The ransomware industry grew in 2023 as it saw a worrying 55.5% increase in victims worldwide, reaching 5,070. But 2024 is starting to paint a very different picture. While the numbers skyrocketed in Q4 2023 with 1309 cases, in Q1 2024, the ransomware industry declined to 1,048 cases. This is a 22% decrease in ransomware attacks compared to Q4 2023.

There may be several reasons for this significant drop.
Reason 1: Law enforcement intervention#
First, law enforcement stepped up in 2024 with actions against both LockBit and ALPHV.
The LockBit# arrests
In February, an international operation dubbed “Operation Cronos” resulted in the arrest of at least three associates of the notorious LockBit ransomware syndicate in Poland and Ukraine.
Law enforcement agencies from multiple countries worked together to take down LockBit’s infrastructure. This included seizing their dark web domains and gaining access to their support systems. Authorities seized cryptocurrency accounts and obtained decryption keys to help victims recover data. They also used Lockbit’s website to publish internal data about the group itself.
Ukraine's cyber police revealed that they had arrested a "father and son" duo allegedly linked to LockBit, whose activities allegedly affected individuals, businesses, government entities and healthcare in France.
During searches of the suspects' residences in Ternopil, Ukraine, law enforcement authorities seized mobile phones and computer equipment suspected of being used in cyberattacks.
In Poland, authorities arrested a 38-year-old man in Warsaw, suspected of being associated with LockBit. He was brought before the prosecutor and charged with criminal offenses.
However, LockBit resurfaced within a week, highlighting the ongoing challenges of fighting cybercrime.
Shortly thereafter, the group continued its global assault on organizations, maintaining its position as a dominant force in ransomware operations. This resilience underscores the group’s formidable strength and capabilities, as well as the robust security measures surrounding its operations, which ensure its continued viability and potentially promising future, as evidenced by quarterly trends over the past few years.

The impact of the abolition of ALPHV
In a major blow to the ransomware industry, the FBI announced on December 19, 2023, that it had taken down the ALPHV/BlackCat ransomware group. This takedown followed a five-day shutdown of the group’s dark web infrastructure that began on December 8. The FBI seized control of one of the ALPHV group’s main sites, replacing it with their signature logo. This action, along with the development of a decryption tool to assist victims, represents a significant victory for law enforcement in the fight against ransomware.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In Q1 2024, ALPHV was behind 51 ransomware attacks, a significant drop from 109 attacks in Q4 2023. Although the group is still active in 2024, the FBI's takedown clearly had a significant impact.
Reason 2: The decrease in ransom payments#
The decrease in ransom payments could also prompt ransomware groups to “pause” and look for alternative sources of income.
In the last quarter of 2023, the percentage of ransomware victims who complied with ransom demands fell to an all-time low of 29%, according to data from ransomware trading firm Coveware.
Coveware attributes this continued decline to several factors, including heightened preparedness among organizations, skepticism about cybercriminals' assurances not to disclose stolen data, and legal restrictions in regions where ransom payments are prohibited.
Not only has the number of ransomware victims making payments decreased, but there has also been a notable decrease in the monetary value of such payments.
Coveware notes that in Q4 2023, the average ransom payment amounted to $568,705, a 33% decrease from the previous quarter, with the average ransom payment standing at $200,000.
New groups emerging#
Despite a drop in the number of attacks from Q4 2023 to Q1 2024 and despite lower profitability, several new ransomware groups emerged in Q1. The new groups include:
- RansomHub – identifying itself as a global hacking group motivated primarily by financial gain.
- Trisec – which openly deviates from conventional ransomware groups by openly aligning itself with a nation-state.
- Slug – who take responsibility for infiltrating and targeting AerCap
- Mydata- a data leak website that names several prominent companies, including Accolade Group, Gadot Biochemical Industries, and others.
Cyberint expects several of these newer teams to strengthen their capabilities and emerge as dominant players in the industry, alongside veteran teams like LockBit 3.0, Cl0p , and BlackBasta.
Read Cyberint's Ransomware Report 2023 for more emerging groups, the top industries and countries targeted, an analysis of the top 3 ransomware groups active in Q1 2024, notable trends and incidents of 2024, and more.
Information source: thehackernews.com
