Ransomware can persist because attackers adapt their economics faster than other criminal groups. The report links 2023 growth to a return of big game hunting, more small attacks, and larger extortion demands. Even when overall crypto crime drops, ransomware can stay profitable if victims still pay and operators can target both small and large organisations.
Why Ransomware Stays Resilient When Broader Crypto Crime Falls
Ransomware is not dependent on the same economics as every other crypto-related crime. If markets, laundering pressure, or law-enforcement disruption reduce one criminal revenue stream, ransomware crews can still pivot because they monetise direct business disruption. That makes the model durable: it can keep generating payments through extortion even when other crime types become less attractive.
The persistence problem is the business model itself. Ransomware does not need every campaign to succeed, only enough victims to pay, and it can adjust pressure by targeting data theft, encryption, or public leak threats. This adaptability is why the category can remain profitable while other forms of crypto crime contract.
Where payments continue, attackers can tune their tactics to the victim profile, for example by running many small incidents or concentrating on high-value organisations that can absorb larger demands. That flexibility gives ransomware a wider operating range than crime types that rely on a narrower technical or market window.
What Keeps the Extortion Economy Working
The economics of ransomware are strengthened by repeatable leverage, not by one-off technical advantage. As long as encryption disrupts operations, stolen data creates reputational pressure, and backups or recovery paths are uncertain, the attacker has multiple ways to force a decision. The report’s pattern of big game hunting alongside smaller attacks reflects that the model scales in both directions.
One useful NHIMG data point here is that NHI Mgmt Group’s Ultimate Guide to Non-Human Identities reports 79% of organisations have experienced secrets leaks, and 77% of those incidents caused tangible damage. That matters because ransomware operators often benefit from weak credential and secrets hygiene before the extortion stage, especially when initial access and lateral movement are enabled by poor control over privileged material.
Victim payment behaviour also shapes persistence. If organisations continue to pay, or if attackers believe they can create enough operational pressure to make payment likely, the criminal market remains viable even when broader crypto theft is less productive. That is why ransomware resilience is better understood as a coercion business model than as a pure financial crime trend.
Risk and Threat Considerations
Ransomware remains persistent because its payoff is tied to immediate operational harm, not only to the wider state of crypto crime. Even if other criminal categories fall due to enforcement or market shifts, a single successful extortion campaign can still justify the effort for attackers.
Failure mechanism: Attackers keep adapting access, targeting, and extortion pressure faster than defenders can reduce willingness to pay, restore quickly, and close common entry paths. That lets the model survive downturns in adjacent criminal markets.
Impact: Organisations face continued exposure to encryption, data theft, service disruption, and repeat extortion attempts, especially when attackers can choose between high-volume low-value targets and larger organisations with deeper pockets.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC — Access Control | Ransomware persistence is often enabled by weak access control and lateral movement paths. |
| RC — Recovery | Rapid recovery reduces the attacker’s extortion leverage and payment pressure. | |
| Recommendation — Tighten access paths to reduce initial compromise and lateral spread. Test restore capability so recovery is faster than extortion escalation. | ||
| CIS Controls v8 | CIS Control 8 — Audit Log Management | Detection and investigation of ransomware activity depend on usable logging. |
| CIS Control 11 — Data Recovery | Recovery quality directly affects whether ransomware can force payment. | |
| CIS Control 6 — Access Control Management | Overly broad access makes ransomware movement and impact easier. | |
| Recommendation — Centralise and retain logs to detect ransomware staging and impact quickly. Maintain and test offline backups to preserve recovery options after encryption. Remove excess access to limit ransomware reach after initial compromise. | ||
| MITRE ATT&CK | T1486 — Data Encrypted for Impact | This is the core ransomware impact technique. |
| T1490 — Inhibit System Recovery | Ransomware often disables recovery paths to increase extortion leverage. | |
| T1485 — Data Destruction | Some ransomware operations threaten destruction to intensify coercion. | |
| Recommendation — Map detections to T1486 and alert on mass file encryption behaviour. Hunt for backup deletion, shadow copy removal, and recovery suppression. Detect destructive actions that convert extortion into irreversible loss. | ||
Practitioner Guidance
What to prioritise: Treat ransomware as an operational continuity problem as much as a malware problem. If recovery is slow, uncertain, or dependent on the attacker’s goodwill, the extortion model remains viable regardless of broader crypto-crime trends.
What to verify: Validate that the path from initial compromise to recovery is measurably shorter than the attacker’s ability to escalate pressure. In practice that means testing backup integrity, restore speed, and whether critical systems can be rebuilt without reusing compromised access paths.
What practitioners underestimate: Ransomware groups do not need stable market conditions to persist, they need only flexible monetisation. The most important defensive question is not whether ransomware is profitable in the abstract, but whether your organisation’s recovery posture makes payment seem like the fastest option.
Practitioner takeaway: The persistence of ransomware comes from adaptable coercion, so the defensive goal is to reduce the attacker’s leverage, not just to reduce exposure to initial access.
Related resources from NHI Mgmt Group
- Why do open vulnerabilities remain a persistent risk even when organisations have standard security tooling?
- Why does employee negligence remain such a persistent security risk even when staff understand their role?
- Why do bots remain such a persistent fraud risk even as AI agents become more capable?
- Why do leaked secrets remain such a persistent NHI risk?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org