/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

South Korean web host Nayana agrees to $1M extortion fee after 153 servers hit by ransomware, after negotiating the sum down from ~$1.6M

Alfred Ng / CNET :

CNET Alfred Ng

Context & Ripple Effects

Nayana's seven-figure payment marks how far ransomware economics have moved in a year: when Cisco tallied the market in mid-2016, the average ransom was about $300 across roughly 9,500 monthly payers. Nayana negotiating from ~$1.6M down to $1M shows attackers now price against what a specific victim's downtime is worth, not a flat fee.

It also extends a pattern set by Hollywood Presbyterian Medical Center, whose network sat down for over a week under a $3.6M demand — proof that organizations with revenue tied to uptime will pay rather than rebuild.

First-order effects

  • Nayana hands over $1M to get 153 servers decrypted, and every customer site hosted on those machines is hostage to how quickly the attackers actually deliver working keys.
  • The negotiation itself confirms the attackers' pricing model: they opened at ~$1.6M knowing a web host's entire book of business rides on restoration speed.

Second-order effects

  • A paid, publicized seven-figure ransom is market signal: it tells ransomware crews that hosting providers — single points of failure for thousands of downstream sites — are premium targets worth bespoke pricing.
  • Every dollar flows back into operator capacity; the same cash-out pipeline later documented for Ryuk's estimated $150M+ in Bitcoin shows how one big score compounds into sustained campaigns.

Third-order effects

  • If the pattern holds, ransomware splits into two markets — commodity attacks at hundreds of dollars and 'big game' strikes on infrastructure priced in millions — which is exactly the split visible by 2020, when CrowdStrike found 27% of hit organizations paid an average of ~$1.1M.
  • Structurally, victims' willingness to pay shifts security spending toward offline backups and incident response, because the alternative — negotiating with attackers who hold your revenue — is now a proven, repeatable business model.

The trend: Ransomware is scaling from mass-market attacks averaging a few hundred dollars to targeted strikes on infrastructure operators who command seven-figure ransoms.