A hospital's files are encrypted. The ransom note includes a link to a live chat. The company opens it expecting silence or threats. Instead, someone on the other end responds within minutes, walks them through the payment process, answers questions about the decryption tool, and offers a "discount" for paying quickly — the same tone, the same scripts, the same faint apology-for-the-inconvenience energy as a telecom retention line.

That chat wasn't staffed by the person who broke in. It almost never is anymore. And understanding who actually was on the other end of it is the key to understanding modern cybercrime.

The Setup

Most people's mental image of a ransomware attack still involves one person: a skilled hacker, alone at a keyboard, breaking into a network, encrypting it, and demanding payment. That image made sense a decade ago. It doesn't anymore, and the gap between the image and the reality is exactly why ransomware keeps growing even as individual gangs get arrested, sanctioned, and taken down.

Ransomware revenue hit roughly $529.2 million in the first quarter of 2026 alone, up 39% from the prior year. That kind of scale doesn't come from lone operators. It comes from an industry — one with specialists, suppliers, contracts, profit-sharing arrangements, and yes, customer support. Once you see the structure underneath a single attack, a lot of what seems confusing about ransomware — why it survives takedowns, why victims get "good service," why new groups appear the moment old ones vanish — stops being confusing at all.

What Everyone Assumed

The assumption is baked into the language itself. We talk about "the attacker" as if ransomware is committed by a single actor with a single skill set — someone technical enough to write malware, break into a network, move through it undetected, and extract payment, all as one continuous act by one person or tightly-knit crew. Law enforcement headlines reinforce it: "hacker arrested," "gang leader identified," as if removing one name ends the operation.

Almost none of that is how it actually works anymore. Modern ransomware isn't committed by an attacker. It's assembled — by a supply chain of specialists who often never speak to each other and sometimes don't even know each other's real names.

This matters because it changes what "stopping ransomware" even means. Arrest one skilled hacker, and you've removed one person from a market with thousands of interchangeable participants, each renting a piece of the same infrastructure. The market itself doesn't notice.

What Actually Happened

Here's the supply chain, broken into the roles that actually get paid. It starts with the Initial Access Broker — someone whose entire job is breaking into networks and then selling that access, not using it. IABs don't deploy ransomware. They compromise a company, verify the access still works, and list it for sale on criminal forums, typically for $500 to $5,000 depending on the size and sector of the victim. Researchers tracked IABs earning at least $14 million in 2025 doing nothing but this — the equivalent of a locksmith who breaks in, confirms the door is open, and sells that fact to someone else entirely.

The buyer is usually an affiliate — someone who rents ready-made ransomware from a Ransomware-as-a-Service operation the same way a small business rents point-of-sale software. The affiliate doesn't need to write malware or maintain encryption tooling. They buy access from an IAB, deploy the RaaS platform's ransomware against it, negotiate with the victim, and keep the overwhelming majority of whatever gets paid — typically 70% to 90%, with the platform developers taking a smaller cut for maintaining the tools. One fast-growing group, "The Gentlemen," has been offering affiliates a 90% cut specifically to undercut competitors and pull talent away from rival platforms, treating affiliate recruitment the way any software company treats a competitive sales incentive.

Around this core sits an entire supporting economy: developers who build and maintain the encryption and negotiation tooling; "packer" services that disguise malware to slip past antivirus; bulletproof hosting providers who rent server infrastructure specifically to operators no legitimate host would touch; and money-laundering specialists who convert ransom cryptocurrency into cash through layered exchanges. Access to this ecosystem is coordinated through dedicated marketplaces — in January 2026, U.S. law enforcement seized RAMP, a major Russian-language forum that had functioned for years as a trading floor connecting IABs, affiliates, and RaaS operators. And yes, the customer support is real: RaaS platforms provide affiliates with negotiation scripts, decryption-testing tools, and live chat interfaces, because a victim who can be walked smoothly through paying is a victim more likely to pay at all. The professionalism isn't an accident. It's a conversion-rate optimization.

The pattern behind all of it

Every role in this chain is designed to be replaceable and specialized, exactly like a legitimate outsourced supply chain. Nobody needs to be a generalist genius. They only need to be good enough at one narrow job, because the market handles the rest.

Decoded

The mental model that changes everything: stop picturing "the attacker" as a person, and start picturing them as a market. A market doesn't get arrested. It doesn't retire. When one RaaS platform gets sanctioned or one forum gets seized, like RAMP in January, activity dips for a few weeks and then reappears under a new name, on a new forum, staffed by the same affiliates and the same IABs, because the specialists never went anywhere — only the storefront changed. This is why ransomware groups that "shut down" so often turn out to have simply rebranded within months.

This reframes the defensive question you should actually be asking. "Could a skilled hacker breach us?" is the wrong question, because it assumes a single determined adversary sizing up your specific defenses. The better question is "which specialized role in this supply chain could reach us?" — because you're not defending against one opponent's creativity. You're defending against a division of labor where someone, somewhere, is specifically good at exactly the gap you happen to have: a leaked credential an IAB is already selling, an unpatched VPN appliance a scanner already flagged, an employee who'll click the one phishing template that's converting this month. You don't need to out-think a genius. You need to not be the cheapest item on a very efficient shelf.

What sits with me about that customer support chat isn't the crime. It's the banality of it — the same scripted reassurance, the same "let us know if you have questions," that you'd get from any subscription service you were trying to cancel. That banality is the tell. It means someone, somewhere, treated victim conversion as a process worth optimizing, the same way a legitimate business optimizes checkout flow. So here's the question worth sitting with: now that you know a ransom note might be answered by a support rep working a completely different job than the person who broke in — does the specific group's name in the headline matter less to you than it did five minutes ago?

This week's question

Now that you know the "attacker" is usually a supply chain of specialists, not one person — does the name of the ransomware group in a headline matter less to you than it did five minutes ago? Hit reply. I read every response.

Sources

Figures drawn from Group-IB and Coveware ransomware payment/blockchain-tracing analysis (Q1 2026 ransomware revenue of ~$529.2M, up 39% year over year); Rapid7 and Vectra AI research on Initial Access Broker pricing and the RaaS affiliate economy ($500–$5,000 per access, IABs earning $14M+ in 2025, 70–90% affiliate revenue splits); Security Affairs and Halcyon reporting on "The Gentlemen" ransomware group's 90% affiliate cut; and Cybernews/DataBreaches.net coverage of the January 2026 U.S. law enforcement seizure of the RAMP marketplace.

Think clearly,

— DJ Brar

SKBSEC | SKB Decoded  ·  www.skbsec.com