Ransomware attacks generated over $800 million in 2025, with hackers increasingly using cryptocurrencies for their transactions. Cryptocurrencies are preferred because they offer higher profits and are more difficult to trace compared to traditional payment methods. Countries like Russia, Iran, and North Korea are known to have ambiguous stances on these activities, complicating efforts by financial authorities to track and stop these crimes.
This summer, a major cyberattack targeted the Direction générale des finances publiques (DGFiP), a French government agency responsible for tax and property records. The attack resulted in the theft of data from 678,000 individuals and professionals, including personal details such as names, addresses, phone numbers, and tax information. This incident is not an isolated case. In 2025, ransomware attacks in France were reported to have generated over $820 million in ransom payments, with the National Agency for Information System Security (ANSSI) documenting 128 major attacks, primarily affecting small and medium-sized enterprises.
Hackers, often known by pseudonyms such as Qilin, TheGentlemen, or DragonForce, use ransomware to encrypt victims' data and steal it. Victims are then asked to pay a ransom to regain access to their files. This is referred to as "simple extortion." For individuals, this might be the end of the story, but for companies, the stakes are much higher. Companies often face the risk of their sensitive data being leaked if they don't pay the ransom, a scenario known as "double extortion." In some cases, attackers may also threaten to launch additional cyberattacks, such as denial-of-service attacks, which are termed "triple extortion."
The history of ransomware dates back to 1989 with the "AIDS Trojan," created by Joseph Popp, an employee of the World Health Organization. Popp distributed floppy disks containing the malware to over 26,000 recipients, asking them to pay $189 to continue using the disks. He was later arrested by the Computer Crime Unit of New Scotland Yard and was found to have mental health issues. In 1996, researchers Adam Young and Moti Yung noted that the concept could be used for extortion, leading to the evolution of a ransomware industry. Notable developments include CryptoLocker in 2013, Locky in 2016, and Lockbit in 2019, which introduced the Ransomware-as-a-Service (RaaS) model.
Estimating the true cost of ransomware is difficult. The FBI, Financial Crime Enforcement Network (FINCEN), and Chainalysis are among the organizations that study these attacks. However, the FBI's figures are often lower, as companies may not report attacks unless required by law, fearing damage to their reputation. The actual costs, including data loss, revenue loss, and reputational damage, can be significantly higher. For example, an attack on Jaguar Land Rover in 2025 is estimated to have cost the company over $350 million, with even greater costs for its subcontractors.
Despite the growing use of cryptocurrencies, which allow for greater anonymity, some countries are taking steps to combat these activities. The Financial Action Task Force (FATF) has called for stricter regulations on cryptocurrency exchanges, and several Russian exchanges have been sanctioned by the U.S. for facilitating ransomware payments. While Bitcoin was once the primary currency for ransom payments, Monero has gained popularity due to its enhanced privacy features. However, with increased scrutiny from regulatory bodies, Bitcoin remains a common option for victims to pay ransoms.
The global fight against ransomware requires a multi-faceted approach. Researchers suggest that public authorities should encourage insurers to limit ransom payments and promote cybersecurity standards. A balance between openness and security, as well as efficiency and resilience, is crucial in developing effective strategies against these cyber threats.
Ransomware Industry Generates Over $800 Million in 2025, Utilizing Cryptocurrencies for Payments
AI-rewritten from original reportingHow it works
ransomwarecybercrimecryptocurrencydouble-extortionstate-supportdata-leak



