Trend Micro: ransomware grew 752% in 2016 and generated $1B in revenue
John Leyden / The Register :
Context & Ripple Effects
Trend Micro's 2016 tally was one of the first attempts to size ransomware as a business rather than a nuisance: 752% year-over-year growth and roughly $1B in criminal revenue. At the time there was no on-chain ledger to audit, so vendor telemetry was the best instrument available.
The measurement problem has since been solved from the other direction. Chainalysis began tracking actual ransomware payments on-chain in 2020, and its series now brackets this early estimate: payments climbed through a record $1.1B in 2023 before falling back as victims stopped paying.
First-order effects
- For defenders in 2016, the 752% growth figure reframed ransomware from scattered extortion into a scaled revenue business, forcing security budgets and incident planning to treat it as a primary threat rather than one malware category among many.
Second-order effects
- The criminal revenue pool attracted an adjacent financial ecosystem: by H1 2020 ransomware accounted for 41% of cyber insurance claims filed, with average ransom demands up 47%, and companies disclosed it in 1,000+ SEC filings as a material risk factor.
Third-order effects
- The economics have since inverted against attackers: Chainalysis counted receipts falling to ~$457M in 2022 and down another 35% in 2024 from 2023's record, driven by more victims refusing to pay — suggesting the market may be structurally shrinking even where attack volume persists.
The trend: Ransomware has moved from explosive criminal growth, when vendors like Trend Micro first sized it at $1B, to a measured decline in payouts as victim non-payment reshapes its economics.