Threats & attacks

What is Ransomware as a Service?

The business guide to ransomware as a service, how the affiliate model works and the controls and reporting duties that limit the damage.

Key takeaways
  • Ransomware as a service (RaaS) is a criminal business model where developers rent ransomware to affiliates who break in and deploy it, then split the proceeds.
  • The model removed the skill barrier, so far more criminals can now run ransomware attacks.
  • The US Department of Justice says LockBit’s operator typically took about 20 percent of each ransom and left the rest to the affiliate.
  • Double extortion means attackers steal data as well as encrypt it, so backups alone no longer end the crisis.
  • The FBI ranks ransomware as the most pervasive threat to US critical infrastructure, and its top 2024 strains all run as affiliate operations.
  • Swedish cases are real. Coop closed around 800 stores in 2021 through the Kaseya supply chain and Akira disrupted Tietoevry’s Primula payroll in 2024.
  • In Sweden, significant ransomware incidents are reported to CERT-SE at the NCSC (part of FRA), which took over from MCF on 1 July 2026, using a 24-hour, 72-hour and one-month cascade.
  • Paying is strongly discouraged and can breach sanctions, and it never guarantees recovery.
  • The controls that work are MFA everywhere, fast patching of internet-facing systems, offline tested backups, network segmentation and 24/7 detection.
  • Operation Cronos disrupted LockBit in 2024, but affiliates regrouped under other programs, so defence has to be continuous.

Ransomware as a Service in Plain Terms

Ransomware as a service or RaaS, is a criminal business model where one group builds and maintains the ransomware and its payment and leak infrastructure, then rents it to other criminals called affiliates. The affiliates break into organisations and deploy the ransomware and the two sides split the proceeds.

The model matters because it removed the skill barrier. A criminal no longer needs to write ransomware to run a ransomware attack. They can rent a proven kit, follow the playbook and keep most of the money. That is how ransomware moved from a niche threat to one of the most common causes of serious business disruption.

The damage is not abstract in Sweden. In August 2025 the ransomware group DataCarry hit Miljödata, an HR software supplier used by around 80 percent of the country’s 290 municipalities. Roughly 200 municipalities were affected and according to the data protection authority IMY, personal data on about 1.5 million people was exposed. Miljödata refused to pay and the data was published anyway.

How the Ransomware as a Service Model Works

A RaaS operation runs like a business with a supply chain. At the top sit the developers, who write and update the ransomware, run the payment portals and host the leak sites where stolen data is published. They recruit affiliates and hand them a control panel, a ransomware builder and support, much as a software vendor serves its customers.

The affiliates do the breaking in. Many buy ready-made access from initial access brokers, a separate class of criminal that sells footholds into networks they have already compromised. Others get in with stolen passwords or by exploiting an unpatched internet-facing system. Once inside, the affiliate moves through the network, steals data and launches the ransomware.

The money is shared. The US Department of Justice says the administrator of LockBit, Dmitry Khoroshev, typically took about 20 percent of each ransom and left the rest to the affiliate who carried out the attack. LockBit stood out because affiliates collected the ransom first and then paid the core group its cut where most programs pay themselves first, a detail noted by the US cybersecurity agency CISA.

This division of labour is what makes RaaS dangerous. It lets skilled developers scale their product across hundreds of affiliates and it lets unskilled criminals rent capability they could never build. The result is more attacks from more people against organisations of every size.

The RaaS Ecosystem and Extortion Tactics

RaaS is not one gang. It is a shifting market of competing programs and affiliates move between them for the best terms. When law enforcement disrupts one brand, its affiliates often reappear under another. CISA noted that RansomHub grew quickly by attracting experienced affiliates from LockBit and ALPHV.

Some names recur. LockBit was for years the most deployed program worldwide. DarkSide, REvil, ALPHV (also called BlackCat), Akira and RansomHub have all run affiliate operations. Their tools differ but the pressure tactics are similar.

Modern RaaS attacks rarely stop at encryption. In double extortion the affiliate steals a copy of the data before encrypting it, then threatens to publish it on a leak site unless you pay. This is why backups alone no longer end the crisis. The threat to leak your data remains even after you restore your systems.

Triple extortion piles on more pressure such as a denial-of-service attack against your website or direct messages to your customers and partners. The European Union Agency for Cybersecurity, ENISA, reports that double extortion and layered pressure are now standard across the ransomware landscape.

The Business Impact of a RaaS Attack

A RaaS attack hits an organisation in several ways at once and the ransom is often the smallest part.

  • Downtime: Operations stop while systems are encrypted and can be down for days or weeks.
  • The ransom: Demands run from thousands to tens of millions, paid in cryptocurrency.
  • Data-leak extortion: Even after you restore from backups, stolen data can still be published, exposing customers and staff.
  • Recovery and rebuild: Incident response, forensics, legal costs and system rebuilds usually dwarf the ransom.
  • Regulatory exposure: A ransomware breach can trigger reporting duties and fines under NIS2 and GDPR.

The scale is significant. The FBI reports that ransomware was again the most pervasive threat to US critical infrastructure in 2024 with complaints up 9 percent on the year, and that its five most reported strains, Akira, LockBit, RansomHub, Fog and Play, all run as affiliate operations.

One program shows the reach. The US Department of Justice says LockBit attacked more than 2,500 victims across at least 120 countries and extorted at least 500 million dollars before an international operation disrupted it in 2024.

Real-World RaaS Cases

Colonial Pipeline and the DarkSide Affiliate

In May 2021 an affiliate of the DarkSide RaaS group shut down Colonial Pipeline, the largest fuel pipeline in the United States for about six days. The route in was mundane. Attackers used a single leaked password for an old VPN account that had no multi-factor authentication.

Colonial paid 75 bitcoin worth about 4.4 million dollars at the time within a day. A month later the US Department of Justice traced the blockchain and clawed back 63.7 of those bitcoin. Multi-factor authentication on every remote-access account stops a single stolen password from working.

Coop Sweden and the Kaseya Supply Chain

Coop is one of Sweden’s largest grocery chains. In July 2021 it had to close around 800 stores because its checkout systems stopped working. Coop itself was never breached. The attack reached it through a supplier, a classic supply chain attack.

Real-World RaaS Cases

The REvil RaaS group had compromised Kaseya VSA, a remote-management tool used by managed service providers and pushed a poisoned update. Coop’s supplier used that tool so the ransomware spread down the chain. REvil demanded around 70 million dollars for a universal decryptor while more than a thousand businesses worldwide were caught up in the same incident.

No amount of internal patching would have saved Coop because the flaw sat in a supplier’s tool. You reduce this risk by assessing the vendors and tools that can reach your systems, monitoring their access and being ready to isolate them quickly.

Tietoevry and the Akira Attack

On the night of 19 to 20 January 2024 the Akira RaaS group encrypted part of a Tietoevry data centre in Sweden. Tietoevry runs IT services for many organisations so the damage spread. Its Primula payroll and HR platform used by more than 30 government agencies and most Swedish universities went down along with retailers and the cinema chain Filmstaden.

Tietoevry isolated the affected platform to contain the attack. A joint FBI and CISA advisory reports that Akira began in 2023 and had already hit more than 250 organisations by early 2024. Akira’s usual way in is an unpatched internet-facing VPN or a remote-access account without MFA so the practical defence is to patch those systems promptly and require MFA on all remote access.

LockBit and Operation Cronos

LockBit was the most prolific RaaS program in the world with nearly 200 affiliates and by the DOJ’s account more than 2,500 victims. In February 2024 a task force led by the UK National Crime Agency, the FBI and Europol seized its servers, took over its leak site and released decryption keys to victims.

LockBit tried to relaunch within days which is why agencies call this a disruption rather than a knockout. Still, it landed. By ENISA’s 2025 threat report LockBit had gone quiet, most likely because of the operation. The takeaway for defenders is that reporting an attack to law enforcement matters and that recoverable backups and shared decryptors can undo the damage without a payment.

Ransomware as a Service and Compliance

A ransomware attack is not only an IT problem in Sweden. It triggers legal duties and the rules changed recently.

Sweden brought the EU NIS2 Directive into national law through Cybersäkerhetslagen (SFS 2025:1506), in force since 15 January 2026. If your organisation is in scope, a significant ransomware incident must be reported in a set cascade, an early warning within 24 hours, a fuller notification within 72 hours and a final report within one month. Under Article 20 the board is accountable and can be held personally liable.

One practical point catches people out. Since 1 July 2026 these reports no longer go to MCF (formerly MSB). The national CSIRT, CERT-SE and the NIS2 contact point moved to the National Cyber Security Centre (NCSC) at FRA through an amendment to the regulation, SFS 2026:623. Report a significant incident to CERT-SE at NCSC and FRA.

Financial firms have a parallel regime. Under DORA, banks, insurers and other financial entities must manage and report ICT incidents to Finansinspektionen so a ransomware attack there is handled under DORA as well as NIS2.

If the attack exposes personal data and double extortion usually does, GDPR Article 33 requires you to notify the data protection authority IMY within 72 hours. The Miljödata case led to one of the largest data-protection investigations in Sweden’s history.

Paying carries its own legal risk. The US Treasury’s sanctions office, OFAC, strongly discourages ransom payments and warns that paying an actor with a sanctions link can itself breach sanctions, a risk that extends to the banks and insurers who help. Several ransomware operators including LockBit’s leader have been sanctioned. Europol’s No More Ransom project offers free decryption tools as a legal alternative to paying.

How to Defend Against Ransomware as a Service

You cannot stop criminals from renting ransomware. You can make your organisation a poor target and limit the damage if an affiliate gets in. The controls below cut off the routes RaaS affiliates rely on.

How to Defend Against Ransomware as a Service
  • Require multi-factor authentication on every remote-access, email and admin account. A stolen password should never be enough on its own.
  • Patch internet-facing systems quickly especially VPNs and remote-access gateways which are common entry points.
  • Keep offline, immutable backups and test that you can restore from them. Backups are what let you recover without paying.
  • Segment your network and apply least privilege so one compromised account cannot reach everything.
  • Run continuous detection so an intrusion is caught during the hours before encryption. Managed detection and response gives smaller teams round-the-clock cover.
  • Train staff to spot phishing and report it since stolen credentials and malicious links are how many affiliates get their first foothold.
  • Write and rehearse an incident-response plan that covers who to call, how to report to CERT-SE and how you would operate with systems down.

One habit sits above the rest. Assume you will be hit and build so that a single breach cannot become a full shutdown. The FBI has handed out thousands of decryption keys since 2022, avoiding more than 800 million dollars in payments, a reminder that reporting early and keeping backups beats paying.

Myths & Facts

Myth

Ransomware as a service is only a threat to big corporations.

If we have backups, ransomware cannot hurt us.

Paying the ransom is the fastest way to recover.

Taking down a ransomware group ends the threat.

RaaS attacks are too sophisticated to prevent.

Ransomware is purely an IT issue.

Fact

Affiliates target organisations of every size, including municipalities and mid-sized firms, because the rental model makes smaller attacks profitable too.

Double extortion means attackers also steal your data and threaten to publish it, so backups restore systems but do not remove the leak threat.

Payment is strongly discouraged, can breach sanctions and never guarantees a working decryptor. Attackers sometimes re-extort or leak the data anyway.

After Operation Cronos disrupted LockBit in 2024, its affiliates moved to other programs. The ecosystem reconstitutes, so the threat persists.

Most affiliates get in through stolen passwords or unpatched systems. MFA, prompt patching and offline backups block the common routes.

In Sweden a significant incident must be reported under Cybersäkerhetslagen, and a data leak triggers GDPR duties to IMY. Boards carry personal liability under NIS2.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. Your company runs an old VPN account with a password but no multi-factor authentication. IT says it is rarely used and low priority.

    What do you do?

    • Leave it, since it is rarely used
    • Add MFA now or disable the account
    • Change the password and move on
  2. You are hit by ransomware. You have clean offline backups and can restore everything. The attackers say they also copied your data and will publish it unless you pay.

    What is your position?

    • You are safe because backups will restore systems
    • Restore from backups and handle the leak as a reportable breach
    • Pay quickly to stop the leak
  3. A managed service provider that supports your systems is hit by ransomware through a tool it uses. You were not attacked directly.

    What matters most?

    • Nothing, because your own systems are patched
    • Assess and monitor supplier access and be ready to isolate it
    • Wait for the supplier to confirm before acting
  4. You confirm a significant ransomware incident at a Swedish organisation in scope of Cybersäkerhetslagen.

    Who do you report to and how fast?

    • MCF, within 24 hours
    • CERT-SE at the NCSC, part of FRA, starting with a 24-hour early warning
    • No one, unless data was stolen

Knowledge Test

  1. What does the 'as a service' in ransomware as a service mean?

    • The ransomware runs in the cloud
    • Developers rent ready-made ransomware to affiliates who carry out attacks
    • Victims subscribe to protection
    • It only targets service companies

    RaaS is a rental model where developers lease the ransomware and affiliates deploy it for a share of the proceeds.

  2. According to the US Department of Justice, roughly how much of each ransom did LockBit's operator typically take?

    • About half
    • About 90 percent
    • About 20 percent
    • Nothing

    The DOJ says LockBit's administrator typically took about 20 percent, leaving the rest to the affiliate.

  3. What is double extortion?

    • Encrypting data and also stealing it to threaten publication
    • Charging two separate ransoms
    • Attacking two companies at once
    • Using two types of malware

    In double extortion the attacker steals a copy of the data before encrypting, so a leak threat remains even after you restore.

  4. Why is paying a ransom discouraged?

    • It is always cheaper to pay
    • It is required by law
    • It removes all legal duties
    • It can breach sanctions and never guarantees recovery

    OFAC warns that paying a sanctioned actor can breach sanctions, and payment gives no guarantee of a working decryptor or data deletion.

  5. Since 1 July 2026, who receives significant NIS2 ransomware incident reports in Sweden?

    • MCF (formerly MSB)
    • CERT-SE at the National Cyber Security Centre (NCSC), part of FRA
    • The police only
    • The European Commission

    The CSIRT and NIS2 contact-point role moved from MCF to CERT-SE at NCSC and FRA on 1 July 2026 via SFS 2026:623.

  6. Which single control would have blocked the Colonial Pipeline intrusion?

    • A bigger ransom budget
    • Turning off email
    • Multi-factor authentication on the VPN account
    • Paying faster

    The attackers used a leaked password on a legacy VPN with no MFA, so MFA would have stopped them.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Most ransomware intrusions still begin with a person. An affiliate sends a convincing phishing email, reuses a leaked password or talks someone into approving a login. Staff who can spot these attempts and report them quickly close the most common door into your network.

Training also shapes how a crisis unfolds. A team that knows to raise the alarm early, preserve evidence and follow the incident-response plan gives responders the hours that decide whether an intrusion is contained or becomes a full encryption event.

Frequently Asked Questions

What is ransomware as a service in simple terms?

Ransomware as a service (RaaS) is a criminal business model where one group builds the ransomware and rents it to others. These affiliates break into organisations and deploy the ransomware, then split any ransom with the developers. It works much like a legitimate software subscription, but for extortion.

How does the ransomware as a service business model work?

In the RaaS model, developers maintain the ransomware, payment portals and data-leak sites, while affiliates carry out the attacks. Affiliates often buy access from initial access brokers or use stolen credentials. The US Department of Justice says LockBit's operator typically took about 20 percent of each ransom.

Is ransomware as a service illegal?

Yes. Building, renting, deploying or profiting from ransomware is a crime across the EU, the US and beyond. Authorities have indicted and sanctioned operators such as LockBit's leader, and international operations have seized RaaS infrastructure and arrested affiliates. Paying a sanctioned group can also carry legal risk.

What is the difference between ransomware and ransomware as a service?

Ransomware is the malicious software that encrypts or steals data for extortion. Ransomware as a service is the business model that sells that software to affiliates. RaaS industrialised ransomware, letting people with little technical skill run attacks and driving the sharp rise in incidents.

Should we pay a ransomware ransom?

Paying is strongly discouraged. The US Treasury's OFAC warns that paying an actor with a sanctions link can breach sanctions, and payment never guarantees a working decryptor or that stolen data will be deleted. Focus on offline backups and reporting to law enforcement instead.

Who do we report a ransomware attack to in Sweden?

Since 1 July 2026, significant incidents under Cybersäkerhetslagen are reported to CERT-SE at the National Cyber Security Centre (NCSC), part of FRA, which took over from MCF. The cascade is a 24-hour early warning, a 72-hour notification and a final report within one month.

What are double and triple extortion?

Double extortion is when attackers steal a copy of your data before encrypting it, then threaten to publish it unless you pay. Triple extortion adds further pressure, such as a denial-of-service attack or contacting your customers directly. Both mean backups alone no longer resolve the incident.

How do we protect our organisation against RaaS attacks?

Focus on the routes affiliates use. Require multi-factor authentication everywhere, patch internet-facing systems quickly and keep offline, tested backups. Add network segmentation, least privilege and continuous detection so an intrusion is caught before encryption. Train staff to report phishing, and rehearse an incident-response plan.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.