惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
博客园 - 聂微东
博客园 - 司徒正美
Hugging Face - Blog
Hugging Face - Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Google DeepMind News
Google DeepMind News
Recent Announcements
Recent Announcements
IT之家
IT之家
J
Java Code Geeks
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
I
InfoQ
爱范儿
爱范儿
Vercel News
Vercel News
Apple Machine Learning Research
Apple Machine Learning Research
阮一峰的网络日志
阮一峰的网络日志
博客园 - Franky
U
Unit 42
酷 壳 – CoolShell
酷 壳 – CoolShell
腾讯CDC
F
Fortinet All Blogs
V
Visual Studio Blog
人人都是产品经理
人人都是产品经理

RUSI: Latest Publications

Recording: Reflections, 25 Years After 9/11 How Low-Skill Russian Sabotage Drives High-Stakes Outcomes The Battery Gap: Building Industrial Strength for a Military Edge Everybody Loves Our Dollars: How Money Laundering Won Doing Business with Criminals: Between Exclusion and Surveillance Steal Barentsburg: Caught Between Worlds Why FSRBs are Central to Sustaining the FATF’s Effectiveness The Dual Burden of FATF Compliance for Developing Countries Proliferation Financing Risk Assessments The FATF Needs to Tackle How War is Financed Is the Financial Action Task Force Fit for the Future? Revision to FATF Recommendation 8: Impacts on Sub-Saharan Africa Sanctions and the Militarisation of Ukraine's Children Cutting Through the Myths of Blockchain Analysis Combatting the Illicit Financing of Hybrid Threats Reassessing Structural, Contextual Constraints in FATF Evaluations A Strong Taskforce Needs a Strong Secretariat Does the FATF Take a Risk-Based Approach? Illicit Finance in a Fragmenting World The Special Relationship in an Era of Strategic Transformation Stay Humble and Listen: Elisa de Anda Madrazo on Leading the FATF Editorial: RUSI Journal, Issue 5, 2026 Security Cooperation Among the Arctic NATO Allies Alliance ‘Dots on the Map’: Jan Mayen and the High North Connection The Russian Way of War: Precision Strike Evolution Episode 127: Great Power Diplomacy: How to Prevent a Third World War The Overstretch Facing the US Navy Australia’s Democratic Coordination in an Age of Foreign Interference Hybrid Navy: Building the Maritime Operating System
Beyond the Hype: AI, Ransomware and Business Models
Will Lyne and Jamie MacColl,[object Object],[object Object] · 2026-08-27 · via RUSI: Latest Publications

AI is not (yet) fundamentally reinventing cybercrime. For bold predictions on how it will change, look to history to understand what drives criminal behaviour online.

We are frequently told by cyber security marketers that we are in the midst of an AI-powered revolution for cybercrime. The short version of these claims is that AI will significantly lower the barrier of entry for would-be cybercriminals, allow them to create autonomous variants of ransomware that will allow them to overwhelm defenders at a scale previously thought impossible.

However, such assessments start from a false premise about what drives the behaviour of cybercriminals. The history of modern cybercrime demonstrates two things. First, that cybercriminal behaviour has been driven more by innovation in business models than technical capabilities. Second, that cybercriminals tend to innovate when they have to, not simply because a new kind of technology becomes available.

Follow the Money, Not the Technology

The levels of innovation within the cybercrime ecosystem are often overstated. Threat actors are profit-seeking actors, like technology companies, but they are dissimilar in that they rarely pursue innovation for its own sake. In an operating environment where the supply of potential addressable victims is effectively unlimited, due to low global resilience levels, cybercriminals generally use what works and stick with it. Most threat actors are not innovative, especially when many cybercrime groups have fragmented in the past couple of years and operate with a ‘Minimum Viable Product’ philosophy; if phishing emails work, send phishing emails; if existing malware continues to compromise organisations, there is little incentive to redesign it. They resemble badly run tech startups as opposed to research labs.

Innovation only occurs when it increases profit or restores profitability after measures (such as increased resilience) systematically reduce returns. Most cybercriminals are not innovators but followers. Money – not technology – is the primary driver of change within the cybercrime ecosystem, and there is little financial benefit in taking the time and risk of innovating when you already have something that works.

The History of Ransomware as a Lesson for the Future

In the case of ransomware, it is also instructive that when innovation has occurred, it is largely through new business strategies rather than technical capabilities. Early attempts at cyber extortion failed to generate significant revenues until the right economic opportunities aligned with the adoption, by cybercriminals, of new strategies and business models to exploit. The rise of the modern ransomware threat as a cybercriminal business model in the late 2010s was not driven by novel technical capabilities – attacks relied on many elements common to banking malware that had been around for nearly a decade.

While cybercriminals will likely continue to experiment with such agents, widespread adoption is unlikely unless existing methods significantly decrease in profitability

Instead, ransomware was driven by profit focused factors, including:

  1. A pivot from targeting individuals to targeting organisations, who could afford larger ransoms.
  2. Having cybercriminals actively running attacks (‘human operated’ ransomware) and tailoring activity, such as what data to steal and initial ransom demands, to the victim.
  3. The specialisation of threat actors into certain elements of the business model, resulting in the commoditisation of capabilities and productivity gains.
  4. Adopting organisational structures sometimes resembling businesses allowed scaling.
  5. The emergence of cryptocurrencies, providing a reliable, direct, cheap and scalable way to cash out profits.
  6. Developing distinct brands to build both notoriety and establish trust when negotiating with victims.

In short, innovation in ransomware has largely come not from technical developments, but from how cybercriminals organise themselves and operationalise the access they have to victims.

AI Improves But Does Not Revolutionise the Ransomware Business Model

This has not prevented significant speculation about AI turning ransomware into something even more harmful and widespread than it already is. One example of this is fear of a vulnerability apocalypse – or ‘vulnpocalypse’ – overwhelming cyber security defenders and giving criminals access to a swathe of victims. However, the potential opportunities from the technical vulnerabilities that can be identified by AI tools such as Mythos, for example, are unlikely to cause a significant shift in ransomware victimisation, given access to potential victims is not a limiting factor on the current, profitable, business model. For example, when the Cl0p ransomware group exploited the MOVEit vulnerability to compromise data relating to over a thousand victims in one go, there were indications that managing the volume of victims generated operational challenges for the group.

There have also been recent reports of agentic AI ransomware, such as JADEPUFFER, but this was not an end-to-end automated operation; a human is still directing target selection, building the infrastructure and overseeing attacks at every stage. While cybercriminals will likely continue to experiment with such agents, widespread adoption is unlikely unless existing methods significantly decrease in profitability.

Enjoy our analysis and research? Ensure it shows up first on Google

Help your search results show more from RUSI. Adding RUSI as a preferred source on Google means our analysis appears more prominently.

At present, then, there is little evidence that AI has changed the operating models of cyber extortionists or will in the short- to medium-term future. Most observed use is, like much of cybercrime, far more mundane. AI is being utilised to optimise the different steps in the cybercriminal business model. It increases the productivity of some steps in a ransomware operation, but not the business model itself. BlackBasta's leaked internal chats show the group discussing ChatGPT use for phishing, debugging persistence tools and verifying stolen email addresses. In other words, for the kind of mundane tasks that software developers or project managers may use such tools for.

The idea of autonomous ransomware and AI reducing organisational constraints that currently limit ransomware operations should not be dismissed. However, there is currently limited evidence that ransomware groups are successfully deploying AI in this manner. It is more likely to augment existing ransomware operations than fundamentally transform them in the near term. The more important question is where it might alter the economics of ransomware instead.

The Potential Impact of AI on Ransomware Business Models

If access was never a constraint, the question is where AI will have an impact. Historically, it has been hard for ransomware groups to clean and exploit the data they have stolen in ransomware attacks. Attacks have routinely hoovered up entire databases using automated scripts resulting in massive repositories of unstructured data that they lack the resources and knowledge (including English language skills) to review. Critical intellectual property or personally identifiable information is often buried within vast quantities of less valuable data. In the short-term, rather than replacing cybercriminals with agentic AI end-to-end capabilities, the greatest scope for innovation is around integrating AI into new ransomware business models and exploiting the access that criminals already have to their victims. There are two specific areas of risk, with some emerging evidence that this is already happening to some extent. Both concern how to more effectively monetise data stolen by ransomware criminals.

Subscribe to the Cyber & Tech Newsletter

Stay up to date with the latest publications and events from the Cyber and Tech Research Group

Subscribe to the RUSI Newsletter

Get a weekly round-up of the latest commentary and research straight into your inbox.

The first is using AI to better exploit stolen data and to more effectively extort victims. A recent GuidePoint Security report showed how the FulcrumSec ransomware group, who primarily operate a data-exfiltration and extortion business model, used an LLM to analyse stolen data for leverage directly in the negotiation engagement with the victim. Should this prove effective in improving payment rates and values, there is the potential this could become another specialised role within the cybercrime ecosystem and offered as-a-service.

The second is using AI to monetise stolen data beyond the initial attack. Ransomware groups have stolen a huge volume of data in ransomware attacks, especially since data exfiltration became the norm in double extortion attacks around 2022. It is unlikely they have deleted this data – storage is cheap, and the NCA showed in their disruption of LockBit in 2024 that even for victims who paid, stolen data was never deleted. Cybercriminals see value in it. However, in March 2026 a specialized cybercriminal dark-web marketplace launched called Leak Bazaar, which is designed to monetise data stolen in ransomware attacks, adding a second level of victimisation on top of the victim of the original attack. If platforms like this prove sustainable, they could create a significant secondary market for stolen data.

Conclusion

There is limited evidence of widespread adoption of these applications. It remains more profitable to run ransomware operations with proven business models, which explains why AI adoption by cybercriminals has and will continue to be incremental. Analysts and policymakers should therefore resist speculative visions of AI-driven cybercrime and focus instead on where AI is actually easing friction in the existing business model. The clearest signal so far is downstream from the point of access. AI’s impact on ransomware may be felt first in helping cybercriminals better exploit stolen data in their attacks, and then monetising the huge backlog of stolen data as opposed to acquiring more of it.


keywords

WRITTEN BY

Will Lyne

Guest Contributor

View profile

Jamie MacColl

Senior Research Fellow

Cyber and Tech

View profile