/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Ransomware payments in 2023 hit a record $1.1B, up from $567M in 2022 and $983M in 2021, after a major escalation of the frequency, scope, and volume of attacks

The Chainalysis 2024 Crypto Crime Report  —  Coming soon  —  In 2023, ransomware actors intensified their operations …

Chainalysis

Context & Ripple Effects

The 2023 total reverses the prior year’s lower estimate, when Chainalysis reported at least $457M in 2022 ransomware payments amid greater victim resistance to paying. It also follows a multi-year expansion from the $350M recorded for 2020.

The record payment pool matters because it coincided with more frequent, broader, and higher-volume attacks. Contemporaneous reporting also showed ransom demands and reported victim losses rising in the first half of 2023, indicating that attackers were increasing both operational activity and the value sought from victims.

First-order effects

  • Ransomware operators captured a record $1.1B in on-chain payments in 2023, improving the near-term economics of campaigns as attack activity escalated.
  • Victims faced a more costly threat environment, with the higher payment total reflecting a larger volume and scope of successful extortion events.

Second-order effects

  • Organizations, insurers, and incident-response providers face stronger pressure to reduce the chance that an intrusion becomes a payable extortion event, rather than treating ransom payment as a dependable recovery path.
  • The rebound challenges the 2022 narrative that payment refusal alone would durably constrain attacker revenues; defenses and recovery readiness become more consequential alongside non-payment policies.

Third-order effects

  • Ransomware is evolving into a volatile but persistent cybercrime market: payment totals can fall or rise with victim behavior and attacker tactics, while attackers retain incentives to adapt their targeting and demands.
  • If elevated attack volume continues, scrutiny of the crypto pathways used to receive and move extortion proceeds is likely to remain part of the broader debate over falling 2024 ransomware payments and cybercrime disruption.

The trend: This is one data point in ransomware’s shift toward adaptive, high-pressure extortion operations whose revenues depend on both attack scale and victims’ willingness or ability to pay.