More than $2 billion in payments from 4,000 ransomware incidents reported to Treasury in recent years
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内。用户已经提供了文章的详细内容,我得先快速浏览一下,抓住关键信息。 首先,文章提到从2022年到2024年,公司向勒索软件团伙支付了超过21亿美元。这三年的数据几乎超过了前九年的总和。然后,2023年是支付金额最高的一年,达到了11亿美元,比2022年增加了77%。主要的勒索团伙包括ALPHV/BlackCat、Akira、LockBit等。 接下来,文章指出在执法部门打击后,2024年的勒索事件有所减少。支付方式主要使用比特币,通过未受监管的加密货币交易所洗钱。此外,勒索软件主要针对金融、制造和医疗行业。 我需要把这些信息浓缩到100字以内。要确保包含时间范围、总金额、最高年份、主要团伙以及支付方式和目标行业。同时,要避免使用“这篇文章”或“内容总结”这样的开头。 最后检查一下字数是否符合要求,并确保信息准确无误。 </think> 从2022年至2024年,企业向勒索软件团伙支付超21亿美元赎金,其中2023年创历史新高(约11亿美元),主要团伙包括ALPHV/BlackCat、Akira和LockBit等。赎金多以比特币支付并通过未受监管的加密交易所洗钱。 2025-12-8 21:31:12 Author: therecord.media(查看原文) 阅读量:4 收藏

Companies made more than $2.1 billion in payments to ransomware gangs from January 2022 to December 2024, a U.S. government report revealed. 

The Treasury Department’s Financial Crimes Enforcement Network (FinCEN) released a study last week covering 4,194 ransomware incidents that were reported through the Bank Secrecy Act over the three-year period. 

The department noted that the figures from the three-year stretch nearly outpaced all of the reports and ransomware payments from the previous nine-year period of 2013 to 2021 — where they received 3,075 reports and saw approximately $2.4 billion in ransomware payments.

The report found that ransomware payments reached an all time high in 2023 with about $1.1 billion making its way into the hands of hackers — a 77% increase compared to 2022. 

Of the 267 ransomware gangs tracked by the department, the ALPHV/BlackCat group was the most prevalent alongside Akira, LockBit, Black Basta and Phobos

The report noted that following the law enforcement takedowns of ALPHV and LockBit, there were noticeable decreases in ransomware incidents in 2024. After seeing 1,512 incidents in 2023, there were 1,476 reported in 2024 that led to about $734 million in payments. 

Throughout the report, 2023 stood out as a particularly damaging year for companies. The median ransomware payment peaked in 2023 at $174,000 — significantly more than the $124,097 in 2022 and $155,257 in 2024. 

Ransomware gangs targeted financial services firms, manufacturing companies and the healthcare industry the most, according to the report.

About 97% of payments were made in Bitcoin, the Treasury Department noted, adding that most gangs used unregulated cryptocurrency exchanges to launder the funds. The report also tied different ransomware gangs to several of the same initial access vendors. 

Screenshot 2025-12-08 at 2.09.40 PM.png

Image: FinCEN

Leading ransomware variants

The 10 ransomware variants with the highest cumulative payments accounted for $1.5 billion over the 2022-2024 period.  

While ALPHV earned nearly $400 million in ransom payments, LockBit saw a ransom total of $252.4 million and Black Basta brought in $137.7 million. Hive, which had $96.3 million in earnings, had the highest median incident value of $411,283.

Akira was responsible for the largest number of ransomware reports at 376, followed by ALPHV and LocKBit which each accounted for 353 incidents. 

The report also covers the ways ransomware gangs communicated with companies and noted that several gangs made further financial demands even after receiving initial ransom payments.

The findings add context to the constantly evolving ransomware ecosystem, which gained national prominence following the 2021 Colonial Pipeline attack that had real world impacts on thousands of people across the East Coast of the U.S. 

Since then, several ransomware incidents have caused chaos around the world, including attacks on major companies like UnitedHealth, the Industrial and Commercial Bank of China and Synnovis as well as the governments of Dallas, Oakland, Costa Rica, Albania, Bermuda and others

The U.S. led the creation of the International Counter Ransomware Task Force in 2023 that involved dozens of countries but the effort has had mixed success because most ransomware gangs are based in Russia or other countries that will not extradite their citizens.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/fincen-treasury-2-billion-ransomware-payments-report
如有侵权请联系:admin#unsafe.sh