Unchained
Unchained

How Ransomware Evolved Into a Big Business - Ep.256

Gurvais Grigg, Chainalysis public sector CTO, and Kim Grauer, director of research at Chainalysis, review the ransomware landscape. Show Highlights: their backgrounds and roles at Chainalysis how a ransomware attack works what types of businesses are usually targeted in ransomware attacks why ransom

Featured Speakers

Gervas Grigg GuestKim Grauer Guest

Topics Discussed

Episode Summary

Executive Summary: Laura Shin’s Unchained episode examines ransomware as a rapidly scaling crypto-enabled crime ecosystem. Chainalysis researchers Kim Grauer and Gervas Grigg explain how attacks work, why criminals favor Bitcoin, how ransomware-as-a-service lowers the barrier to entry, and why the network’s concentration in a few laundering/off-ramp services creates a major investigative weakness.

Main Topics: Ransomware basics and how attacks unfold (Priority: 5/5): The guests define ransomware as malware that locks, encrypts, steals, or threatens to leak data, then demands payment for restoration or silence. Victims may first notice inaccessible systems, degraded performance, or explicit ransom messages. Ransomware as a service and the criminal supply chain (Priority: 5/5): The conversation details how modern ransomware operates like SaaS: operators sell malware and infrastructure while affiliates carry out attacks, with separate services for hosting, laundering, and cashing out stolen funds. Why cryptocurrency is the preferred payment rail (Priority: 5/5): Bitcoin is favored for speed, ease of onboarding, fungibility, and perceived anonymity. The hosts also discuss why privacy coins are less practical for large ransom demands because of liquidity and exchange restrictions. Chainalysis data and concentration in laundering off-ramps (Priority: 5/5): Grauer explains that ransomware proceeds are unusually concentrated in a small number of services and deposit addresses, which makes them easier to profile and potentially disrupt than other illicit crypto activity. Ransomware groups, Russian/CIS ties, and threat attribution (Priority: 4/5): The guests discuss code that avoids attacking CIS countries, the prevalence of groups linked to Russian-speaking regions, and how jurisdictional laxity or weak enforcement can create safe havens for cybercriminals. Government response, law enforcement, and counterterrorism parallels (Priority: 4/5): Grigg frames ransomware as analogous to terrorism because it creates fear and disrupts essential services. The discussion emphasizes whole-of-government coordination, sanctions, legislation, and focused dismantlement of key nodes. Colonial Pipeline and recovering stolen crypto (Priority: 3/5): The episode briefly references the Colonial Pipeline case and DOJ’s seizure of part of the ransom, highlighting that recovery may come through exchanges, compromised keys, or arrests, though the exact method was not discussed.

Key Arguments: Ransomware has evolved from simple data encryption to a broader extortion model that includes data theft, leak threats, and service disruption, increasing the pressure on victims. Ransomware-as-a-service lowers the technical barrier to entry, enabling more criminals to participate by buying malware, hosting, laundering, and cash-out services. Bitcoin remains attractive because it is fast, widely accessible, and perceived as more anonymous than traditional payment channels, even if it is traceable on-chain. Chainalysis can map ransomware ecosystems because blockchain data exposes payment flows, allowing researchers to identify repeated off-ramp services and laundering nodes. The concentration of ransomware proceeds in a small set of laundering addresses/services suggests the ecosystem is smaller and more vulnerable than it may appear. Law enforcement can best fight ransomware by targeting critical nodes, using data, subpoenas, sanctions, and international cooperation rather than treating each attack as isolated. Authorities generally advise victims not to pay, since ransom payments fuel future attacks, but if victims do pay they should contact law enforcement immediately. The parallels to counterterrorism lie in the need for national coordination, public-private partnerships, awareness, and dismantling the infrastructure that sustains the threat.

Data Points: Ransomware extorted last year: $412 million - Laura cites Chainalysis figures for ransomware payments in the prior year. Ransomware obtained in first five months of this year: $127 million - Laura cites year-to-date 2021 ransomware receipts. Revil attack scale: More than 1 million computers infected - Laura describes the early-July attack attributed to Revil/Sodinokibi. Revil ransom demand: $70 million - Laura references the demand in the major Revil attack. Colonial Pipeline ransom demand: 75 BTC - Laura notes the amount demanded from Colonial Pipeline. Colonial Pipeline amount reportedly paid: 63.7 BTC - Laura states the portion allegedly paid to the hackers. Ransomware growth in 2020: Over 300% growth - Grauer references Chainalysis’s characterization of 2020 as the year of ransomware. Crypto.com Earn rate on Bitcoin: Up to 8.5% - Sponsor read in the episode intro and mid-roll. Crypto.com Earn rate on stablecoins: Up to 14% - Sponsor read in the episode intro and mid-roll. Crypto.com user base: Over 10 million users - Sponsor read promoting the Crypto.com app. Crypto.com supported coins: Over 90 cryptocurrencies - Sponsor read promoting the Crypto.com app. U.S. crypto ATM count mentioned: Over 15,000 - Grigg references the number of Bitcoin/crypto ATMs in the United States.

Pivotal Quotes: "At the end of the day, it's all about money, Laura." — Gervas Grigg: Explaining why ransomware groups may make public exceptions or carve-outs while still prioritizing profit. "There is no kind of central data source with U.S. dollars where you can see where all the illicit money is going." — Kim Grauer: Describing why blockchain analytics are uniquely valuable for tracking ransomware proceeds. "The perception that cryptocurrencies are anonymous. And at best, they're pseudo-anonymous." — Gervas Grigg: Clarifying why criminals prefer crypto while noting that blockchain activity can still be traced.

Implications: Ransomware is becoming more industrialized and easier to launch, but also more traceable through blockchain analytics. For industry and government, the priority is better data, stronger coordination, and targeting the small number of laundering and cash-out nodes that sustain the ecosystem.

🔓 Sign Up for Unlimited Episode Search

About Unchained

View all episodes from Unchained