Europol says that free tools provided as part of its three-year-old “No More Ransom” project prevented ransomware gangs from making at least $108M in profits
Context & Ripple Effects
Two years after Europol, Kaspersky, and private partners launched No More Ransom as a joint law enforcement–industry effort, Europol is putting a number on what the project's free decryptors cost attackers: at least $108M in profits gangs never collected because victims recovered their files without paying.
That figure lands in a corpus of escalating Europol counter-ransomware work — from detaining 12 suspects behind attacks on 1,800+ victims across 71 countries to the later multinational disruption of the DoppelPaymer gang, where US victims alone paid out €40M+ — making No More Ransom the prevention layer alongside the arrest-driven enforcement track.
First-order effects
- Victims infected with ransomware strains covered by the portal's free decryptors now have a no-cost alternative to paying, directly cutting into gang revenue on those families.
- Europol gains a measurable success metric for the public-private model, strengthening the case for partners like Kaspersky to keep contributing decryption tools.
Second-order effects
- Gangs face pressure to rotate to strains without published decryptors or to lean harder on data theft and extortion, since stolen-data leverage survives a free decryption tool.
- Ransomware operators' real economics stay visible despite the prevention win — McAfee tracked NetWalker alone pulling ~$25M in payments in months — so enforcement partners keep pursuing takedowns alongside the tooling.
Third-order effects
- If the pattern holds, counter-ransomware settles into a two-front structure: free decryption eroding payment incentives while coordinated police operations target the gangs themselves, shifting the market toward extortion models that decryption cannot defuse.
- The No More Ransom template — law enforcement plus security vendors sharing tools publicly — points toward prevention becoming a standing part of cybercrime response rather than ad-hoc incident handling.
The trend: Counter-ransomware is institutionalizing as a combined prevention-plus-enforcement effort, with Europol pairing public decryptor libraries with multinational gang takedowns to squeeze attacker profits from both sides.