A new report from the Financial Crimes Enforcement Network (FinCEN) reveals that ransomware activity peaked in 2023, before declining in 2024 , following a series of law enforcement actions targeting the ALPHV/BlackCat and LockBit ransomware gangs .

The report documents 4,194 ransomware incidents between January 2022 and December 2024.These reports show that organizations paid over $2.1 billion in ransom, nearly matching the total amount reported over the 8-year period from 2013 to 2021.
In total, from 2013 to 2024, FinCEN identified approximately $4.5 billion in payments to ransomware gangs.
See also: Hackers exploit ad networks to distribute Triada Trojan
Law enforcement targeted BlackCat and LockBit ransomware
According to the report, 2023 was the best year for ransomware gangs, with victims reporting 1,512 individual incidents and approximately $1.1 billion in ransom payments, a 77% increase from 2022.
However, both statistics declined in 2024, with a small drop to 1,476 incidents, but a dramatic decrease in payouts ($734 million). This decrease is believed to be due to law enforcement operations targeting BlackCat in 2023 and LockBit in early 2024.

Both of these ransomware gangs were the most active at the time of the outage. Many of the perpetrators moved on to new malicious operations, while others attempted to resume operations.
See also: MuddyWater targets Turkey-Israel-Azerbaijan with UDPGangster Backdoor
FinCEN reports that the amount paid varied, with most ransom payments being under $250,000. The analysis also showed that the manufacturing, financial services , and healthcare sectors suffered the most ransomware attacks, with financial institutions reporting the largest dollar losses.
“Between January 2022 and December 2024, the most frequently targeted industries (based on the number of incidents identified in BSA reports related to ransomware during the review period) were manufacturing (456 incidents), financial services (432 incidents), healthcare ( 389 incidents), retail (337 incidents), and legal services (334 incidents),” FinCEN explained.
In total, FinCEN identified 267 different ransomware families, with only a small number responsible for most of the reported attacks.
See also: FvncBot: New Android banking malware steals data

Akira ransomware and other major groups
Akira ransomware appeared in the most incident reports (376), followed by ALPHV/BlackCat, which also earned the most, approximately $395 million in ransom payments. LockBit with $252.4 million in payments.
Other ransomware gangs included Black Basta, Royal, BianLian, Hive, Medusa, and Phobos. Collectively, the 10 most active ransomware gangs accounted for $1.5 billion in ransom payments from 2022 to 2024.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Payment methods were also tracked, with the majority being paid via Bitcoin (97%), and a small number being paid in Monero, Ether, Litecoin, and Tether.
FinCEN encourages organizations to continue reporting attacks to the FBI and ransom payments to FinCEN to help combat cybercrime.
Source: www.bleepingcomputer.com
