Ransomware Payments Traced to Specific Groups
Blockchain's permanent record lets investigators follow ransom payments back to their operators.

Ransomware payments don't vanish the way people think they do. Bitcoin handles the vast majority of reported ransomware transactions, according to FinCEN's December 2025 analysis, and every one of those transactions gets written into a permanent public ledger. That ledger is the whole reason forensic analysts can trace a payment from a scared IT director's wallet back to a named criminal group, and it's quietly changing what victims decide to do the moment a ransom note shows up.
Pseudonymous means the wallet address is public while the name behind it stays hidden, at least for a while. Every hop that money takes gets stamped into the blockchain permanently, and bolting on a mixer or a bridge adds more hops for someone to follow later. Chainalysis's 2024 money-laundering data found that nine deposit addresses account for over half of all ransomware value received by exchanges. Nine addresses, half the money. I've seen a lot of concentrated numbers in this field, and that one still stops me for a second every time I pull the report back up.
How forensic analysts move from a raw payment to a named group
The trace usually starts simple. Victim wallet sends money to an affiliate wallet, which kicks a cut up to an operator wallet. Ransomware-as-a-service groups run like franchises, and franchises collect royalties. That revenue split has to happen somewhere, and somewhere, in this business, is always on-chain, sitting in plain sight for anyone who knows where to look.
Wallet reuse is usually the first crack. Affiliates rotate handles to look like separate actors, but the timing and structure of their payments cluster right back to the same operator wallet, over and over. LockBit's admin panel leak in May 2025 laid this out in almost embarrassing detail: something like 60,000 Bitcoin addresses configured just to skim the group's 20% affiliate cut. Seeing it in address form feels like an org chart.
From there, analysts start building a laundering fingerprint. Groups tend to reuse the same off-ramps, the same exchanges, the same bridge providers, similar timing windows between receipt and cash-out. Do that enough and it becomes a signature. Mixing services used to handle 10 to 15% of ransomware laundering flows every quarter, per Chainalysis, until sanctions hit Tornado Cash and Sinbad and law enforcement dismantled ChipMixer. Actors moved to cross-chain bridges instead. Those are traceable, just slower to crack open.
Monero is where the whole approach hits a wall. LockBit's leaked panel listed 1,355 Monero wallets next to 2,338 Bitcoin wallets. That ratio alone tells you the group knew exactly where the forensic blind spot was and planned around it.
What the LockBit infrastructure leak revealed about operator-level attribution
The LockBit leak felt like finally getting the answer key after years of guessing. One database, wallet addresses, affiliate roster, and payment records, all sitting together for the first time.
And what it showed, again, was concentration. Of 159 Bitcoin addresses tied directly to attacks, only 19 ever received funds, and 18 of those got exactly one transaction each. One address, one payment, and then nothing. The single largest payment in the whole dataset was 4.22 BTC, worth about $433,061 at the time, per Forescout's review. The affiliate side, though, was enormous by comparison: 3,693 invite entries mapping to those 2,338 Bitcoin and 1,355 Monero wallets.
Blockchain tracing had already fingered individuals well before the leak surfaced. Rostislav Panev allegedly pocketed roughly $230,000 in Bitcoin for development work. Dmitry Khoroshev, LockBit's alleged leader, reportedly sent around $5,000 in BTC every two weeks to LockBit members starting in 2022, then bumped that to roughly $10,000 monthly from mid-2023 into early 2024, according to the indictment as reported by Chainalysis. The leak confirmed a story investigators had already sketched out by hand, address by address. By the FBI's count, LockBit had been linked to more than 2,000 attacks and at least $120 million in ransom payments between January 2020 and May 2023, over 15% of the entire ransomware market at the time.
How law enforcement used payment tracing to disrupt LockBit and reshape the threat landscape
The NCA and FBI took LockBit apart in early 2024, and the money confirmed it worked. LockBit's payment volume in the second half of 2024 dropped roughly 79% compared to the first half, per Chainalysis. That's about as clean a before-and-after as this field ever produces. Before the takedown, the UK's National Crime Agency had linked the group to more than 7,000 attacks worldwide since June 2022, right up until Khoroshev got named and sanctioned.
Disruption looks like musical chairs. RansomHub showed up in February 2024, almost too conveniently timed, and absorbed displaced LockBit and BlackCat affiliates fast enough to post the highest victim count of any group that year. ALPHV/BlackCat went a darker route. After FBI action, the group still pulled $22 million out of Change Healthcare, then vanished with it in what blockchain analysts documented as a straight exit scam. The affiliate wallets went silent. The money never resurfaced anywhere traceable.
That's the shape of things now. Take down the brand name, and the on-chain fingerprints of the affiliates just pop up somewhere else under new letterhead. Total payments still cratered across the back half of 2024, from $492 million in H1 to $321 million in H2, per Chainalysis, so the disruptions clearly did something real. They reset the board rather than ended the game.
Tracing affiliate lineage and rebrand continuity across group transitions
Black Basta is the textbook rebrand case, and blockchain tracing caught it almost as it happened. When Conti went dark in May 2022, several million dollars moved straight from Conti-linked wallets into Black Basta wallets, according to tracing reported by Barracuda. The wallet lineage told the story before anyone made a public claim about who Black Basta actually was. That group went on to collect at least $107 million in ransom payments through late 2023 before going quiet in early 2025.
Here's the part that matters most for attribution over the long run: affiliate wallet habits travel with the person, not the group name on the ransom note. An affiliate who jumps from LockBit to RansomHub carries the same wallet patterns with them, which means cross-group attribution is possible even without another lucky leak handed to researchers.
Cl0p shows a different flavour of persistence, one where the group doesn't bother rebranding at all. It had 93 listed victims across all of 2024, then 358 in the first quarter of 2025 alone, a jump of roughly fourteenfold, driven by zero-day exploitation of Cleo file transfer software, per Optiv's Q1 2025 report. The significance isn't the rebranding question; it's that a single zero-day vulnerability in widely deployed file transfer software multiplied one group's victim count by 14x in a single quarter. Same name, same infrastructure, just a much bigger hammer swung at a much softer target. And when RansomHub shut down in April 2025, Qilin absorbed the overflow, doubling its monthly victim count from 36 at the start of the year to 75 by the third quarter, according to SOS Ransomware data.
Attribution tracks the people and infrastructure underneath the group names. The blockchain remembers the people and infrastructure.
What FinCEN's three-year payment dataset adds to the attribution picture
FinCEN's numbers put real scale behind all of this. Between January 2022 and December 2024, the agency received 7,395 Bank Secrecy Act reports covering 4,194 separate ransomware incidents, totaling more than $2.1 billion in payments. Compare that to the nine years before it: 2013 through the end of 2021 produced only 3,075 reports and roughly $2.4 billion. Nearly a decade's worth of damage, compressed into three years. Better reporting infrastructure and attackers growing more effective both drove that jump.
Across 267 identified ransomware variants, the top 10 by cumulative payment accounted for well over a billion dollars. That lines up neatly with the wallet concentration story from earlier: harm clusters around a small number of named actors, not a long tail of nobodies. The most prevalent variants in FinCEN's data, Akira, ALPHV/BlackCat, LockBit, Phobos, and Black Basta, are the exact same names showing up in private blockchain analytics from separate commercial firms. Two completely different methodologies, government reporting and private forensics, landing on the same list. That convergence is deliberate.
Median transaction values tell their own quiet story. around $124,000 in 2022, up to roughly $175,000 in 2023, then down to around $155,000 in 2024, tracking almost exactly with the LockBit and BlackCat disruption timeline. Financial services, manufacturing, and healthcare reported the most incidents and the highest aggregate payments, which at least gives victims and their insurers a real baseline for what exposure looks like in their own sector.
How attribution findings are now changing victim payment decisions
Total ransomware payments fell about 35% in 2024, down to roughly $813.55 million from $1.25 billion the year before, per Chainalysis. Attack volume held steady while willingness to pay fell sharply.
Once a group gets sanctioned or its leader gets a name and a face attached, paying them becomes a legal liability on top of an operational headache. Sending funds into sanctioned wallet infrastructure creates OFAC liability, plain and simple, and forensic attribution made that liability possible in the first place. Akira's attributed haul, hundreds of millions of dollars as of late September 2025 per the FBI, carries weight beyond the raw dollar figure. It's pressure sitting on the next company staring at an Akira ransom note, wondering if paying makes them complicit in funding something regulators are actively watching.
Then there's Dark Angels, which took in the largest single ransomware payment ever recorded: $75 million, confirmed by Chainalysis, from a large publicly traded US company. Attribution work showed Dark Angels operates as its own standalone outfit rather than a RaaS franchise, and that distinction changes the entire risk calculus around negotiation and recurrence. A franchise has dozens of affiliates who might resurface under a different name next year, whereas a standalone group carries its own distinct recurrence risk. Public company boards now have to weigh disclosure obligations against attribution findings in real time, which is a reality that emerged entirely within the last decade.
The practical upshot: insurers and victims increasingly bring in blockchain analysis before and during negotiations, just to answer one question. Where does this money actually go, and what does that look like on our books six months from now?
Where on-chain attribution still falls short and what fills the gap
Monero remains the biggest hole in the net. Those transactions simply aren't publicly traceable the way Bitcoin's are, and LockBit's leaked roster carrying 1,355 Monero wallets alongside its Bitcoin ones tells you this wasn't an accident. Groups map the forensic blind spots precisely.
Cross-chain bridges have mostly replaced mixers as the obfuscation tool of choice. They're traceable, technically, but the forensic techniques are still catching up, delivering slower answers exactly when speed matters most. There's also a harder wall between the transaction graph and an actual legal identity. Blockchain analysis can cluster wallets and map infrastructure all day long, but turning that into a name a prosecutor can put on an indictment requires exchange KYC records, seized laptops, informants, or OSINT that happens to intersect with the wallet data. The chain gets you most of the way there, rarely all of it.
Akira's $244 million in attributed payments and Cl0p's reported total of hundreds of millions of dollars since 2021 both make the same point from different directions: knowing exactly who you're dealing with falls short of shutting them down. Both groups are still active right now, as you read this.
The real state of the art is layered, not singular. Private forensics firms like Chainalysis and TRM Labs feed findings to financial intelligence units, which feed law enforcement, which feeds sanctions bodies, and leaked operational data (like the LockBit panel) validates or corrects the whole chain along the way. Stacked together, those layers catch enough to matter.


