Executive Summary
The ransomware-as-a-service ecosystem has fragmented sharply since the 2024 law enforcement dismantling of LockBit and ALPHV, producing a larger, less disciplined, but no less dangerous market that now counts well over 120 active brands as of 2025, according to Europol's Internet Organised Crime Threat Assessment 2026. The structural shift matters to corporate security and risk executives because fragmentation has not reduced attack volume; it has redistributed it across hundreds of operators with weaker operational security and shorter rebranding cycles, compressing the window defenders have to build threat-specific controls.
Cryptocurrency laundering tradecraft has pivoted from mixers to cross-chain bridges, a shift documented by TRM Labs in its 2026 Crypto Crime Report, and the financial and cyber implications are mutually reinforcing: harder-to-trace laundering sustains ransom economics, which sustains attack incentives.
- Security and IT leaders: As of Q3 2026, healthcare businesses (pharmaceutical manufacturers, billing providers) represent the fastest-growing target segment, up 36% in H1 2026 per Comparitech. Prioritize third-party vendor security reviews over perimeter-only controls.
- Risk officers: New entrant groups offering 90/10 affiliate splits, such as The Gentlemen documented by Check Point in June 2026, are growing victim counts faster than established brands, making IOC-based defenses insufficient.
- Policy and regulatory teams: Sanctions pressure has driven laundering to jurisdictionally ambiguous cross-chain bridge services rather than eliminating it; monitor FATF guidance updates on virtual asset service provider (VASP) obligations.
Law enforcement takedowns since 2024 have fragmented RaaS markets without reducing overall victimization, while healthcare and critical infrastructure sectors face the highest targeting intensity and the most limited room to absorb downtime costs.
Key Findings
- The 2024 LockBit and ALPHV takedowns produced market fragmentation rather than market contraction, with active ransomware brands growing from 79 to over 120 within twelve months.
- Affiliate trust in large RaaS platforms has structurally declined since ALPHV's 2024 exit scam, driving operators toward smaller platforms offering higher revenue shares and toward cartel-style consolidation models like DragonForce.
- Ransomware operators have shifted post-payment laundering from cryptocurrency mixers to cross-chain bridges, increasing traceability for analysts but reducing jurisdictional reach for law enforcement seizing funds.
- Healthcare is the single highest-concentration ransomware target globally, with 22% of all publicly disclosed attacks hitting medical organizations in 2025, and the attack surface is expanding into healthcare supply chain vendors rather than hospitals directly.
- RaaS fragmentation has created a detection opportunity by pushing more operators into jurisdictionally reachable infrastructure and generating more intelligence through leaks and financial pattern repetition, but defenders anchored to single-group IOC tracking will miss the majority of attacks.
How Fragmentation Reshaped The Affiliate Talent Market
When Operation Cronos dismantled LockBit's server infrastructure in February 2024 and ALPHV collapsed via exit scam in March 2024, the dominant RaaS duopoly that had structured affiliate incentives for three years ceased to function. The immediate consequence was not a reduction in available criminal labor but a redistribution of it. According to Secureworks, groups listing victims on dark web leak sites rose from 43 to 68 within weeks of the LockBit takedown. Black Kite's retrospective found 52 new groups emerged in the subsequent twelve months, lifting the total to 95 by year-end 2024 and beyond 120 by 2025 per Europol's IOCTA 2026.
The structural change in affiliate behavior is the more consequential development. TechInformed and Analyst1 both document a pattern of experienced operators leaving large platforms in favor of smaller, more nimble groups after ALPHV demonstrated that platform administrators could abscond with ransom proceeds. The $22 million Change Healthcare payment, allegedly pocketed by ALPHV operators rather than distributed to the executing affiliate, destroyed trust at the franchise level. Chainalysis confirmed that ALPHV was capturing over 30% of all ransomware payments before the exit scam, meaning its collapse forced significant capital reallocation across the ecosystem.
The replacement architecture has taken two recognizable forms. First, cartel-style coalitions: Sophos and Secureworks have documented DragonForce evolving from a traditional RaaS into a broader coalition absorbing operators from multiple disbanded groups. Second, aggressive affiliate bidding: The Gentlemen, analyzed by Check Point and reported by Krebs on Security in June 2026, grew to become the second most active group by victim count by offering affiliates 90% of ransom proceeds rather than the market-80%, reaching at least 332 published victims since inception in mid-2025.
What is not being reported: industry victim counts drawn from dark web leak sites systematically undercount total attacks, because groups running data-only extortion increasingly skip the public leak site step when victims pay quickly. The 120-plus active brand count and the victim tallies in circulation are floors, not ceilings.
Europol's IOCTA 2026 adds a third structural trend: RaaS operators are broadening service offerings to include AI-assisted attack customization and more flexible branding, treating the platform itself as a competitive product rather than a fixed franchise. This drives [Y] through a commoditization pathway: entry barriers fall, attack volume rises, but negotiation quality and average ransom size per incident decline, consistent with Vectra AI's finding that payment rates dropped to roughly 25% in Q4 2025.
Cryptocurrency Laundering Tradecraft: The Bridge Shift
The post-2024 laundering environment is not a story of detection failure; it is a story of jurisdictional arbitrage. TRM Labs' 2026 Crypto Crime Report provides the clearest available quantification: bridge-related activity from ransomware wallets grew 66% across 2024-2025 while mixer-related activity declined 37%. The mechanism is specific. Traditional mixers, including coinjoin services catalogued by Europol's IOCTA 2026, require identifiable on-chain staging that compliance teams at major exchanges have learned to screen. Bridges route value across chains, accessing new liquidity venues and introducing jurisdictional complexity that outpaces current VASP monitoring frameworks.
TRM Labs tracked Akira ransomware through four distinct laundering evolutions as of August 2025, each responding to law enforcement monitoring of the previous phase. Phase III routed all proceeds through the Defiway bridge. Phase IV, beginning August 2025, routes each payment through a unique intermediary address before consolidating at a single global VASP. TRM analysts noted that FOG ransomware used the same Defiway routing in Phase III, suggesting either coordination or shared infrastructure between the two groups. By late 2025, Akira received approximately $150 million, and deviations then appeared involving Chainflip into Tornado Cash, potentially signaling the beginning of a fifth evolution.
SecAlliance notes a parallel evasion technique: operators now withhold wallet addresses from initial ransom demands, preventing victims or their insurers from initiating on-chain monitoring before payment is made. This constrains the window during which blockchain forensics firms can pre-position for asset tracing.
Europol's IOCTA 2026 highlights that privacy coins remain in use among professional money launderers linked to ransomware, and that coinjoin services remain a popular alternative for dark web marketplace vendors despite enforcement pressure following the cryptomixer.io takedown. The financial and cybersecurity implications are mutually reinforcing: without effective VASP-level cash-out monitoring enforced under the FATF VASP framework, ransom economics remain viable, sustaining attack incentives across all sectors. Enforcement pressure has raised operational costs for the laundering layer but has not collapsed it.
An arxiv.org research paper analyzing a leaked LockBit MySQL management panel found two distinct cash-out pipelines, with a small portion of ransom retained in long-lived addresses (likely operator profit) and the remainder aggregated into two high-volume addresses processing over 200,000 BTC combined before being distributed to affiliates. The financial scale and structural separation of the operator-affiliate payout architecture reveals an industrial-grade back office, not opportunistic criminal freelancing.
Sector And Geographic Targeting: Where Prioritization Now Points
Healthcare's dominance as the primary ransomware target is now durable rather than cyclical. The FBI IC3 2024 Annual Report recorded 460 US healthcare ransomware incidents, more than any other critical infrastructure subsector. Cybelangel's 2026 research puts 22% of all publicly disclosed global attacks on medical organizations, the highest concentration of any single sector. The targeting logic, as articulated by the American Hospital Association in May 2026, is operational leverage: US healthcare average downtime costs $900,000 per day, and hospitals cannot defer clinical operations during negotiations. Average breach identification and containment time runs 279 days per ORDR's 2026 analysis, meaning attackers have extensive dwell time to prepare data exfiltration alongside encryption.
The target mix within healthcare is shifting in a strategically significant way. Comparitech's H1 2026 tracker shows attacks on hospitals and direct care providers declining 7% in the US while attacks on healthcare businesses (pharmaceutical manufacturers, billing providers, health tech companies) rose 36%. The AHA attributes this to what it calls the "ransomware blast radius" strategy: attacking a third-party mission-critical vendor causes disruption across all of its healthcare clients simultaneously. The Stryker attack in 2026 and the 2024 Change Healthcare incident are the operational templates, per AHA. Healthcare businesses now represent 163 of the 410 attacks tracked by Comparitech in H1 2026.
Beyond healthcare, manufacturing and critical infrastructure remain high-priority targets. The North Korean state-sponsored Lazarus Group's linkage to the Gunra ransomware operation, documented by AhnLab and reported by The Record in April 2025, shows that state actors are increasingly using RaaS structures to blend revenue generation with espionage targeting, particularly against South Korean manufacturing and financial sector networks. The Canadian Centre for Cyber Security's Ransomware Threat Outlook 2025-2027 assesses that RaaS expansion will sustain elevated risk through 2027 across all sectors.
Geographically, the United States recorded the highest healthcare ransomware attack volume in H1 2026 with 225 incidents per Comparitech, followed by Germany, India, Canada, and Australia. The deepstrike.io 2026 ransomware statistics analysis notes that enforcement-driven affiliate migration is pushing some operators toward less-protected organizations in developing markets, a trend the evidence does not yet resolve with precision; the direction is observable but the magnitude remains uncertain.
Short-term gain, long-term cost: healthcare organizations facing 25% payment rates are increasingly refusing to pay, per Vectra AI data. This translates directly into extended operational disruptions and data exposure events rather than resolved incidents, compounding the systemic risk to patient care systems rather than reducing it.
Key Assumptions
The table below identifies the assumptions on which the primary findings rest, with falsifying conditions and the observable data that would most quickly signal a need to revise the assessment.
| Assumption | Supporting Evidence | Falsifying Evidence | Impact if Wrong | Monitoring Metric |
|---|---|---|---|---|
| Affiliate fragmentation is a durable structural shift, not a temporary dispersal | Secureworks group count data; 52 new groups in 12 months; Black Kite 2025 report; IOCTA 2026 trend data | Emergence of a single dominant platform reconsolidating >30% of active affiliates within 6 months | Assessment of disruption opportunity through fragmentation requires revision; concentrated market would restore pre-2024 negotiation discipline | Ransomware payment market share tracking from Chainalysis Crypto Crime Report (quarterly updates) |
| Cross-chain bridge activity reflects deliberate laundering evasion, not organic DeFi adoption | TRM Labs 2025-2026 data showing 66% bridge growth concurrent with mixer decline; Akira four-phase evolution documented | Broad legitimate DeFi volume growth that accounts statistically for the observed bridge share increase without ransomware-specific clustering | Laundering scale assessment overstated; enforcement intervention at bridge level may be premature | TRM Labs quarterly blockchain analytics reports and FATF VASP compliance monitoring publications |
| Healthcare businesses (non-hospital) will remain the fastest-growing attack target through H2 2026 | 36% Q-on-Q increase documented by Comparitech; AHA blast-radius strategy analysis; declining hospital attack share | Return of hospital-direct targeting driven by a major group specifically prioritizing clinical care disruption for coercion | Sector-specific defensive investment recommendations require reweighting toward providers rather than vendors | Comparitech worldwide ransomware tracker (monthly release) and FBI IC3 sector data |
| Payment rates near 25% are suppressing average ransom size but not attack frequency | Vectra AI 2025-2026 data; 93 new variants in 2025 per TRM Labs despite lower payment rates | Payment rate recovery above 40%, which would restore economics sufficient to reconcentrate affiliate activity on high-demand enterprise targets | Volume attack model may give way to targeted high-demand attacks, reversing the fragmentation trend | Coveware quarterly ransomware market reports (ransom payment rate and average demand metrics) |
Counterarguments
-
Fragmentation may be overstated as a signal of ecosystem resilience: The 120-plus active brand count from Europol and GuidePoint includes a large proportion of short-lived rebrands with minimal independent capability. Black Kite's own 2025 report notes that many newcomers lack the negotiation discipline of LockBit or ALPHV and leak data within days without meaningful negotiation, reducing average per-incident ransom capture. If the majority of new groups generate minimal revenue before dissolving, the ecosystem-level financial pressure on victims may be lower than the headline group count implies. The evidence does not currently distinguish high-capability surviving groups from low-capability flash-in-the-pan operations with precision. LockBit's share dropped nearly 80% per Chainalysis despite operational continuity, suggesting that the post-takedown market is financially weaker even if numerically larger.
-
Blind spot: state-nexus ransomware actors are analytically underweighted in sector targeting models: The Gunra-Lazarus Group linkage documented by AhnLab and The Record in April 2025 illustrates a category of ransomware threat that Western targeting models built around financially motivated criminal franchises miss almost entirely. If state-sponsored groups are actively supplying tools, exploits, and access to criminal RaaS operators, targeting is no longer purely profit-driven. This spills directly into the sector risk assessment: state actors with espionage mandates overlay ransomware economics with intelligence priorities, meaning financial vulnerability alone no longer predicts which organizations get targeted. The picture is mixed on how widespread this pattern is beyond the Korean financial software case; independent corroboration beyond AhnLab is limited.
-
The bridge-laundering shift creates a single-source dependency risk in the assessment: The core evidence for the bridge-over-mixer trend comes primarily from TRM Labs data. While TRM is a credible blockchain analytics firm (source reliability assessed), the 66%/37% directional statistics do not yet have independent corroboration from Chainalysis or Elliptic in the specific 2025 timeframe. If TRM's methodology for attributing bridge transactions to ransomware as opposed to other illicit or legitimate cross-chain activity overstates the ransomware-specific share, the laundering evasion narrative remains directionally correct but the magnitude is uncertain. The Akira case study provides concrete corroboration for the behavioral pattern even if the aggregate statistics remain a single-source dependency at this time.
Indicators To Watch
The table below lists observable conditions that would confirm or falsify the primary findings over the next 6-12 months.
| Indicator | Current State | Warning Threshold | Time Horizon |
|---|---|---|---|
| Active ransomware brand count (Europol / GuidePoint tracking) | 120+ brands as of 2025 (Europol IOCTA 2026) | Decline to below 80 active brands, signaling reconsolidation | 6-12 months |
| Healthcare business (non-hospital) attack share as percentage of total healthcare incidents | 40% of 410 healthcare incidents in H1 2026 (Comparitech) | Rise above 50%, confirming blast-radius strategy as dominant targeting doctrine | 3-6 months |
| Bridge vs. mixer share in ransomware post-payment flows (TRM Labs quarterly data) | Bridges 66% higher YoY; mixers 37% lower (TRM Labs 2026) | Bridge share exceeding 60% of all ransomware laundering volume, confirming complete migration | 6-9 months |
| Ransomware payment rate (Coveware quarterly report) | Approximately 25% in Q4 2025 (Vectra AI) | Recovery above 35%, signaling that volume attack economics are sufficient to sustain the current fragmented model | 3-6 months |
| Emergence of a dominant post-LockBit platform with >20% affiliate market share | RansomHub, Qilin, and The Gentlemen share the top tier without dominance (Comparitech, Check Point 2026) | Any single group exceeding 20% share of published victim count, indicating reconsolidation | 6-12 months |
Near-term watch list: (1) Chainalysis Crypto Crime Report mid-year update (expected Q3 2026), which will provide independent bridge vs. mixer attribution data that either corroborates or challenges the TRM Labs directional finding; (2) Europol's follow-on to the IOCTA 2026 PDF covering Operation Endgame Phase III outcomes (expected Q4 2026), which will clarify whether continued infrastructure dismantling is further accelerating group proliferation or beginning to suppress it; (3) FBI IC3 2025 Annual Report (expected early 2026 publication cycle), which will provide the authoritative sector-by-sector incident count to confirm whether healthcare businesses have overtaken hospitals as the primary sub-sector target.
Decision Relevance
Scenario A (~55%): Fragmented, high-volume RaaS environment persists through 2027 with no dominant platform. If your organization operates in healthcare, pharmaceutical manufacturing, medical billing, or health technology, prioritize vendor security assessments and third-party access controls over perimeter defenses. The blast-radius attack model means your highest exposure is the weakest link in your vendor ecosystem, not your own infrastructure. If you are not in healthcare, monitor your critical service providers for signs of compromise in the 4-5 day window between initial access and encryption by deploying network and identity behavioral analytics rather than relying on signature-based detection, per Vectra AI's dwell-time analysis.
Scenario B (~30%): A dominant successor platform reconsolidates affiliate talent, restoring high-demand negotiation discipline. This is the scenario in which Check Point's analysis of The Gentlemen's 90/10 split proves to be a transitional recruitment mechanism for a platform that scales into the structural role LockBit once occupied. If you hold cyber insurance policies with ransomware coverage, reassess policy terms and sublimits; reconsolidation historically drives average ransom demand back upward as negotiation sophistication returns. If you are a risk officer, use the Chainalysis Q3 2026 update as the trigger point: a single group exceeding 20% victim share is the signal to revise premium expectations and incident response assumptions.
Scenario C (~15%): Sustained enforcement pressure, combined with declining payment rates, forces a structural shift away from encryption toward pure data-extortion and destruction-only attacks. Vectra AI documents that data-only extortion payment rates were already declining sharply as of Q4 2025. If encryption economics collapse further, some operators will shift toward data destruction or sabotage to maintain coercive leverage without the decryption key negotiation overhead. If your organization's recovery plan depends primarily on the availability of a decryption key, this scenario invalidates it. Organizations in all sectors should validate offline backup integrity and test recovery-without-key scenarios in the next two quarters regardless of scenario probability.
Analytical Limitations
- The active group counts cited (120+ for 2025, 124 per GuidePoint, 93 new variants per TRM Labs) are drawn from leak site monitoring and blockchain analytics that systematically miss attacks resolved without public disclosure; actual attack volume is higher than reported figures in all sectors.
- Sector-specific geographic targeting granularity beyond the US-Germany-India-Canada-Australia healthcare ranking is not available in current open sources; the claim that enforcement pressure is redirecting some affiliates toward less-protected developing-market organizations is directional only and would require corroboration from national CERT incident databases before driving investment decisions.
- The Gunra-Lazarus Group linkage rests on AhnLab reporting that has not been independently corroborated by Western threat intelligence vendors at the time of writing; the state-nexus RaaS pattern is plausible and operationally significant if confirmed, but this assessment treats it as illustrative rather than established.
- Average ransom and payment rate statistics (including the approximately 25% Q4 2025 payment rate from Vectra AI) are aggregates across victim size and sector; small and medium enterprises likely face materially different payment rates than enterprise targets, and the aggregate figure may not be decision-relevant for organizations outside the enterprise segment.
- The TRM Labs 2026 Crypto Crime Report is the primary source for the bridge-versus-mixer laundering shift; until Chainalysis or Elliptic publish comparable 2025-2026 attribution data, the 66% bridge growth figure carries single-source uncertainty on magnitude even while the directional shift is corroborated by the Akira operational case study and Europol's IOCTA 2026 observations on mixer decline.
Sources & Evidence Base
- UngradedRansomware Groups Evolve Affiliate Models | SOPHOS
secureworks.com
- Ungraded
- Ungraded
- INTERNET ORGANISED CRIME THREAT ASSESSMENT 2021
europol.europa.eu
- 2026 Global Ransomware Statistics Key Trends & Costs
deepstrike.io
- UngradedRansomware Trends 2026: AI Attacks & Defense Strategies
adaptivesecurity.com
- Top 10 Ransomware Groups of 2025
socradar.io
- UngradedRansomware & Extortion Activity | Analyst1
analyst1.com