The Evolution of Ransomware: From 1989 Floppy Disks to Multi-Million Dollar Extortion Empires
The history of ransomware stretches from a peculiar 1989 postal campaign to today's sophisticated criminal ecosystem featuring affiliate programs, access brokers, leak sites, technical support, and professional negotiators. In 1989, victims were instructed to mail $189 to a Panamanian post office box. By 2021, REvil demanded $70 million for a universal decryptor after compromising Kaseya VSA. By 2026, ransomware had evolved from odd mailings into a structured criminal market.
1989: Floppy disks, a biologist, and the first ransom
In autumn 1989, thousands of scientists and medical workers received floppy disks labeled “AIDS Information Introductory Diskette v2.0.” The mailing targeted participants of the 1988 International AIDS Conference in Stockholm and subscribers to journals such as PC Business World. Estimates range from 20,000 to 26,000 disks distributed. After 90 system reboots, the program hid directories and renamed files on drive C:, rendering documents inaccessible while leaving data intact. A message demanded $189 sent to PC Cyborg Corporation in Panama. The author, Harvard-educated evolutionary biologist Joseph Popp, was arrested but never stood trial after psychiatric evaluation found him unfit. The underlying idea survived its creator.
2000s: Cryptography moves to criminals
The concept remained largely theoretical until the internet became widespread and cryptographic libraries accessible. Early GPCode variants around 2004–2005 used weak symmetric encryption that researchers could break. By 2008, GPCode.ak employed 1024-bit RSA, making brute-force impractical. Archiveus in 2006 introduced full asymmetric encryption by archiving files and demanding purchases from a specific online pharmacy; operators were quickly identified and the password leaked.
2012–2014: Psychology, Bitcoin, and the first industrial model
Reveton (2012) blocked the screen and impersonated law enforcement, displaying localized warnings from the FBI, German BKA, or UK Police Central e-Crime Unit. CryptoLocker (September 2013) combined RSA-2048 encryption, the Gameover Zeus botnet, and Bitcoin payments at scale.
2016–2017: National-scale impact
Petya (2016) overwrote the MBR and encrypted the MFT, preventing system boot. WannaCry (May 2017) used the leaked EternalBlue exploit (MS17-010) to spread autonomously, affecting over 200,000 systems in 150 countries and forcing the UK NHS to cancel operations. Researcher Marcus Hutchins halted it by registering a kill-switch domain. NotPetya (June 2017) masqueraded as ransomware but functioned as a wiper, causing an estimated $10 billion in damage including $300 million to Maersk and $870 million to Merck; it originated via a compromised M.E.Doc update and combined EternalBlue with Mimikatz.
2018–2020: Professionalization
Groups such as Ryuk used Trickbot and Emotet for initial access, spent weeks mapping networks, destroyed backups, then deployed encryptors. Maze popularized double extortion in 2019 by exfiltrating data before encryption and threatening leaks. The Ransomware-as-a-Service model emerged, with developers taking 20–30% of ransoms and affiliates handling attacks. Access brokers began selling corporate entry points.
2021: Peak big-game hunting
DarkSide hit Colonial Pipeline, causing six-day fuel shortages; the company paid $4.4 million. REvil targeted JBS Foods for $11 million and later compromised Kaseya VSA, demanding $70 million. The FBI obtained a decryptor key without payment.
2022–2024: Major operations and brand resilience
LockBit conducted over 2,000 attacks since 2020, earning at least $120 million. Operation Cronos seized its infrastructure in 2024, yet the brand re-emerged. ALPHV/BlackCat infrastructure was disrupted in late 2023; the group was later linked to the Change Healthcare incident. Cl0p exploited MOVEit Transfer in 2023. Newer actors include Akira, Qilin, and Lynx.
2025–2026: Market fragmentation and new targets
The FBI IC3 report for 2025 recorded 3,600+ ransomware complaints and $32 million+ in stated losses, plus 63 new variants. Frequent names include Akira, Qilin, INC/Lynx/Sinobi, BianLian, Play, RansomHub, LockBit, DragonForce, SafePay, and Medusa. Medusa uses timers on leak sites and sells publication delays. Akira now targets virtual disks on Nutanix AHV, VMware ESXi, and Hyper-V. ENISA and Europol reports note continued use of known vulnerabilities, affiliate collaboration, privacy coins, and AI-assisted reconnaissance and phishing.
Why the model remains resilient
RaaS, access brokers, and role specialization lower attack costs. Double and triple extortion combine encryption, data leaks, customer notifications, regulatory pressure, and DDoS. Bitcoin and privacy coins facilitate payments, though blockchain analytics increasingly enable seizures. Victims in healthcare, manufacturing, and critical infrastructure often pay to avoid downtime.
AI assistance and minimum defenses
Generative AI aids reconnaissance, phishing text, and document analysis but does not autonomously execute full attacks. Recommended protections include isolated, immutable, tested backups following the 3-2-1 rule; MFA on all remote access; timely patching; network segmentation; EDR/XDR monitoring; and pre-established incident response plans.
Related articles
WannaCry Ransomware: How EternalBlue Turned One Infection Into a Global Epidemic
On 12 May 2017, the WannaCry ransomware worm rapidly infected more than 230,000 computers across at least 150 countries by exploiting the unpatched SMBv1 vulnerability with the EternalBlue exploit. The malware combined remote code execution via EternalBlue with file encryption and ransom demands in Bitcoin, affecting hospitals, manufacturers, and government organizations worldwide. Microsoft had released the MS17-010 patch two months earlier, yet many systems remained vulnerable due to delayed deployment in large environments. WannaCry scanned both local subnets and random public IPv4 addresses in parallel threads, allowing infected machines to autonomously discover and compromise new targets without user interaction. Security researcher Marcus Hutchins halted the initial wave by registering a hardcoded kill-switch domain, though later variants removed this check. The incident demonstrated how a known, patchable flaw combined with worm-like propagation could produce worldwide operational disruption.
International Law Enforcement Operation Dismantles KillSec Ransomware Group and Seizes 110 TB of Stolen Data
An international operation coordinated by Eurojust with support from Europol has dismantled the infrastructure of the KillSec ransomware group. Authorities seized five servers containing at least 110 terabytes of data stolen from victims and took control of the group's leak site domains. Three individuals were arrested, including a 16-year-old identified as the group's primary administrator and operator. The coordinated action involved law enforcement from nine countries and included eight searches across Spain, Greece, the United Kingdom, and Romania. KillSec has been active since 2024 and is linked to nearly one thousand ransomware incidents worldwide, primarily using a double-extortion model that combines data encryption with threats to publish stolen information. The seized data volume highlights the scale of the group's operations, which frequently targeted healthcare environments where system downtime directly impacts patient care.
ShinyHunters Claims Breach of FBI Recruitment Portal and Demands Eight-Figure Ransom
The hacker group ShinyHunters has publicly claimed responsibility for compromising the FBI's official recruitment website, FBIjobs.gov, asserting access to sensitive data belonging to nearly all FBI agents as well as job applicants. According to the group, the intrusion extended to multiple internal systems including criminal justice databases, human resources platforms, and Medlink. The attackers stated they exploited a zero-day vulnerability in Oracle PeopleSoft to achieve remote code execution and subsequently defaced the careers site with a fabricated seizure notice. The FBI has acknowledged awareness of unauthorized activity on the portal but has not confirmed any data theft or the scope of the intrusion. ShinyHunters is now demanding an eight-figure ransom payment, framing the amount as a minor fraction of its own resources and warning that time is limited. The operation appears to be retaliation for an FBI public statement issued in May regarding the group's prior activities. Independent verification of the claims remains unavailable, and experts note that extortion groups routinely exaggerate the value of stolen data to increase pressure on victims.
PAYLOAD Ransomware Seizes Active Directory GPO to Disrupt Entire Windows Domain Without Encryption
Researchers at Kaspersky have documented an attack by the PAYLOAD ransomware that paralyzes an entire Windows domain without encrypting a single file. Instead of encryption, the operators leverage native Windows policy mechanisms to enforce disruption across the environment. The core of the attack is a malicious Group Policy Object named PAYLOAD linked directly to the root of the Active Directory domain. This placement allows the policy to reach virtually every connected device, turning it into a corporate-wide disruption tool. Through the GPO, the group distributes ransom notes from SYSVOL, replaces wallpapers and lock screens with extortion images displaying the message Welcome to Payload, and disables local administrator accounts on affected machines. A second policy object named win Firewall Off disables the Windows firewall across the entire fleet, increasing exposure during the operation. Initial access occurred in April 2026 via a compromised legitimate domain account on a FortiGate SSL VPN, with possible entry vectors including phishing, password spraying, and credential stuffing. The victim is a manufacturing company in the Middle East. The extortion model combines data theft with operational shutdown, delivering effects similar to traditional ransomware but without any decryption key to negotiate.