SardineCon SF/2026

Learn More
Crypto & blockchain crime4 分で読めます

Ransomwareとは?

SUBSCRIBE

Ransomware is malware that encrypts a victim's data or locks their systems and demands a ransom, almost always in crypto, for the key to unlock it. Attacks increasingly steal data too for double extortion, and any payment to a sanctioned actor carries legal prohibition risk on top of the loss itself.

What is ransomware, in plain English?

Ransomware is malicious software that takes a victim hostage digitally. It encrypts files or locks systems so the victim can no longer use them, then displays a demand: pay a ransom, almost always in cryptocurrency, and you get the decryption key to restore access. It hits individuals, hospitals, city governments, and large companies alike, and the crypto payment is what makes the extortion practical at scale.

Modern attacks often add double extortion. Before encrypting, the attacker quietly steals a copy of the data, then threatens to publish or sell it unless paid, even if the victim could restore from backups. That turns a recovery problem into a data-breach threat and increases the pressure to pay. Some go further with additional threats, but the core leverage is the same.

For a fraud or AML program, the payment side is where ransomware becomes a compliance issue. The ransom moves in crypto, which means it leaves a traceable on-chain trail, and the destination address may belong to a sanctioned group. Paying, or helping to pay, a sanctioned actor can be a violation in its own right, separate from the underlying loss.

How a ransomware attack unfolds

Most incidents follow a recognizable path from break-in to payout:

  1. Access — Break in. Attackers enter through phishing, stolen credentials, or an unpatched system.
  2. Steal — Exfiltrate data. In double-extortion cases, a copy of sensitive data is quietly taken before anything is locked.
  3. Lock — Encrypt and demand. Files are encrypted, systems freeze, and a ransom note demands crypto for the key.
  4. Pay — Ransom is sent. The victim sends crypto to the attacker's address, creating an on-chain record.
  5. Launder — Cash out. Funds move through mixers and exchanges toward off-ramps, where investigators try to interdict.

Who is involved?

Who

Their role

The attacker

Deploys the malware, demands the ransom, and controls the receiving crypto address.

The victim organization

Faces locked systems and stolen data, and must decide whether and how to pay.

Incident responders

Investigate the breach, negotiate, and check whether the destination is sanctioned before any payment.

Compliance and exchanges

Screen ransom addresses against known clusters and interdict cash-out at regulated venues.

What it looks like in practice

In practice

A mid-sized company arrives one morning to find its files encrypted and a note demanding payment in crypto within a deadline. The attackers also claim to have copied customer records and threaten to leak them, the double-extortion play.

Before anyone moves money, the company's advisors screen the demand address against known ransomware and sanctions clusters. It matches a strain tied to a sanctioned group, which means paying could itself be a legal violation. The team pivots to restoring from backups and reporting the incident. On the compliance side, an exchange later spots funds from that same cluster arriving as a deposit, freezes them, and files a report, helping trace the operation's cash-out.

Why it matters to operators

Ransomware is where cybercrime and crypto compliance meet. The payment is the choke point: it has to move in crypto, which leaves a trail investigators can follow, and it has to cash out somewhere real, usually a regulated exchange. That gives compliance teams a genuine chance to screen ransom addresses, flag attacker clusters, and interdict funds before they disappear, which is why on-chain screening of these payments matters so much.

The sanctions angle raises the stakes. If the destination is tied to a sanctioned group, paying the ransom can turn a bad day into a separate legal violation for the victim and anyone who facilitates the payment. That is why responders screen the address first and tread carefully, and why regulators expect crypto businesses to catch ransom flows moving through their platforms.

What to watch for

  • Screen before paying. Check any ransom address against known ransomware and sanctions clusters. A sanctioned destination can make payment illegal.
  • Known-cluster deposits. Funds arriving at your platform from an address tied to a ransomware strain should trigger review and reporting.
  • Mixer and exchange hops. Ransom funds typically move through mixers toward off-ramps; trace them toward the cash-out point.
  • Double extortion. Data theft alongside encryption raises the pressure to pay even with good backups, and adds breach obligations.
  • Facilitation risk. Helping a victim pay a sanctioned group can create exposure for the facilitator, not just the victim.

Quick questions

Why do attackers demand crypto?

Crypto lets them receive large payments quickly across borders without a bank that could freeze or reverse the transfer. It is what makes extortion at scale practical, even though it also leaves an on-chain trail.

Can ransom payments be traced?

Yes, that is the good news for investigators. The payment moves on a public chain, so compliance teams can screen the destination and follow the funds through mixers and exchanges toward cash-out points.

What is double extortion?

The attacker steals a copy of the data before encrypting, then threatens to publish or sell it unless paid. That way even a victim with good backups still faces a leak, increasing the pressure to pay.

Why is paying a sanctioned group a problem?

Dealing with a sanctioned person or entity is prohibited for regulated parties. Paying such a group can be a separate legal violation on top of the loss, so responders screen the destination address first.

What is the difference from ransomware-as-a-service?

Ransomware is the malware and the attack. Ransomware-as-a-service is a business model where developers lease the malware to affiliates who run attacks and split the proceeds, which is why one strain hits many victims.

What should a crypto business do about ransom flows?

Screen deposit addresses against known ransomware and sanctions clusters, freeze and report matches, and cooperate with investigators tracing the funds. Catching cash-out is often where the operation is disrupted.

Go deeper

  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.
  • OFAC, US Treasury ↗ — Administers US sanctions programs, the SDN list, and licensing.

Ransomwareと併せて知っておきたい用語