A ransomware strategy focusing exclusively on large organizations capable of paying very high ransoms.
Big game hunting describes the strategic shift of ransomware groups toward the deliberate targeting of large organizations, Fortune 500 companies, critical infrastructure, major hospitals or significant public bodies, capable of paying ransoms of several million dollars. This approach contrasts with indiscriminate mass campaigns that simultaneously targeted hundreds of thousands of modest entities for unit ransoms of a few hundred to a few thousand dollars. The shift to big game hunting was enabled by the maturation of RaaS models, the emergence of Initial Access Brokers providing qualified access to high-value targets, and the professionalization of negotiating units. Ransom demands in this context are calibrated against the victim's publicly available financial data, often between 0.5 and 3 percent of annual revenue. For the insurer, this bifurcation of the ransomware market concentrates the most costly claims on insureds who often hold the broadest coverage, creating an adverse correlation between the presence of cyber insurance and the magnitude of the ransom demanded. The growing gap between the mean and median ransom payment precisely reflects this concentration on large victims.
The ALPHV/BlackCat attack on Change Healthcare in 2024 illustrates big game hunting at scale: the target is a healthcare payment processor handling one third of US medical records, the ransom paid reaches 22 million dollars, and the total loss cost exceeds 1.5 billion dollars for the UnitedHealth group.
chasse au gros gibier, attaques grandes entreprises, BGH