Cybersecurity
October 1, 2026
People have always been fascinated by the idea of a ransom. Being forced to confront a stark question — how much are you really willing to pay for something important? — has been sparking the public imagination for generations.
In 1932, the kidnapping and subsequent demand for a ransom for aviator Charles Lindbergh’s infant son was dubbed “the crime of the century” by the American media. In 1973, John Paul Getty III was kidnapped in Italy and a ransom demand of $123 million in today’s money was sent to his grandfather, John Paul Getty Sr., then the richest man in the world. The family ultimately paid £1.8 million for his return — though only after one of Getty’s ears was delivered to a local newspaper.
These days, many of the most valuable — and vulnerable — targets aren’t physical at all. They’re in the form of data. Going after these new targets has become a lucrative industry for cybercriminals in the form of ransomware attacks.
Ransomware attacks have been a threat for years, with one of the most high-profile attacks, the so-called WannaCry cryptoworm, attacking more than 300,000 computers in 150 countries back in May 2017, including England and Scotland’s National Health Service, which had to turn away non-critical patients as their computers seized up, with all their data encrypted unless they were willing to pay a bitcoin ransom.
A recent Mastercard report shows how industrialised and far-reaching the ransomware business has become. An analysis of more than 8,300 publicly reported attacks between 2015 and 2025 revealed 277 active ransomware gangs, including 102 operating in 2025 alone, targeting a huge swath of sectors, led by health care, education and manufacturing. And the threat is not isolated to the targeted victim: Businesses with large supplier networks may feel the pain of multiple ransomware-related disruptions each year.
As technology has become more sophisticated, so have the attacks, with criminals and developers locked in a race to outwit the other. AI has become a critical weapon in fraudsters’ arsenals, helping them develop more convincing phishing attacks and increase the persistence and durability of their attacks. According to Palo Alto Networks’ Global Incident Response Report 2026, ransomware attacks are also beginning to shift away from typical encryption and extortion tactics, with encryption now seen as “optional rather than essential.” According to their findings, in 2025, several intrusions proceeded with extortion even when victims continued to retain access to their systems. “In these cases, data exposure, direct pressure or both were sufficient to generate leverage without file-locking.”
It’s not just their tactics that have evolved, but their organisation as well. Many ransomware attackers are not just isolated gangs or random actors. They’re part of a complicated network with a hierarchy and ecosystem that can rival any corporate industry. According to The Record from Recorded Future News, the Medusa ransomware gang, which in April shut down the University of Mississippi Medical Center, originally operated on its own, but in 2023 decided to transition to an affiliate model. The gang now sells access to its ransomware technology to other hacking groups, with different levels of access available depending on the hackers’ experience and earnings.
Citing an FBI report, The Record claims that in some cases developers at Medusa act as mentors for more inexperienced groups: “For newer or less experienced affiliates, important operations such as ransom negotiation may be centrally controlled by the developers.”
While ransomware gangs may operate as organized businesses, that doesn’t mean they’re always working together. Just as legitimate companies engage in competition, ransomware groups can also compete — without any regulator to ensure they’re fighting fair. Earlier this month, extortion group ShinyHunters took over the dark web site of the Cl0p ransomware gang, holding their own data for an eight-figure ransom.
“I hope you can pay that much because that is the demand, negotiable,” ShinyHunters said in a notice, also reported in The Record. “Get your bosses in front of the whiteboard in the war room. Clock is ticking moron. Kindly excuse our unprofessionalism.”
Whatever happened to honour among thieves?