Ransomware as a Service in Plain Terms
Ransomware as a service or RaaS, is a criminal business model where one group builds and maintains the ransomware and its payment and leak infrastructure, then rents it to other criminals called affiliates. The affiliates break into organisations and deploy the ransomware and the two sides split the proceeds.
The model matters because it removed the skill barrier. A criminal no longer needs to write ransomware to run a ransomware attack. They can rent a proven kit, follow the playbook and keep most of the money. That is how ransomware moved from a niche threat to one of the most common causes of serious business disruption.
The damage is not abstract in Sweden. In August 2025 the ransomware group DataCarry hit Miljödata, an HR software supplier used by around 80 percent of the country’s 290 municipalities. Roughly 200 municipalities were affected and according to the data protection authority IMY, personal data on about 1.5 million people was exposed. Miljödata refused to pay and the data was published anyway.
How the Ransomware as a Service Model Works
A RaaS operation runs like a business with a supply chain. At the top sit the developers, who write and update the ransomware, run the payment portals and host the leak sites where stolen data is published. They recruit affiliates and hand them a control panel, a ransomware builder and support, much as a software vendor serves its customers.

The affiliates do the breaking in. Many buy ready-made access from initial access brokers, a separate class of criminal that sells footholds into networks they have already compromised. Others get in with stolen passwords or by exploiting an unpatched internet-facing system. Once inside, the affiliate moves through the network, steals data and launches the ransomware.
The money is shared. The US Department of Justice says the administrator of LockBit, Dmitry Khoroshev, typically took about 20 percent of each ransom and left the rest to the affiliate who carried out the attack. LockBit stood out because affiliates collected the ransom first and then paid the core group its cut where most programs pay themselves first, a detail noted by the US cybersecurity agency CISA.
This division of labour is what makes RaaS dangerous. It lets skilled developers scale their product across hundreds of affiliates and it lets unskilled criminals rent capability they could never build. The result is more attacks from more people against organisations of every size.
The RaaS Ecosystem and Extortion Tactics
RaaS is not one gang. It is a shifting market of competing programs and affiliates move between them for the best terms. When law enforcement disrupts one brand, its affiliates often reappear under another. CISA noted that RansomHub grew quickly by attracting experienced affiliates from LockBit and ALPHV.
Some names recur. LockBit was for years the most deployed program worldwide. DarkSide, REvil, ALPHV (also called BlackCat), Akira and RansomHub have all run affiliate operations. Their tools differ but the pressure tactics are similar.
Modern RaaS attacks rarely stop at encryption. In double extortion the affiliate steals a copy of the data before encrypting it, then threatens to publish it on a leak site unless you pay. This is why backups alone no longer end the crisis. The threat to leak your data remains even after you restore your systems.
Triple extortion piles on more pressure such as a denial-of-service attack against your website or direct messages to your customers and partners. The European Union Agency for Cybersecurity, ENISA, reports that double extortion and layered pressure are now standard across the ransomware landscape.
The Business Impact of a RaaS Attack
A RaaS attack hits an organisation in several ways at once and the ransom is often the smallest part.
- Downtime: Operations stop while systems are encrypted and can be down for days or weeks.
- The ransom: Demands run from thousands to tens of millions, paid in cryptocurrency.
- Data-leak extortion: Even after you restore from backups, stolen data can still be published, exposing customers and staff.
- Recovery and rebuild: Incident response, forensics, legal costs and system rebuilds usually dwarf the ransom.
- Regulatory exposure: A ransomware breach can trigger reporting duties and fines under NIS2 and GDPR.
The scale is significant. The FBI reports that ransomware was again the most pervasive threat to US critical infrastructure in 2024 with complaints up 9 percent on the year, and that its five most reported strains, Akira, LockBit, RansomHub, Fog and Play, all run as affiliate operations.
One program shows the reach. The US Department of Justice says LockBit attacked more than 2,500 victims across at least 120 countries and extorted at least 500 million dollars before an international operation disrupted it in 2024.
Real-World RaaS Cases
Colonial Pipeline and the DarkSide Affiliate
In May 2021 an affiliate of the DarkSide RaaS group shut down Colonial Pipeline, the largest fuel pipeline in the United States for about six days. The route in was mundane. Attackers used a single leaked password for an old VPN account that had no multi-factor authentication.
Colonial paid 75 bitcoin worth about 4.4 million dollars at the time within a day. A month later the US Department of Justice traced the blockchain and clawed back 63.7 of those bitcoin. Multi-factor authentication on every remote-access account stops a single stolen password from working.
Coop Sweden and the Kaseya Supply Chain
Coop is one of Sweden’s largest grocery chains. In July 2021 it had to close around 800 stores because its checkout systems stopped working. Coop itself was never breached. The attack reached it through a supplier, a classic supply chain attack.

The REvil RaaS group had compromised Kaseya VSA, a remote-management tool used by managed service providers and pushed a poisoned update. Coop’s supplier used that tool so the ransomware spread down the chain. REvil demanded around 70 million dollars for a universal decryptor while more than a thousand businesses worldwide were caught up in the same incident.
No amount of internal patching would have saved Coop because the flaw sat in a supplier’s tool. You reduce this risk by assessing the vendors and tools that can reach your systems, monitoring their access and being ready to isolate them quickly.
Tietoevry and the Akira Attack
On the night of 19 to 20 January 2024 the Akira RaaS group encrypted part of a Tietoevry data centre in Sweden. Tietoevry runs IT services for many organisations so the damage spread. Its Primula payroll and HR platform used by more than 30 government agencies and most Swedish universities went down along with retailers and the cinema chain Filmstaden.
Tietoevry isolated the affected platform to contain the attack. A joint FBI and CISA advisory reports that Akira began in 2023 and had already hit more than 250 organisations by early 2024. Akira’s usual way in is an unpatched internet-facing VPN or a remote-access account without MFA so the practical defence is to patch those systems promptly and require MFA on all remote access.
LockBit and Operation Cronos
LockBit was the most prolific RaaS program in the world with nearly 200 affiliates and by the DOJ’s account more than 2,500 victims. In February 2024 a task force led by the UK National Crime Agency, the FBI and Europol seized its servers, took over its leak site and released decryption keys to victims.
LockBit tried to relaunch within days which is why agencies call this a disruption rather than a knockout. Still, it landed. By ENISA’s 2025 threat report LockBit had gone quiet, most likely because of the operation. The takeaway for defenders is that reporting an attack to law enforcement matters and that recoverable backups and shared decryptors can undo the damage without a payment.
Ransomware as a Service and Compliance
A ransomware attack is not only an IT problem in Sweden. It triggers legal duties and the rules changed recently.
Sweden brought the EU NIS2 Directive into national law through Cybersäkerhetslagen (SFS 2025:1506), in force since 15 January 2026. If your organisation is in scope, a significant ransomware incident must be reported in a set cascade, an early warning within 24 hours, a fuller notification within 72 hours and a final report within one month. Under Article 20 the board is accountable and can be held personally liable.
One practical point catches people out. Since 1 July 2026 these reports no longer go to MCF (formerly MSB). The national CSIRT, CERT-SE and the NIS2 contact point moved to the National Cyber Security Centre (NCSC) at FRA through an amendment to the regulation, SFS 2026:623. Report a significant incident to CERT-SE at NCSC and FRA.
Financial firms have a parallel regime. Under DORA, banks, insurers and other financial entities must manage and report ICT incidents to Finansinspektionen so a ransomware attack there is handled under DORA as well as NIS2.
If the attack exposes personal data and double extortion usually does, GDPR Article 33 requires you to notify the data protection authority IMY within 72 hours. The Miljödata case led to one of the largest data-protection investigations in Sweden’s history.
Paying carries its own legal risk. The US Treasury’s sanctions office, OFAC, strongly discourages ransom payments and warns that paying an actor with a sanctions link can itself breach sanctions, a risk that extends to the banks and insurers who help. Several ransomware operators including LockBit’s leader have been sanctioned. Europol’s No More Ransom project offers free decryption tools as a legal alternative to paying.
How to Defend Against Ransomware as a Service
You cannot stop criminals from renting ransomware. You can make your organisation a poor target and limit the damage if an affiliate gets in. The controls below cut off the routes RaaS affiliates rely on.

- Require multi-factor authentication on every remote-access, email and admin account. A stolen password should never be enough on its own.
- Patch internet-facing systems quickly especially VPNs and remote-access gateways which are common entry points.
- Keep offline, immutable backups and test that you can restore from them. Backups are what let you recover without paying.
- Segment your network and apply least privilege so one compromised account cannot reach everything.
- Run continuous detection so an intrusion is caught during the hours before encryption. Managed detection and response gives smaller teams round-the-clock cover.
- Train staff to spot phishing and report it since stolen credentials and malicious links are how many affiliates get their first foothold.
- Write and rehearse an incident-response plan that covers who to call, how to report to CERT-SE and how you would operate with systems down.
One habit sits above the rest. Assume you will be hit and build so that a single breach cannot become a full shutdown. The FBI has handed out thousands of decryption keys since 2022, avoiding more than 800 million dollars in payments, a reminder that reporting early and keeping backups beats paying.



