South Korean web host Nayana agrees to $1M extortion fee after 153 servers hit by ransomware, after negotiating the sum down from ~$1.6M
Alfred Ng / CNET :
Context & Ripple Effects
Nayana's seven-figure payment marks how far ransomware economics have moved in a year: when Cisco tallied the market in mid-2016, the average ransom was about $300 across roughly 9,500 monthly payers. Nayana negotiating from ~$1.6M down to $1M shows attackers now price against what a specific victim's downtime is worth, not a flat fee.
It also extends a pattern set by Hollywood Presbyterian Medical Center, whose network sat down for over a week under a $3.6M demand — proof that organizations with revenue tied to uptime will pay rather than rebuild.
First-order effects
- Nayana hands over $1M to get 153 servers decrypted, and every customer site hosted on those machines is hostage to how quickly the attackers actually deliver working keys.
- The negotiation itself confirms the attackers' pricing model: they opened at ~$1.6M knowing a web host's entire book of business rides on restoration speed.
Second-order effects
- A paid, publicized seven-figure ransom is market signal: it tells ransomware crews that hosting providers — single points of failure for thousands of downstream sites — are premium targets worth bespoke pricing.
- Every dollar flows back into operator capacity; the same cash-out pipeline later documented for Ryuk's estimated $150M+ in Bitcoin shows how one big score compounds into sustained campaigns.
Third-order effects
- If the pattern holds, ransomware splits into two markets — commodity attacks at hundreds of dollars and 'big game' strikes on infrastructure priced in millions — which is exactly the split visible by 2020, when CrowdStrike found 27% of hit organizations paid an average of ~$1.1M.
- Structurally, victims' willingness to pay shifts security spending toward offline backups and incident response, because the alternative — negotiating with attackers who hold your revenue — is now a proven, repeatable business model.
The trend: Ransomware is scaling from mass-market attacks averaging a few hundred dollars to targeted strikes on infrastructure operators who command seven-figure ransoms.