo exposes its author to strict liability, that is, independent of proof of culpable intent. On the same day, OFAC listed for the first time a cryptocurrency exchange platform, SUEX OTC, on its list of Specially Designated Nationals, paving the way for a policy of designating financial intermediaries rather than direct perpetrators alone.

Attribution as a Technical Lock

The sanctions framework rests on the operational capacity to attribute an attack to an identified actor. This attribution runs up against considerable technical limitations that constrain its practical scope. RaaS operators operate under interchangeable pseudonyms, affiliates migrate from one group to another, and ransomware strains are regularly rebranded after each dismantlement operation. Operation Cronos revealed that several LockBit affiliates were also active under other banners, blurring the boundaries between groups.11 For the insurer, this uncertainty translates into a specific operational risk: the blocking of a payment mid-negotiation if attribution becomes problematic during the process, which prolongs the duration of the loss and mechanically amplifies the indemnifiable business interruption losses.

The Market Effect of the LockBit Dismantlement

Operation Cronos produced an immediate but time-limited market effect. Global payments fell 35% in 2024, dropping from $1.25 billion in 2023 to $813.5 million, with a particularly sharp collapse in the second half of the year.12 No major group immediately filled the void left by LockBit. The market fragmented into second-tier actors such as RansomHub and Akira, which favored more modest targets and more moderate ransoms. This transition illustrates a fundamental characteristic of the ransomware market: the disruption of a dominant operator does not eliminate the underlying demand; it temporarily redistributes supply toward less efficient actors until a new concentration occurs.

5. The Insurer Facing Endogenous Losses

The Post-2022 Repricing and MFA Requirements

The cyber insurance market underwent a brutal repricing between 2020 and 2022 as ransomware losses became uninsurable at previous pricing levels. Premiums tripled across major portfolios, ransomware coverage sub-limits were reduced, and technical requirements imposed on policyholders tightened in an unprecedented manner. Reinsurers made multi-factor authentication on all remote access, offline backup segmentation, and an incident response plan tested by annual exercise mandatory prerequisites for underwriting. This transformation marked the shift from pure indemnification logic to a co-insurance logic for cybersecurity best practices.

The Exclusion of State-Sponsored Cyber Operations

In parallel, Lloyd's of London published in August 2022 Market Bulletin Y5381 requiring all syndicates to include, from March 31, 2023, an exclusion for state-sponsored cyberattacks in all standalone cyber policies.13 The Lloyd's Market Association published for this purpose four model clauses in their A and B versions, whose principal difference concerns the treatment of attribution. Version A clauses integrate a reference to determination by a competent authority, while Version B clauses dispense with this. This segmentation reflects the persistent legal difficulty of defining what constitutes a state-sponsored cyberattack within the meaning of an insurance exclusion, and represents a considerable zone of potential litigation for the coming decade, as the boundary between criminal group and state actor is deliberately maintained by certain sponsoring states.

The Insurance Circularity Ransomware confronts the insurer with a structural peculiarity unprecedented in the history of the property and casualty branch. The ransom that the insurer indemnifies can itself feed the criminal ecosystem that produces future losses. This circularity distinguishes ransomware from traditional risks and fuels the debate on an outright ban on payments, as North Carolina decided for its public entities in 2022.

The Limits of the Insurance Model

The debate on the legitimacy of ransom payment remains vigorous within the cyber insurance market. The dominant position of major insurers continues to hold that payment must remain a supervised option rather than a prohibited act, insofar as its prohibition would deprive victims of a business continuity lever whose cost-benefit balance is not systematically unfavorable.14 The challenge for the coming decade is to isolate the ransomware component within the insurable cyber perimeter, address it through public-private co-insurance mechanisms potentially backed by a pool, and link its indemnification with an obligation of systematic reporting to the authorities. Failing this, the characterization of ransomware as an underground financial asset will remain the blind spot of cyber coverage that inadvertently finances its operational liquidity.


Sources and references

1. Institute for Security and Technology, Combating Ransomware: A Comprehensive Framework for Action, Ransomware Task Force report, April 2021.

2. National Crime Agency, press release of February 20, 2024; Europol, Operation Cronos file, February 2024.

3. Flare Threat Intelligence, The Initial Access Broker Economy: A Deep Dive into Dark Web Hacking Forums, September 2023; Rapid7, Initial Access Brokers have Shifted to High-Value Targets, H2 2025.

4. Coveware, Ransomware Quarterly Report Q4 2024, February 4, 2025.

5. Testimony of Andrew Witty, CEO of UnitedHealth Group, before the House Energy and Commerce Committee, April 30, 2024.

6. UnitedHealth Group, Forms 8-K and 10-Q filed with the Securities and Exchange Commission, Q1 through Q3 2024.

7. TechTarget, Ransomware actors increasingly demand payment in Monero, January 2022; Bank Info Security, Ransom Payments: Monero Promises Privacy, April 2022.

8. Bax N., Tracing the WannaCry 2.0 Monero Transactions, 2021; Möser M. et al., An Empirical Analysis of Monero Cross-Chain Traceability, arXiv:1812.02808.

9. Chainalysis, 2025 Crypto Crime Report, Ransomware chapter, February 2025.

10. Office of Foreign Assets Control, Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments, US Department of the Treasury, September 21, 2021.

11. Trend Micro, Unveiling the Fallout: Operation Cronos' Impact on LockBit Following Landmark Disruption, April 2024.

12. Chainalysis, Ransomware Payments Drop 35% in 2024, February 2025; CyberScoop and The Record, February 2025.

13. Lloyd's Market Bulletin Y5381, August 2022; LMA Bulletin LMA23-002-PD of January 20, 2023, clauses LMA5615 to LMA5618.

14. Geneva Association, Cyber Insurance and the Question of Ransom Payments, position paper, 2023; Lloyd's, Cyber Underwriting Minimum Standards, 2023-2024 updates.

Related articles
09

The Financial Lines Market Post-Covid

Since 2018, the financial lines market has offered the purest textbook case of the underwriting cycle. A cleansing of supply collided with the fear of a wave of Covid-related claims to produce the most brutal hard market of the century.

Financial LinesD&O
Read →
07

Solvency II Tested by Cyber Risk

Solvency II rests on two postulates inherited from classical actuarial science, the ability to diversify weakly correlated risks and the ability to estimate their distribution from historical data. Cyber risk contradicts both.

Solvency IICyber Risk
Read →
03

Silent Cyber: from Grey Zone to Explicit Clause

Revisiting the Lloyd's LMA 21-042 directive and its implications for Property & Casualty reinsurance treaties

Silent CyberLloyd's
Read →
Editorials you might enjoy
HS04

The day Solvency II met a ransom

The regulator asks a simple question, how much money must you hold to survive your worst year in two centuries. For a book of hurricanes, the actuary answers without flinching. For a book of ransomware, the room falls silent.

Solvency IICyber Risk
Read →
HS05

NIS2, the directive no one has read but that binds you anyway

A mid-sized company receives a letter from its largest client, a clause demanding proof of NIS2 compliance within ninety days, or the contract ends. Its director has never heard of NIS2. And they are wrong not to worry.

LawCyber
Read →