Cybercrime DB

Ransomware Examples From Major Attack Campaigns

Understanding how attackers operate teaches defenders what actually stops them.

Staff Writer · · 10 min read
Cover illustration for “Ransomware Examples From Major Attack Campaigns”
ransomware groups and operators · August 13, 2026 · 10 min read · 2,311 words

Ransomware is now present in 44% of confirmed breaches, up 37% year-over-year according to Verizon's 2025 Data Breach Investigations Report. That number has moved from background trend to main event.

But aggregate stats only tell you how bad things are. Defenders need to understand how things work. And if you are trying to defend something, the "how" is what actually matters.

This piece walks through the most instructive ransomware campaigns of the past several years. The goal is to pull out what each one actually teaches. Every attack below illustrates a specific mechanism, a specific choice attackers made, or a specific shift in how this whole ecosystem operates. Read them that way and they become a lot more useful than a timeline.

Unpatched Infrastructure at Scale: The WannaCry Lesson

In May 2017, WannaCry spread to more than 300,000 computers across 150 countries in a matter of days. It did this by exploiting EternalBlue, a vulnerability in Windows' SMB protocol that had been leaked from the NSA's own toolkit. Attackers needed only a worm and a world full of unpatched machines. Think of it as leaving every door in a city unlocked and then being surprised when someone walks in.

The human cost anchor here is the NHS. Hospitals across England and Scotland lost access to patient records. GP offices could not pull up appointments. Pharmacies went dark. Legacy infrastructure in healthcare persists because replacing it costs enormous amounts of money and political will, and the consequences of a botched upgrade can be as dangerous as a cyberattack. The NHS was an outlier only in visibility. It was a preview.

The operational detail worth sitting with is the kill switch. Marcus Hutchins, a security researcher, discovered that WannaCry contained a hardcoded domain. When he registered it, the worm stopped spreading. The attackers had accidentally (or carelessly) left a single off switch inside their own weapon.

The US and UK formally attributed WannaCry to North Korea in December 2017. State-linked actors operating ransomware-style tools was already happening years before it became a regular headline.

The takeaway: Worm-enabled ransomware turns one unpatched host into a global outbreak. Patch management is a frontline control, not a housekeeping task.

NotPetya Was Not Ransomware. It Was a Weapon Wearing a Costume.

One month after WannaCry, NotPetya hit. Same EternalBlue exploit, but deployed with entirely destructive intent.

NotPetya spread through a software update for MeDoc, accounting software widely used across Ukraine. That supply chain entry point is the key distinction. WannaCry mass-scanned the internet, whereas NotPetya rode in through trusted software. Once inside, it destroyed. The ransom demand was theatre: the actual goal was wiping data and crippling infrastructure.

Total estimated damage: around $10 billion. The most costly cyberattack in known history at the time. Maersk, one of the world's largest shipping companies, reported approximately $300 million in losses. Maersk was not the target. It just happened to use the compromised software. That is collateral damage at a scale that should reframe how anyone thinks about software they depend on.

The takeaway: An attack that looks like ransomware may have no financial motive at all. When there is no real payment mechanism, the goal is destruction. Defenders who assume financial motivation will misread this class of threat.

Ransomware-as-a-Service: How a Specialist Crime Became a Franchise

By 2025, roughly 72% of ransomware incidents involved the RaaS model, meaning nearly three in four attacks were conducted by affiliates who did not build the tool they used. The basic mechanic is simple: core developers build and maintain the ransomware, then lease it to affiliates who run the actual attacks and split the proceeds. An affiliate needs only access to the platform and a target.

The UK Home Office flagged this directly in its 2025 ransomware consultation: RaaS lowered the barriers to entry to the point where almost any criminal can cause widespread harm. That is the operating reality.

The Conti group is a useful early example of what this looks like at scale. Sophisticated double-extortion tactics (encrypt the data, then threaten to publish it). Cold-calling victims to pressure payment. Attacks on Ireland's Health Service Executive in 2021. An attack on Costa Rica's government in 2022 that escalated to a declaration of national emergency.

The takeaway: This section has no single headline number. Its job is to make the business model legible before we get to the bigger cases. When you understand how the model works, what happens next makes a lot more sense.

Colonial Pipeline: The $4.4 Million Password Problem

On May 7, 2021, DarkSide accessed Colonial Pipeline's network through a single compromised VPN password. The account had no multi-factor authentication.

That is it. That is the entry point. The entry point was a username, a password, and an open door.

Within two hours, 100 gigabytes of data had been exfiltrated before encryption even began. Double extortion in action: steal first, lock second, now you have two levers. Colonial paid 75 Bitcoin (roughly $4.4 million at the time) within hours of the attack. The DOJ later recovered 63.7 Bitcoin, worth approximately $2.3 million at recovery. The gap reflects crypto price volatility between payment and seizure. Even the "win" was complicated.

The policy response was significant. A Biden executive order on cybersecurity followed. Emergency declarations came at federal and state levels. The attack on a fuel pipeline made ransomware a national security conversation in a way it had not been before.

The takeaway: The most consequential attacks often hinge on the most preventable failures. MFA absence was the root cause here, rather than advanced tradecraft. Any organisation still running critical systems without MFA should treat that as an active liability.

LockBit's Volume Strategy, and What Operation Cronos Actually Accomplished

LockBit was responsible for roughly 25% of ransomware attacks in 2023 and 2024, per the UK National Crime Agency. More than 7,000 attacks globally between June 2022 and February 2024. More than $120 million extorted across more than 2,000 claimed victims. The strategy was simple: hit everything, hit often.

On February 20, 2024, Operation Cronos changed the conversation. The NCA, FBI, Europol, and partners from multiple countries seized darknet infrastructure, took down 34 servers across eight countries, froze 200 cryptocurrency accounts, and shut down thousands of accounts. LockBit's leader was identified as Russian national Dmitry Yuryevich Khoroshev (known online as LockBitSupp), and charges were filed. He has not been apprehended.

Within days, LockBit had a new site live. Some of the same victim listings reappeared, and the group reconstituted fast.

The evidence raises a hard question: what does a successful takedown accomplish when the affiliate network reorganises around a new brand? Operation Cronos was genuinely significant: it disrupted operations, exposed leadership, and demonstrated coordinated international capability. It also left a decentralised criminal ecosystem intact. Both outcomes deserve acknowledgement.

The takeaway: Takedowns matter, and the RaaS model is specifically designed to survive them.

MOVEit: Why Attacking Shared Software Is Devastatingly Efficient

In May and June of 2023, the Clop group exploited a zero-day vulnerability in MOVEit Transfer, a file-transfer tool used across thousands of organisations. Victims included US federal agencies, the BBC, British Airways, and Shell. Cross-sector sweep. Single vulnerability. Total ransom demands estimated to have exceeded $100 million.

Here is what makes this case particularly instructive: Clop exfiltrated data and threatened to publish it. The leverage came entirely from the data itself, with no encryption involved.

The takeaway: Attacking shared software multiplies impact without multiplying effort. One vulnerability, hundreds of victims. Third-party tools are part of an organization's own attack surface — treating them as a separate problem leaves a significant gap.

MGM and Caesars: The $100 Million Phone Call

In September 2023, attackers linked to the ALPHV/BlackCat group called the MGM Resorts IT help desk, impersonated an employee, and talked their way into the network. The entry point was a convincing phone conversation.

MGM saw hotel check-in systems go down, slot machines stop working, and digital room keys fail. The disruption lasted weeks and cost an estimated $100 million or more. MGM refused to pay.

Caesars Entertainment reportedly paid approximately $15 million and avoided the extended operational damage MGM experienced. That contrast sits at the center of an ongoing debate that does not have a clean answer. Was Caesars rational? Was MGM principled? Both, probably. Depending on your position.

Sophos's State of Ransomware 2025 data shows 18% of ransomware attacks in 2025 were initiated through phishing, up from 11% in 2024. Social engineering as a first step is growing, not fading.

The takeaway: Technical defences are a foundation, but process and human verification matter equally. When a help desk employee can be talked into handing over access, controls need to extend to verification procedures, not just network perimeters.

Change Healthcare: When the Target Is the Plumbing Nobody Sees

On February 21, 2024, ALPHV/BlackCat hit Change Healthcare, a division of UnitedHealth Group that processes a significant share of US healthcare transactions. The attack affected tens of millions of people, making it the largest breach of medical data in US history by individuals affected.

The downstream disruption was severe because of concentration risk. Change Healthcare was critical infrastructure that most of the healthcare system depended on without fully understanding that dependence. When it went down, pharmacies could not process prescriptions. Providers could not get paid. The ripple effects were immediate and widespread.

Healthcare remained the most expensive sector for ransomware recovery in 2025, averaging $7.42 million per breach (down from $9.77 million in 2024). The combination of sensitive data and operational criticality makes it both a premium target and a premium victim.

Worth noting: ALPHV/BlackCat was also behind MGM and Caesars. Same group, different sectors, different techniques. That adaptability is what well-resourced RaaS affiliates actually look like in practice.

The takeaway: Critical infrastructure risk extends beyond pipelines and power grids. Administrative systems that healthcare depends on carry equivalent systemic exposure. If something failing would break the entire sector, it needs to be treated like critical infrastructure, regardless of what it is called.

The $75 Million Dark Angels Payment and What It Signals

In 2024, an unnamed Fortune 50 company paid $75 million to a group called Dark Angels. Per Varonis, it is the largest single ransomware payment ever recorded.

Dark Angels operates on the opposite logic from LockBit. Small number of targets. Deep infiltration. Patient, methodical exfiltration. The goal is one enormous payment, not hundreds of mid-size ones. In some operations, exfiltration and the threat of publication are the only levers Dark Angels deploy.

This connects to a broader bifurcation happening in the market. The median ransom demand in 2025 was $1.32 million (down from $2 million in 2024), and the median payment was $1 million. Overall medians are falling. But the upper end keeps setting records. Some groups are chasing volume. Others have concluded that one well-chosen target is worth more than hundreds of opportunistic ones.

The takeaway: The $75 million number is evidence that a segment of the ransomware market has made a deliberate strategic shift toward precision over volume. Defenders at large enterprises need to account for that calculation.

Diagram: The Ransomware Market Is Splitting in Two. Visualizes: Contrast two diverging attacker strategies visible in 2024–2025 data.

The Pattern: What Attackers Keep Choosing and Why

Diagram: How Extortion Models Closed the Defender's Exit Options. Visualizes: Show the evolution of ransomware extortion mechanics as a three-stage progression, each stage removing one more defensive exit for victims.

Across all of these campaigns, a few patterns show up consistently.

Initial access keeps being the easy part. WannaCry used a worm. NotPetya used a software update. Colonial used a stolen password. MGM used a phone call. The vector changes. The underlying reality does not: getting in is rarely the hard part. Sophisticated encryption is not where attackers spend most of their effort.

Extortion models keep evolving to remove the defender's exit options. Encryption-only gave defenders an out (restore from backups). Double extortion (encrypt plus exfiltrate) closed that option. Exfiltration-only, as Clop and Dark Angels both demonstrate, removes the encryption step entirely, making the backup strategy progressively less complete as a response.

Target selection is drifting toward leverage maximization. Mass scanning gave way to sector concentration (healthcare, critical infrastructure), which is giving way to big game hunting (Fortune 50 targets). The trend is toward more leverage per attack, not more attacks.

Law enforcement can disrupt, but not dissolve. Operation Cronos was real and significant. LockBit was back up in days. The RaaS model is structurally resilient. Takedowns are worth doing, and they remain one tool among many.

Payment refusal is rising, but attack volume is not falling. The victim payment rate fell to approximately 28% in 2025, a record low. Recorded attack cases in 2024 hit the highest annual volume since NCC Group began monitoring in 2021 (5,263 cases). Lower payment rates have accelerated the shift toward higher-value targets where a single payment justifies the effort, and attack frequency has continued to rise.

Defenders who are best positioned understand attacker decision logic, not just incident tracking. Why did this group choose this vector? Why this target? Why this extortion model? That reasoning determines where to prioritise controls.

Producing Technically Credible Ransomware Content That Practitioners Will Actually Read

Most ransomware coverage stops at "here is what happened." Practitioners need "here is what this reveals about how attackers think" -- an analysis that is actually useful to someone building a defence.

Security leaders and marketing teams at cybersecurity vendors run into this constantly. Newsworthy incidents are plentiful. The hard part is figuring out which ones are worth publishing on, what angle earns credibility with a technically sophisticated audience, and how to produce analysis that does not read like a vendor press release dressed up as thought leadership.

Cyberou works with more than 30 cybersecurity vendors, combining practitioner judgement with specialist authorship. That process determines which campaigns belong in a piece like this, rather than which incidents happened to generate the most headlines. The result is content that gets taken seriously by the people it is trying to reach, which is reflected in more than 300 tier-one media features connected to Cyberou research.

Technically credible content earns that kind of downstream interest, where volume output falls short.

Sources

  1. fortinet.com

More in ransomware groups and operators