Conti was the most corporate ransomware operation of its era — payroll, HR, R&D, the works — until an internal leak in 2022 exposed the entire enterprise and its political alignment. Here is how it grew, how it operated, and how it collapsed into a network of successor brands.
Jesse William McGraw
LockBit was the most prolific ransomware operation in history, running an industrialised RaaS program with the world’s fastest encryptor — until Operation Cronos shredded its infrastructure in early 2024.
Ransomware-as-a-Service turned ransomware from a craft into a franchise. Core developers write the malware, affiliates run the intrusions, and revenue is split. Here is how RaaS works, who plays which role, and why it has been so hard to disrupt.
Not all ransomware is alike. Crypto-ransomware, lockers, scareware, leakware, doxware, wipers — each works differently and demands a different defensive response. A practical taxonomy.
A ransomware attack is a weeks-long intrusion that ends in encryption, not a single event. The ten stages from initial access to extortion, the tools used at each, how long it takes, and where defenders can break the chain.
Ransomware did not start with Bitcoin. It started in 1989, on floppy disks mailed to AIDS researchers, and spent thirty years evolving into the multibillion-dollar criminal industry we know today.
Ransomware is malware that locks organisations out of their data and demands payment, and in its modern form steals the data first. What it is, how an attack unfolds, who gets hit, what it costs and why fewer victims pay, with live figures from 9,500 confirmed attacks.