How cloud computing, AI, and geopolitics could shape the evolution of ransomware, which could cost victims $265B annually by 2031, as the AIDS Trojan turns 35
Ransomware is now a billion-dollar industry. But it wasn't always that large — nor was it a prevalent cybersecurity risk like it is today. Bluesky: @michae.lv . LinkedIn: Ryan Browne Bluesky: Michael Veale / @michae.lv : on AI and ransomware - CNBC has commentary that it's a bit overblown because it's the simplest social engineering that is often the most successful. i agree! but the q is how simple AI helps social engineering scale, not how complex AI attacks outthink & outwit ppl. www.cnbc.com/2024/12/30/r... LinkedIn: Ryan Browne : It's been 35 years since the first ransomware attack - and the technology has come a long way. — Now one of the most common forms of cyberattack …
Context & Ripple Effects
Ransomware coverage has traced a shift from dispersed, smaller extortion payments to fewer, higher-value targets, while reporting in 2021 described gangs operating with global-scale budgets. The 35-year marker puts today’s discussion of cloud, AI, and geopolitical forces in a much longer arc of adaptation.
The article tempers claims that AI will autonomously outsmart victims: its more immediate relevance may be scaling the simple social engineering that already works. That distinction matters as the threat’s economic exposure continues to be framed in increasingly large terms.
First-order effects
- Victims and security teams face a threat model in which cloud infrastructure, AI-enabled workflows, and geopolitical conditions may alter how campaigns are delivered and propagated.
- The cited $265 billion annual-cost projection raises the stakes for organizations whose defenses still center on preventing individual intrusions rather than limiting the damage from a successful one.
Second-order effects
- If AI scales convincing but routine social engineering, defenders will need to prioritize identity verification, employee-facing controls, and rapid containment—not only detection of technically sophisticated malware.
- Cloud providers and enterprise security vendors may face greater pressure to make abuse prevention, recovery, and cross-environment visibility operationally usable for customers, especially against well-resourced ransomware operations.
Third-order effects
- If these enablers continue to reduce the effort needed to run campaigns, ransomware could become less defined by novel malware and more by the industrialization of access, persuasion, extortion, and recovery disruption.
- The pattern points toward cybersecurity becoming more entangled with infrastructure governance and geopolitical risk, although the article does not establish how much AI or cloud services will contribute relative to established attack methods.
The trend: Ransomware is evolving from a malware problem into an infrastructure- and influence-enabled extortion economy, where scalable social engineering may matter as much as technical novelty.