Back to glossaryCyber

Ransomware as a Service (RaaS)

A cybercriminal business model in which operators rent a turnkey ransomware kit to affiliates in exchange for a share of the ransom.

Definition

Ransomware as a Service is a model for organizing cybercrime that mirrors the software-as-a-service economy. A group of operators develops and maintains the ransomware itself, its payment infrastructure and its data-leak site, then makes the whole package available to affiliates who handle intrusion and deployment. Ransom proceeds are split according to a negotiated key, often around 70 to 80 percent for the affiliate. This division of labor sharply lowers the technical barrier to entry, since an attacker no longer needs coding skills to run a campaign. For the cyber insurer, RaaS is a structural factor, as it explains the industrialization of attacks, the professionalization of ransom negotiation and the growing correlation of claims when a single strain hits many policyholders at once. One important nuance deserves emphasis: the ecosystem is volatile, with ransomware brands dissolving and re-forming under new names after law-enforcement operations, which complicates historical loss analysis by group.

Example

The LockBit group operated for years on a RaaS model, providing affiliates with a victim-management panel and a leak site for stolen data, until its partial takedown by the international Operation Cronos in 2024.

Related terms
Related articles
Also known as

rançongiciel à la demande, raas