The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →The U.S. Treasury’s Financial Crimes Enforcement Network (FinCEN) says Bank Secrecy Act reports reflected approximately $4.5 billion in ransomware payments from 2013 through 2024. That is not a worldwide total of every ransom paid. It is the amount visible in financial reports submitted to FinCEN, making it a documented measure of reported activity rather than a complete count of ransomware losses.
What the $4.5 billion figure counts
FinCEN compiles information from Bank Secrecy Act (BSA) reports filed by financial institutions and other covered businesses. The reports can identify transactions associated with ransomware incidents, including payments made through banks, virtual-asset services and other financial channels.
The approximately $4.5 billion total covers reports received for the period 2013 through 2024. Treasury did not directly observe every ransom payment worldwide, and the figure does not include payments that never appeared in the reporting system or activity outside its coverage.
- It is a cumulative total reflected in BSA reporting.
- It is not a census of all victims, attacks or payments.
- It should not be described as total global ransomware damage.
How the recent years compare with the earlier period
FinCEN’s December 2025 analysis separated the newer three-year period from the earlier years. More than $2.1 billion in reported payments was associated with 2022–2024, compared with approximately $2.4 billion reported from 2013 through the end of 2021.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
| Reporting period | Reported ransomware payments | What the figure represents |
|---|---|---|
| 2013–2021 | Approximately $2.4 billion | Payments reflected in FinCEN reports through the end of 2021 |
| 2022–2024 | More than $2.1 billion | Payments associated with the incidents reviewed by FinCEN for these three years |
| 2013–2024 | Approximately $4.5 billion | Cumulative amount reflected in the reported data across both periods |
The periods are different lengths, and changes in reporting volume and coverage affect the totals. The figures show the scale of reported financial activity, but they do not by themselves prove that worldwide ransomware activity increased in exactly the same proportion.
What happened in 2022, 2023 and 2024
For 2022–2024, FinCEN analyzed 7,395 reports associated with 4,194 incidents. Those counts are reports and identified incidents, not necessarily unique victims or a complete attack count.
| Year | Reported payments | Qualification |
|---|---|---|
| 2023 | Approximately $1.1 billion | The high point of the three-year period in FinCEN’s reported data |
| 2024 | Approximately $734 million | Reported amount for that calendar year |
| 2022 | Not stated separately in the cited summary | Included in the more-than-$2.1 billion 2022–2024 total |
Treasury’s 2026 National Money Laundering Risk Assessment restates the recent scale as nearly 7,400 reports, nearly 4,200 incidents and nearly $2.1 billion in payments for 2022–2024. The rounded numbers describe the same review period and should not be added to the earlier figures again.
Why Treasury treats ransomware payments as a financial-crime issue
Ransomware is not only a cybersecurity problem. Criminal groups use financial institutions, digital-asset exchanges, mixers and other service providers to receive, convert and move proceeds. Those channels create risks involving money laundering, sanctions evasion and the financing of illicit networks.
Rank #3
Ransomware-as-a-service
Treasury describes ransomware-as-a-service as a business model in which administrators supply malware and supporting infrastructure to affiliates. Affiliates find and attack targets, then share ransom proceeds with the administrators. The arrangement allows specialized criminal roles—such as access brokers, malware operators and negotiators—to work together without belonging to one organization.
Digital assets and payment routes
Digital assets can be used to request or receive ransom, transfer value between jurisdictions and attempt to conceal proceeds. A cryptocurrency transaction is not automatically anonymous; exchanges and other regulated providers may hold identifying and transaction records, and those records can become part of financial investigations.
Rank #4
How FinCEN reporting and sanctions guidance differ
FinCEN reporting requirements and the Office of Foreign Assets Control (OFAC) sanctions guidance address related but different risks.
- FinCEN: collects and analyzes suspicious-activity and other BSA reports to help identify illicit financial flows.
- OFAC: warns that facilitating a ransomware payment can create sanctions exposure when a designated person, group or jurisdiction is involved.
Treasury’s coordinated 2021 actions included an updated FinCEN ransomware advisory and OFAC guidance. Anyone handling a current incident should consult the latest official advisories and obtain qualified legal and incident-response advice; the 2021 materials are historical policy context, not a substitute for current compliance guidance.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
What the number means for households and small businesses
The headline does not mean an individual household owes part of a $4.5 billion loss, nor does it establish how much any particular victim paid. It does show why ransomware remains a serious operational and financial risk: payments can be routed through complex channels, and a victim may face legal, sanctions and recovery issues in addition to the cost of restoring systems.
For personal-finance readers, the practical lessons are defensive:
- Keep offline or otherwise isolated backups so a locked device is not the only copy of important records.
- Use multifactor authentication, especially for email, cloud storage and financial accounts.
- Update operating systems, browsers, routers and security software promptly.
- Do not assume that paying guarantees decryption, prevents data publication or ends an attack.
- If an incident occurs, preserve messages and wallet or bank details, contact law enforcement and notify relevant financial institutions quickly.
How to read future Treasury ransomware statistics
When Treasury or FinCEN publishes a new total, check four details before comparing it with another headline:
- Time period: confirm the start and end dates.
- Reporting basis: determine whether the figure comes from BSA reports, another survey or an estimate.
- Unit being counted: distinguish dollars, reports, incidents and victims.
- Rounding and coverage: note whether the number is approximate and whether reporting changes could affect the trend.
Using those checks, the accurate reading of Treasury’s headline is straightforward: approximately $4.5 billion in ransomware payments appeared in FinCEN’s covered financial-reporting data from 2013 through 2024, with more than $2.1 billion tied to the 2022–2024 review period. It is a substantial documented total, but not a complete worldwide accounting of ransomware payments.
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




