The a16z Podcast
The a16z Podcast

All About Ransomware

How ransomware works, from the anatomy of a hack to how the groups operate; the role of nation-states, insurers, and regulators; and what to do if your stuff is taken hostage...

Featured Speakers

a16z Host

Topics Discussed

Episode Summary

Executive Summary: This episode explains ransomware as a fast-growing, profit-driven cybercrime business model: criminals gain initial access through basic vulnerabilities, move laterally, encrypt systems and increasingly steal data, then demand payment via sophisticated negotiation portals. The discussion covers criminal syndicates, nation-state protection, cyber insurance incentives, OFAC/legal risks, and practical prevention/response steps.

Main Topics: What ransomware is and why it exploded (Priority: 5/5): Ransomware is framed as crimeware that takes computers or data hostage for payment. Its growth is driven by the fact that nearly every business is now digital, making information assets valuable leverage. How ransomware attacks work end-to-end (Priority: 5/5): Attackers typically exploit exposed RDP services, phishing, or old unpatched vulnerabilities, then use tools like Cobalt Strike to move laterally, disable defenses, remove backups, and encrypt systems within hours. Ransomware as an organized business ecosystem (Priority: 5/5): The speakers describe ransomware groups as multi-role criminal enterprises with reconnaissance, payload delivery, command-and-control, negotiation, and data-resale functions, often shared across forums and ransomware-as-a-service models. Data theft, encryption, and the economics of extortion (Priority: 5/5): The episode explains the shift from locking hardware to encrypting hard drives and now stealing data, using asymmetric encryption to make recovery infeasible without the private key and to maximize leverage. Nation states, safe havens, and attribution problems (Priority: 4/5): Ransomware flourishes where law enforcement is weak or tacitly tolerant. The episode highlights Eastern Europe/Russia as enabling environments and notes that criminal actors may be connected to state or political power. Cyber insurance and regulator pressure (Priority: 4/5): Cyber insurers have historically paid ransoms, which helped incentivize attacks; now premiums are rising and OFAC-related restrictions create legal risks for paying sanctioned groups, complicating response decisions. Prevention and incident response basics (Priority: 5/5): The speakers stress basic hygiene—2FA, patching, password managers, and offline backups—as the most effective prevention, and advise victims to seek expert help and law enforcement guidance immediately.

Key Arguments: Ransomware is less a single technical product than a business model for monetizing access at scale. Criminal groups reuse existing infrastructure and tactics as spam, phishing, and malware methods get disrupted, showing organizational adaptability. The rise in ransomware is largely economic: higher payouts attract more groups and more investment in criminal capability. Simple, widely known weaknesses—especially exposed RDP, phishing, and unpatched systems—remain the most common entry points. Attackers increasingly target backups, internal systems, and domain controllers so recovery is harder and ransom pressure is higher. Modern ransomware often combines encryption with data theft, creating double extortion and making privacy exposure part of the leverage. Ransomware groups behave like legitimate companies, with specialization, outsourcing, reputation management, and even customer-service-like decryption workflows. Cyber insurance can unintentionally increase demand for ransom payment, while also making insurers and victims more likely to engage with criminals. Sanctions and OFAC rules add legal uncertainty, especially because victims often cannot reliably identify who is behind an attack. Good fundamentals—2FA, patching, offline backups, and password managers—remain the most effective defenses because many attacks use low-effort tactics. When a victim is hit, the first priority is to get expert help and avoid improvising, because ad hoc recovery often makes the situation worse. The future risk is more personal: stolen data will increasingly be used to target individuals, not just organizations.

Data Points: Ransom size (historical high end): $200,000 to $500,000 - Earlier ransomware demands; described as the higher end a couple years ago. Ransom size (current starting point): About $200,000 - Current baseline demand cited by Joel De LaGarza. Ransom size (observed today): $40 million to $50 million - Amounts Flashpoint has seen in real incidents. Ransom size (reported by others): Up to $100 million - Tom Hoffman says others have reported demands reaching this level. Time to full network encryption: As soon as 5 or 6 hours - Time from initial infection to full network encryption in a typical attack. Cracking time for industrial-grade encryption: 35,000 years - Estimated time to decrypt without the key using available computing power. Insurance policy estimate seen by attackers: $20 million - One criminal group reportedly knew the victim’s insurance cap and tailored ransom demands accordingly. Stolen credentials observed recently: 100 million new credentials - Tom Hoffman cites this as newly seen in the past month. Cyber insurance penetration: About 30% of companies - Estimated share of companies currently carrying cyber insurance. Expected cyber insurance penetration: 60% to 70% over 10 years - Projected future adoption rate for cyber insurance. Premium increase forecast: 40% to 50% - Expected across-the-board increase in cyber insurance premiums. Premium increase after ransom payment: Triple to 5x - Victims that have paid a ransom may face much higher future premiums. Syndicate pay split: 80% to operator, 20% to collective - Ransomware-as-a-service revenue sharing model described in the episode. Monthly earnings for recruits: Up to $60,000 per month - Compensation mentioned for joining a syndicate after technical submissions.

Pivotal Quotes: "Ransomware is kind of the pinnacle of the crimeware/slash hacking for profit type activities that we see." — Joel De LaGarza: Defines ransomware as the peak form of profit-driven cybercrime. "It is really just as simple as using 2FA, patching your systems, and just doing good IT hygiene." — Joel De LaGarza: Summarizes the episode’s core prevention advice. "You don't know." — Tom Hoffman: Response to whether victims can know if attackers are on an OFAC list or will later be sanctioned.

Implications: Ransomware will keep scaling unless organizations improve basic hygiene, insurers rethink incentives, and governments coordinate across borders. Expect more double extortion, more legal complexity, and greater personal risk from stolen data.

🔓 Sign Up for Unlimited Episode Search

About The a16z Podcast

The a16z Podcast discusses tech and culture trends, news, and the future – especially as ‘software eats the world’. It features industry experts, business leaders, and other interesting thinkers and voices from around the world. This podcast is produced by Andreessen Horowitz (aka “a16z”), a Silicon Valley-based venture capital firm. Multiple episodes are released every week; visit a16z.com for more details and to sign up for our newsletters and other content as well!

View all episodes from The a16z Podcast