Double-Extortion Ransomware: A Study of Cybercriminal Profit, Effort, and Risk

The work

AuthorsTom Meurs
Editors
Typephdthesis
Year2025
Also known asmeursdoubleextortion
Citekeymeurs2025doubleextortion

Where it appeared

PublisherUniversity of Twente

Identifiers

DOI10.3990/1.9789036564182
ISBN978-90-365-6417-5

Abstract

The increasing reliance on internet-based technologies has provided cybercriminals with numerous opportunities to exploit vulnerabilities in IT infrastructure. Among the various cyberattacks, double-extortion ransomware has emerged as particularly damaging and lucrative. Double-extortion ransomware involves both encrypting and exfiltrating the victim’s data, with the goal of publishing the stolen information if the ransom is not paid. Despite the growing prevalence of double-extortion ransomware, there is limited empirical research on the decision-making processes of ransomware offenders. In this dissertation we address this gap by applying Rational Choice Theory (RCT), which states that the decision-making processes of ransomware offenders is best understood through evaluating profitability, effort, and risks when conducting double-extortion ransomware attacks. Our main research question is: How do double-extortion ransomware attacks influence profitability, effort, and risk for offenders? Our first contribution is the development of a theoretical framework that explains the profit, effort, and risk of double-extortion ransomware with the concept of crime chains (Chapter 2). First, we introduce crime chains to define coordinated attacks and discuss how interconnected malicious activities enhance cybercriminals’ operations. Afterwards, we conduct a systematic literature review, to examine the advantages of online crime chains for offenders in terms of profitability, effort, and risks. Finally, we provide a theoretical framework to understand the trade-offs involved in double-extortion ransomware, showing how data exfiltration increases both effort and profits. Our second contribution is identifying how offender and victim characteristics, as well as contextual variables, influence the profitability of double-extortion xxii xxiii ransomware (Chapters 3–5). First, we combine data from police reports, incident response companies, and leak pages, to provide an empirical estimation of ransomware prevalence in the Netherlands between 2019 and 2022. Our analysis indicates that approximately 60% of ransomware attacks on medium- and large-sized companies go unreported, with an even higher rate for small companies. Afterwards, we use data from the police and incident response companies to examine how various offender and victim characteristics influence ransomware profitability. For instance, larger companies are targeted more frequently due to their ability to pay higher ransoms. Additionally, double-extortion ransomware tends to result in higher ransom payments compared to encryption-only ransomware, although it requires more effort from offenders. Our third contribution is differentiating ransomware targeting Network Attached Storage (NAS) devices from other types of ransomware in terms of modus operandi, victim characteristics, and timeline (Chapter 6). NAS ransomware, which primarily involves individuals with lower financial resources, typically results in smaller ransom demands. However, these attacks are highly automated and involve fewer stages compared to ransomware attacks targeting businesses. This automation allows offenders to compensate for lower profits per attack by maximizing returns through volume rather than high-value targets. Our fourth contribution is identifying the incentive for offenders to bluff about data exfiltration during ransomware attacks (Chapters 7 and 8). By analysing a signaling game model, we show how information asymmetry can increase offender profits without much additional effort. Offenders may falsely claim to have exfiltrated sensitive data to inflate ransom demands. Victims, often unaware of whether data has been exfiltrated due to misconfigured or deleted monitoring logs, may be more inclined to pay to prevent the publication of sensitive data, thereby increasing offender profits. However, when offenders themselves are unsure of the value of the stolen data, ransom payments may be mitigated, reducing profits. To conclude, information asymmetry illustrates how offenders may manipulate victims’ risk perception to enhance profitability with minimal extra effort. Our fifth contribution is demonstrating how various law enforcement interventions have led ransomware groups to publish fewer and less significant victims on leak pages (Chapter 9). We evaluate the impact of interventions such as arrests, cryptocurrency freezes, and leak page server takedowns on the profitability, effort, and risks for ransomware offenders. We assess the effectiveness of law enforcement interventions by analyzing the number and type of victims listed on offenders’ leak pages before and after interventions. Our findings show a reduction in the number and significance of victims published after interventions. The results indicate that decreasing the profits (e.g., decryptor releases and cryptocurrency freezes), increasing the effort (e.g., leakpage server takedown), or increasing the risk (e.g., sanctions and arrests) could effectively reduce activity of ransomware groups. In conclusion, this dissertation demonstrates that ransomware offenders’ decision-making is best understood by evaluating the elements of RCT: profit, effort, and risk. Additionally, the relationship between these elements offers insights into how interventions can be designed to make ransomware attacks less attractive, ultimately reducing their prevalence. We are confident that the findings in this dissertation will directly help policymakers and law enforcement agencies to combat ransomware more effectively.

A copy is held

pdf, 6.8 MB. Not published — it may be under copyright. The facts and links here are.

How it got here

How it got hereimport via bibtex
Added2026-08-04 00:00 UTC
Approved bya person 2026-08-16 15:37 UTC

Cite it as

@phdthesis{meurs2025doubleextortion,
  title        = {Double-Extortion Ransomware: A Study of Cybercriminal Profit, Effort, and Risk},
  author       = {Tom Meurs},
  year         = {2025},
  publisher    = {University of Twente},
  isbn         = {978-90-365-6417-5},
  doi          = {10.3990/1.9789036564182},
}

This record lives at https://refs.drheap.org/meurs2025doubleextortion/ and will keep doing so. It used to be called meursdoubleextortion, and those addresses still resolve to this one.