Crime and Justice Atlas

How Justice Is Served
Sign In
Text size
100%
Theme
Offense

Ransomware Extortion

Cyber and Technology-Enabled Offenses

Ransomware extortion is the offense of deploying malicious software that encrypts a victim's data or locks them out of their own computer systems, then demanding payment, typically in cryptocurrency, in exchange for restoring access, combining unauthorized computer access with the coercive demand-for-payment structure of traditional extortion applied to digital infrastructure. Modern ransomware operations frequently add a second layer of coercion known as double extortion, in which the attacker also exfiltrates a copy of the victim's data before encrypting it and threatens to publicly release or sell the stolen data even if the victim restores their own systems from backup without paying, increasing pressure on victims who might otherwise decline to pay a ransom. The offense has grown from a largely individual-victim nuisance into a major organized transnational criminal enterprise, with some ransomware operations functioning on a ransomware-as-a-service model in which developers lease their malicious software to affiliated criminal operators in exchange for a share of extorted proceeds, a structure criminologists studying cybercrime treat as a significant evolution in organized digital crime. Ransomware attacks against hospitals, municipal governments, and critical infrastructure operators have drawn particular law-enforcement and national-security attention beyond ordinary extortion cases, given the potential for the attack itself, independent of any ransom paid, to cause serious disruption to essential public services.

Facts
Classification Code
In the US state of Maryland, the original draft of bill HB 340 made creating ransomware a felony punishable by up to ten years in prison. 1
Typical Penalty
British ransomware attacker Zain Qaiser was jailed for more than six years at Kingston upon Thames Crown Court in 2019, described as the most prolific cyber criminal sentenced in the UK. 1
Elements of Offense
Ransomware coerces payment by encrypting or locking a victim's files, with the victim needing either a program that decrypts the files or an unlock code that reverses the payload's changes to regain access. 1
Notable Example
The May 2021 DarkSide ransomware attack on the Colonial Pipeline forced a voluntary shutdown of the pipeline supplying 45 percent of fuel to the US East Coast, described as the worst cyberattack to date on US critical infrastructure. 1
Jurisdiction Variation
Australia requires ransomware victims, in some cases, to report their ransom payments to the Australian Signals Directorate, a disclosure duty distinct from the criminal-statute approach seen in Maryland. 1
Classification
Offense Grade
Serious or Indictable Offense 1
Connections

Associated With

Source Wikipedia: Cybercrime

Has Offense Grade

Entity-backed identity for the offense-grade enum value this offense already carries, resolved to a crime concept by an explicit value-to-entity map (phase 3 bucket conversion, docs\design_entity_backed_browse_buckets_20260928.md). The offense-grade fact itself stays on the offense unchanged.

In the Other Atlases
Sources
1. Ransomware (Wikipedia)
Wikipedia
  • lead paragraph, first sentence, Ransomware article
    Ransomware is a type of malware that takes the personal data of a victim hostage until a ransom is paid.
  • Legal aspects section, Maryland HB 340
    In the state of Maryland, the original draft of HB 340 made it a felony to create ransomware, punishable by up to 10 years in prison.
  • Operation section, payment paragraph
    Payment is virtually always the goal, and the victim is coerced into paying for the ransomware to be removed either by supplying a program that can decrypt the files, or by sending an unlock code that undoes the payload's changes.
  • Legal aspects section, final sentence
    Australia requires ransomware victims to report their payments to the Australian Signals Directorate in some cases.
  • DarkSide section
    The Federal Bureau of Investigation identified DarkSide as the perpetrator of the Colonial Pipeline ransomware attack, perpetrated by malicious code, that led to a voluntary shutdown of the main pipeline supplying 45% of fuel to the East Coast of the United States.
  • Zain Qaiser section, first sentence
    A British student, Zain Qaiser, from Barking, London was jailed for more than six years at Kingston upon Thames Crown Court for his ransomware attacks in 2019.
View the Source
Wikipedia: Cybercrime
Associated With: Cybercrime, Lead and law-enforcement sections
Quote, Associated With: Cybercrime, Lead and law-enforcement sections
Cybercrime encompasses a wide range of criminal activities that are carried out using digital devices and/or networks.
View the Source
Comments (0)
No comments yet. Be the first to share a thought.
Reader Challenges (0)
No disputes yet. Spotted an error or a better source? Open the first one.