Inside “No More Ransom”, a joint law enforcement and private industry effort to fight cybercrime, launched by Europol, Kaspersky, and others last year
No More Ransom launched a year ago: here's the story of how cybersecurity firms and law enforcement are working together to bring down ransomware.
Context & Ripple Effects
When Europol, Kaspersky and their partners launched No More Ransom, the bet was that free decryption tools could break the pay-or-lose-your-data logic that made ransomware profitable. Two years on, Europol credited those tools with blocking at least $108M in would-be gang profits — evidence the decryptor-first model works at scale.
The initiative also normalized something rarer: cybersecurity vendors sharing intelligence with police. That template shows up repeatedly in later coverage, from the DOJ's internal ransomware taskforce memo to the multi-country disruption of DoppelPaymer operators and the 11-nation seizure of LockBit infrastructure.
First-order effects
- Ransomware victims gain a no-cost alternative to paying: if their strain is covered by one of the project's decryption tools, law enforcement and vendors can restore files without a ransom changing hands.
- Ransomware gangs lose guaranteed revenue from every victim who finds a working decryptor instead of paying, directly shrinking the economics that fund further attacks.
Second-order effects
- Competing security firms that once guarded threat data as proprietary now face pressure to join shared-intelligence efforts like this one, since withholding samples leaves victims — and reputations — exposed.
- The demonstrated success of vendor-police cooperation pushes governments toward standing structures rather than ad-hoc alliances, visible in the DOJ taskforce and the 60-plus-expert task force urging US and allied action.
Third-order effects
- If the pattern holds, anti-ransomware work consolidates around ecosystem-wide defense: not just decrypting victims but jointly attacking the gangs' infrastructure, payments, and laundering channels across jurisdictions.
- Ransomware stops being treated as an unavoidable cost of doing business online and becomes a target for sustained, coordinated disruption — shifting leverage from attackers toward defenders over time.
The trend: Ransomware response is evolving from isolated victim payments to standing public-private coalitions that combine free decryption with cross-border takedowns.