US Treasury Department report: in H1 2021, financial firms flagged ~$600M in suspected ransomware payments out of an estimated $5.2B in such payments
Financial firms flagged nearly $600 million in suspected ransomware payments; Treasury investigators identified billions more
Context & Ripple Effects
The headline number lands on top of coverage from two days earlier, when the Treasury reported $590M in suspicious ransomware activity in H1 2021 — already more than the $416M reported for all of 2020. What this report adds is the denominator: against an estimated $5.2B actually paid, flagged flows are barely a tenth of the market.
That gap matters because suspicious-activity reports are the government's primary window into ransomware finance. The trajectory since has confirmed the scale problem: FinCEN later counted ~$1.2B in likely ransomware payments processed by US firms in 2021 alone, and Chainalysis put 2023 at a record $1.1B before payments fell in 2024.
First-order effects
- US banks and money-services businesses now carry documented evidence that their ransomware filings cover roughly a tenth of estimated flows, putting their SAR programs directly in Treasury's crosshairs.
- Treasury gains a quantified baseline it can use to justify tightening ransomware-related AML expectations on the financial firms doing the flagging.
Second-order effects
- Compliance teams will be pushed to detect ransomware proceeds further downstream — into exchanges and conversion points — since the flagged $600M implies most payments reach cash-out without being caught.
- Insurers and incident responders face pressure as payment behavior becomes a policy variable; the corpus shows victims' refusal to pay later drove a 35% drop in 2024 receipts (down to ~$813.55M from 2023's record), shifting the economics attackers rely on.
Third-order effects
- If the pattern holds, ransomware becomes an AML-enforcement problem rather than purely a cybercrime one, with Treasury using payment-flow data to target laundering infrastructure — consistent with its later sanctions posture against crime-linked networks.
- Structurally, the market peaks when victims stop paying: the arc from 2019's rising per-attack averages (~$84K in Q4 2019) through the 2023 record to the 2024 decline suggests the industry's ceiling is set by victim willingness, which regulation aims to suppress further.
The trend: Ransomware is being pulled into the anti-money-laundering regime, with Treasury using the widening gap between flagged and actual payments to justify stricter reporting duties on financial firms.