RSS Amplifier

Full Signal by Max Avery · Dec 5, 2025

What to Know About Ransomware and Online Blackmail

0
Sign in to vote or save

Max Avery · Full Signal by Max Avery

“Over 80% of victims who pay ransom still don’t fully recover their data, and they become marked targets for future attacks. The real solution starts way before an attack ever happens.” – Max Avery, Digital Ascension Group

TL;DR

Digital extortion has grown into a global crisis, with the FBI reporting over $16 billion in losses for 2024 alone - a 33% jump from the previous year. Global cybercrime costs are projected to reach $11.9 trillion in 2026. The good news? Payment rates have plummeted to historic lows as more organizations realize that paying ransoms rarely works. In Q4 2024, 84% of victims who paid still failed to recover all their data. Meanwhile, 97% of organizations can now restore their systems from backups. Attacks often begin with something as basic as a weak password or a single phishing email. Your two-factor authentication might have vulnerabilities you’ve never considered. And if you become a victim, documenting evidence properly is far more complicated than most people expect. The best defense remains preparation, not panic.

I’ve been tracking cybersecurity trends for years, and honestly, the numbers coming out of recent federal reports made me do a serious double-take. We’re not talking about some abstract threat that only affects Fortune 500 companies. This hits small businesses, families, regular people who thought they were doing everything right. So I wanted to break down what’s actually happening in the world of digital extortion heading into 2026 - and more importantly, what most people still get wrong about protecting themselves.

The FBI’s 2024 Internet Crime Report landed in April 2025 with alarming statistics. Reported losses from cybercrime topped $16.6 billion last year. That represents a 33% increase from 2023. The Internet Crime Complaint Center received nearly 860,000 complaints, averaging more than 2,000 every single day.

Extortion now ranks among the top three reported cybercrimes in America, sitting right alongside phishing and personal data breaches. The criminals behind these attacks have grown smarter, more organized, and significantly more aggressive in their tactics.

Modern ransomware gangs don’t just encrypt files anymore. They’ve adopted “double extortion” - stealing data first, then encrypting it, then threatening to publish everything online if payment doesn’t arrive. Some groups have moved to “triple extortion,” adding denial-of-service attacks and going after a victim’s customers and business partners simultaneously.

The ransomware industry has expanded from roughly 4 major groups before 2020 to over 95 active groups by late 2024 - a 40% increase from the 68 groups operating in 2023. The business of digital blackmail is booming.

Looking at global projections, cybercrime costs are expected to reach $11.9 trillion in 2026. By 2030, that figure could hit $19.7 trillion, surpassing the current GDP of China. To put this in perspective, if cybercrime were a country’s economy, it would rank third in the world, trailing only the United States and China.

Here’s where things get counterintuitive. When someone’s files are locked and the clock is ticking, paying the ransom feels like the obvious solution. Get the decryption key, restore everything, move on with life. Right?

The 2025 data says otherwise - and the trend has become even clearer.

In Q4 2024, 84% of victims who paid ransoms failed to fully recover their data after the attack. The decryption tools criminals provide are often buggy, slow, or simply don’t work as promised. Sometimes the attackers take the money and disappear entirely. There’s no customer service hotline for cybercrime.

Payment rates have dropped to historic lows. Only 23% to 37% of victims paid ransoms in 2025, down from nearly 50% in 2024. Several factors are driving this shift. First, 97% of organizations can now recover their data from backups, reducing the desperation that leads to payment. Second, cyber insurance providers increasingly refuse to reimburse ransom payments. Third, victims have learned that payment offers no guarantees.

It gets worse for those who do pay. Organizations that hand over money become marked as “willing payers” in criminal circles. Research consistently shows that 80% of companies that paid a ransom got hit a second time. In 70% of those repeat attacks, criminals demanded even more money than before.

The FBI’s position on this remains clear. Paying doesn’t guarantee anything. The agency has documented countless cases where organizations never received a working decryption key after transferring funds.

There’s another wrinkle most people don’t consider. The U.S. Treasury Department’s Office of Foreign Assets Control has sanctioned numerous ransomware groups and the infrastructure providers that support them. In 2025 alone, OFAC took coordinated action with international partners against Russian bulletproof hosting providers like Zservers and Media Land, along with cryptocurrency exchanges that launder ransom payments. Making payments to these sanctioned entities - even as a victim trying to recover your own data - can result in civil penalties from the federal government.

The Colonial Pipeline attack from May 2021 remains one of the most striking examples of how digital extortion spills into the real world. It also demonstrates a pattern that repeats in attack after attack.

Colonial Pipeline supplies about 45% of the fuel consumed on the East Coast. When ransomware hit their systems, the company shut down operations entirely. Gas stations ran dry. Prices spiked to their highest levels since 2014. The President declared a state of emergency.

The entry point for this attack? A single compromised password for an old VPN account that didn’t have multi-factor authentication enabled.

That’s it. No sophisticated zero-day exploit. No inside job. Just one password that had probably been floating around in some data breach for months or years. The attackers used it to walk right in.

Colonial ended up paying nearly $4.4 million in bitcoin within hours of the attack. The decryption tool they received was so slow that they ended up relying more on their own backups anyway. The Department of Justice later recovered about $2.3 million of the ransom, but the damage was done.

This pattern repeats constantly. The Change Healthcare attack in 2024 became the most damaging cyberattack ever reported in the healthcare industry, affecting more than 190 million Americans. In 2025, Yale New Haven Health System experienced a breach affecting over 5.5 million people. Frederick Health in Maryland suffered a ransomware attack impacting nearly 934,000 patients.

Healthcare organizations face particularly brutal targeting. Attackers know these organizations cannot tolerate disruption because patient safety hangs in the balance. In the first nine months of 2025, 293 ransomware attacks hit hospitals, clinics, and other direct care providers. Attacks on healthcare businesses - including pharmaceutical manufacturers, medical billing providers, and health tech companies - rose by 30%.

Two-factor authentication is supposed to be the gold standard for account security. And it is - mostly. But there’s a weakness baked into the system that most people completely ignore.

When setting up 2FA on any account, users typically receive a set of backup codes. These one-time-use codes let you regain access if you lose your phone or authentication device. They don’t expire. They work indefinitely.

From an attacker’s perspective, these codes are a jackpot. If someone finds your backup codes saved in an unencrypted file on your desktop or backed up to cloud storage, they can bypass 2FA entirely. Your password plus one backup code equals full access - as if two-factor authentication never existed.

Security researchers in 2025 documented multiple techniques for exploiting backup code vulnerabilities. These include brute-forcing backup code checks, exploiting improper invalidation of used codes, and stealing codes through cross-site scripting vulnerabilities or misconfigured APIs. If backup codes are generated immediately when 2FA is enabled and remain accessible via an insecure endpoint, attackers who obtain login credentials can pull the codes and bypass protection completely.

Newer attacks like “Salty 2FA” use sophisticated multi-stage phishing that captures both credentials and 2FA codes in real-time, relaying them to attackers who can log in before victims even realize they’ve been compromised.

The recommended solution is surprisingly low-tech. Print out those backup codes and store them in a physical location - a locked safe, a filing cabinet, somewhere completely separate from your digital devices. Never save them in a notes app or a document on your computer.

Come to think of it, when was the last time you checked where your backup codes are stored?

For anyone who becomes a victim of online harassment, threats, or blackmail, proving what happened turns into its own nightmare. Taking a screenshot of a threatening message seems obvious. It’s also often insufficient.

Courts may not accept a screenshot of a single message without context. Victims need to capture entire conversations, often using multiple overlapping screenshots where the last message in one image appears at the top of the next. This creates a continuous record that holds up legally.

Apps like Snapchat create additional problems. Many are designed to notify the sender if you take a screenshot, which could alert the perpetrator and escalate the situation. A safer approach involves using a separate device - another phone or a camera - to photograph the screen.

The perpetrator’s identity needs documentation too. Screenshots should include their profile, username, full profile URL, and any associated phone numbers or email addresses. Without this information, law enforcement can’t connect threatening messages to a real person.

Timestamps matter more than people realize. On an iPhone, swiping left on a message reveals the exact time it was sent. Forwarding an email destroys metadata that might be needed later. Every detail counts when building a case.

The experts at federal agencies like CISA, the NSA, and the FBI all point toward similar defensive strategies. None of them are glamorous. All of them require effort before an attack happens.

Backups remain the single most effective defense against ransomware. The shift in payment rates tells the story - when 97% of organizations can recover their data from backups, the leverage that criminals have disappears. But these backups need to be offline or in immutable storage. Ransomware actively searches for and encrypts or deletes accessible backups. If your backup drive is connected to your network, it’s probably vulnerable.

Recovery speeds have improved significantly. In 2025, 54% of organizations recovered within one week after an attack, compared with just 35% the year before. For healthcare specifically, nearly 60% of providers recovered within one week, up from only 21% previously.

Multi-factor authentication - the phishing-resistant kind - should be enabled everywhere possible. VPNs, email, anything that touches sensitive data. The Colonial Pipeline attack happened because one inactive account lacked this protection.

Network segmentation limits damage when breaches occur. If an attacker gets into one part of a network, proper segmentation prevents them from moving freely to other areas. Think of it like fire doors in a building - they contain the damage.

Regular patching sounds boring, but unpatched systems remain one of the primary ways attackers get in. Internet-facing servers deserve particular attention. A joint advisory issued in late 2025 by the FBI, CISA, and international partners specifically highlighted how the Akira ransomware group exploits unpatched vulnerabilities and misconfigured networks.

User training rounds out the picture. Phishing remains the most common way attackers gain initial access. In 2025, the Anti-Phishing Working Group observed over 1 million phishing attacks in Q1 alone - the highest since late 2023, with nearly 31% targeting financial and payment sectors. Teaching people to recognize suspicious emails, verify unexpected requests, and report potential threats costs relatively little compared to the alternative.

The digital extortion economy feeds on victims who react instead of prepare. Organizations and individuals who wait until an attack happens are already at a disadvantage.

Building real resilience means understanding these threats before they arrive. That includes knowing your vulnerabilities, having tested recovery plans, and creating clear protocols for what happens when something goes wrong.

Interestingly, the data shows progress. Ransom payments dropped 35% to $813 million in 2024. The median ransom demand fell 34% to $1.32 million in 2025. Recovery costs decreased 44% to $1.53 million. Organizations that negotiate are seeing success - 53% of victims who paid in 2025 successfully negotiated a lower amount than the initial demand.

These trends suggest that preparation and resistance work. Attackers are facing a “buyer’s market” where victims hold more leverage than in previous years.

If you’d like to learn more about protecting yourself or your organization from digital threats, the team at Digital Ascension Group can answer questions and point you toward appropriate resources and professionals. Visit DAG.com to start a conversation.

Looking at the patterns behind these attacks, one thing becomes clear. The biggest vulnerabilities are rarely the ones people worry about. They’re the forgotten accounts, the reused passwords, the backup codes saved in convenient places, the assumption that “it won’t happen to me.”

What’s the single weakest link in your own digital life? And what are you going to do about it today?

No posts

Read the original on maxavery.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.