/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

FinCEN: US financial firms processed ~$1.2B in likely ransomware payments in 2021, up almost 3x YoY; ~75% of H2 2021 ransomware incidents were linked to Russia

- U.S. banks and financial institutions processed more than $1 billion in potential ransomware-related payments in 2021.

CNBC Chelsey Cox

Context & Ripple Effects

FinCEN's full-year figure closes out an escalation the Treasury had already flagged mid-year: its $590M in H1 2021 suspicious-activity reports alone exceeded all of 2020's $416M, and the year-end total of ~$1.2B lands near triple the prior year. The new detail is attribution — roughly three-quarters of second-half incidents traced to Russia, which converts a fraud-statistics story into a sanctions-enforcement one.

The payment rail matters as much as the total: these are flows moving through US-regulated financial institutions, which is why FinCEN can see them at all. Later blockchain-forensics data confirmed the arc — a record $1.1B paid in 2023 before a 35% drop in 2024 as more victims refused to pay — making this 2021 report the baseline against which both the peak and the retreat were measured.

First-order effects

  • US banks and financial institutions now carry the compliance burden: every likely ransomware payment they process becomes a reportable event feeding FinCEN's dataset, raising screening and reporting obligations on crypto-touching transactions.
  • Russia-linked ransomware crews move to the top of US enforcement priorities, giving Treasury and FinCEN a data-backed case for targeting the wallets, exchanges, and intermediaries that cash out their proceeds.

Second-order effects

  • Crypto exchanges and payment processors serving US customers face tightened KYC and transaction monitoring, since the same rails that make ransomware traceable also expose them to penalties for processing it.
  • Insurers and corporate victims gain leverage from the published totals: with payment volumes this visible, underwriters and regulators can price or discourage paying ransoms rather than treating each incident as private.

Third-order effects

  • Ransomware stops being an IT-cost line item and hardens into a national-security finance problem, where the response runs through sanctions, AML enforcement, and cross-border pressure on safe-haven jurisdictions like Russia.
  • If victim refusal keeps rising the way the 2024 data suggests, the criminal business model shifts from volume-of-payments to extortion-without-payout — pressuring the ecosystem toward disclosure mandates and recovery-by-enforcement instead of negotiation.

The trend: Ransomware is consolidating around Russia-linked operators whose proceeds flow through regulated financial rails, turning payment-tracking agencies like FinCEN into the primary instrument of US counter-ransomware policy.

Discussion

  • @johnnysaks130 John Sakellariadis on x
    3) Curious for some reactions to FINCEN's linking 75% of all attacks to Russian groups. There is clearly a Russia problem, yes. But the criteria for that “attribution” is pretty unscientific (Russian-language code, advertised on Russia forums or CIS keyboard locks). Thoughts?
  • @ericgeller Eric Geller on x
    Banks reported nearly $1.2b in potential ransom payments to the Treasury Department in 2021, more than double the amount reported in 2020, per a new FinCEN report. https://www.fincen.gov/... Russian ransomware strains accounted for 58% of those involved in reported incidents. htt…
  • @johnnysaks130 John Sakellariadis on x
    Amid the flashy numbers in the new FINCEN report on 2021 ransom payments, I want to highlight three things: 1) the 1.2Bn figure is *reported* payments last year, many of which back to 2020. In part, it's actually a good news story about reporting! https://www.fincen.gov/...
  • @swagitda_ Kelly Shortridge on x
    Ok so U.S. banks processed ~$1.2bn in ransomware payments in 2021. How much did they process in payments to anti-ransomware vendors? What about pen test payments? Ransomware is the big, scary threat invoked by infosec to fund and reify the panopticon and... only $1.2bn? Ok. https…
  • @johnnysaks130 John Sakellariadis on x
    2) Why the reporting uptick, you ask? No surprises there: the second half of 2021 was effectively the world post-Colonial Pipeline, when ransomware became a household term. To boot, FINCEN issued some new reporting guidance in the second half of the year.
  • @serghei Sergiu Gatlan on x
    “In 2021, FinCEN received 1,489 ransomware-related filings worth nearly $1.2 billion, a 188 percent increase compared to the total of $416 million for 2020.” Press release: https://www.fincen.gov/... FinCEN's analysis: https://www.fincen.gov/... https://twitter.com/...