Ransomware groups expanded and adapted their operations in the first half of 2024, according to Rapid7’s analysis released alongside Black Hat USA. But the evidence does not show that every gang’s profits kept rising: attack activity, ransom demands, payments, victim recovery costs, and criminal net profit are different measures. Later U.S. Treasury data recorded lower BSA-reported ransomware payments in 2024 than in 2023.
What Black Hat 2024-era reporting found
Rapid7 released its Ransomware Radar Report on August 6, 2024, alongside its Black Hat USA presence. The report examined attacker activity over the 18 months ending June 30, 2024. Its findings point to an active, changing criminal ecosystem—not a complete count of all ransomware attacks or a ledger of gang profits.
- Rapid7 identified 21 new ransomware groups in the first half of 2024, including rebrands.
- It counted 2,611 leak-site posts by 68 groups from January through June 2024, 23% more than in the first half of 2023. A post represents an extortion attempt in Rapid7’s analysis; it does not establish that the victim paid.
- RansomHub made 181 leak-site posts between February 10 and June 30, 2024, according to Rapid7.
- Rapid7 observed an average of 40 groups posting to leak sites per month in the first half of 2024, compared with 24 per month in the first half of 2023.
These figures describe Rapid7’s observed leak-site activity and definitions. Posts, groups, and incidents are not interchangeable: a single attack may lead to multiple posts, and attacks that are not publicly disclosed may not appear in leak-site tracking.
How ransomware groups adapted their operations
Rapid7 described practices that make parts of the ecosystem look like a business network: groups marketing services to prospective buyers, offering commissions to insiders who provide access, and running bug bounty programs. Its analysis also identified three clusters of ransomware families with similar source code, which Rapid7 interpreted as a move toward more specialized variants. These are findings about the activity it analyzed, not verified traits of every criminal group.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
Ransomware-as-a-service (RaaS) arrangements can divide work among operators and affiliates, while rebrands and affiliate movement make group labels hard to treat as stable entities. A group’s public name or leak site can change without providing a straightforward measure of how many people are involved or how much money they retain.
A July 2024 Black Hat MEA overview discussed LockBit, 8Base, and Phobos. It described double extortion—stealing data as well as encrypting it—and noted 8Base’s name-and-shame tactics and Phobos’s use of RaaS tools. The overview said LockBit’s infrastructure was seized in February 2024 and that the group resumed activity soon afterward. That is a dated account, not a statement of those groups’ current status.
What the reported numbers measure
Several widely cited ransomware figures cover different populations, periods, and collection methods. They can all be useful without forming one continuous trend line.
| Source and period | What was counted | Reported result |
|---|---|---|
| Rapid7, January–June 2024 | Leak-site posts and groups in Rapid7’s analysis | 2,611 posts by 68 groups; 23% more posts than in the first half of 2023 |
| Black Kite Research Group, April 2023–March 2024 | Confirmed victim announcements tracked by Black Kite | 4,893 announcements, compared with 2,708 in the preceding year |
| FinCEN, January 2022–December 2024 | Ransomware incidents and payments reported through financial institutions’ Bank Secrecy Act filings | 4,194 incidents and more than $2.1 billion in reported payments |
| Sophos 2024 survey, as summarized by Black Hat MEA | Survey responses from organizations about ransom payments and recovery costs | $2 million average ransom payment among surveyed organizations and $2.73 million average recovery cost |
Black Kite’s figures come from its 2024 ransomware threat landscape report. Tracked victim announcements are not a census of all attacks. The Sophos figures were summarized in a July 2024 Black Hat MEA article; they are survey averages, not amounts that every victim paid. Differences among these results reflect what each source tracked, as well as different time windows.
Do ransomware gangs’ profits keep growing?
“Profit” is stronger than the available evidence supports. A ransom demand is what a criminal requests; a payment is what a victim actually sends; neither establishes what an operator keeps after costs, affiliate shares, unpaid demands, or seized funds. Recovery costs are expenses borne by victims, not revenue earned by attackers.
FinCEN’s 2025 financial trend analysis says BSA reports covered 4,194 ransomware incidents and more than $2.1 billion in payments from January 2022 through December 2024. The reported payment total was $1.1 billion in 2023 and $734 million in 2024. FinCEN said incidents and payments fell in 2024 following law-enforcement disruption of two prominent groups. These are payments reported through financial institutions’ filings, not a global account of criminal revenues or net profit.
Rank #4
The survey numbers answer a different question. Black Hat MEA’s July 2024 summary of Sophos’s State of Ransomware 2024 survey reported an average ransom payment of $2 million among surveyed organizations, compared with $400,000 in 2023, and an average recovery cost of $2.73 million. A higher survey average does not mean every victim paid more, nor does it contradict a lower total in a separate dataset: the figures describe different measures and populations.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What this means for organizations and personal finances
For an organization, the distinction between the ransom and the full cost of an incident matters. Even when no ransom is paid, restoring systems, investigating an intrusion, and responding to operational disruption can create substantial expenses. The survey’s recovery-cost figure is a respondent average, not a forecast for any one business.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesBest Value
For individuals, business ransomware can still have indirect financial consequences when an affected organization holds personal or payment data. Public victim announcements and leak-site posts may indicate exposure, but they do not by themselves confirm which personal information was accessed or whether a particular person is at risk. Follow notices from the affected organization and relevant financial institutions, and use the specific protective steps they recommend.
Organizations assessing their own exposure can consider incident-response support and business backup and disaster-recovery planning. Those are broad preparedness categories, not guarantees against an attack or a substitute for evaluating a provider’s specific capabilities.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




