Beyond the Hype: AI, Ransomware and Business Models
AI is not (yet) fundamentally reinventing cybercrime. For bold predictions on how it will change, look to history to understand what drives criminal behaviour online.
We are frequently told by cyber security marketers that we are in the midst of an AI-powered revolution for cybercrime. The short version of these claims is that AI will significantly lower the barrier of entry for would-be cybercriminals, allow them to create autonomous variants of ransomware that will allow them to overwhelm defenders at a scale previously thought impossible.
However, such assessments start from a false premise about what drives the behaviour of cybercriminals. The history of modern cybercrime demonstrates two things. First, that cybercriminal behaviour has been driven more by innovation in business models than technical capabilities. Second, that cybercriminals tend to innovate when they have to, not simply because a new kind of technology becomes available.
Follow the Money, Not the Technology
The levels of innovation within the cybercrime ecosystem are often overstated. Threat actors are profit-seeking actors, like technology companies, but they are dissimilar in that they rarely pursue innovation for its own sake. In an operating environment where the supply of potential addressable victims is effectively unlimited, due to low global resilience levels, cybercriminals generally use what works and stick with it. Most threat actors are not innovative, especially when many cybercrime groups have fragmented in the past couple of years and operate with a ‘Minimum Viable Product’ philosophy; if phishing emails work, send phishing emails; if existing malware continues to compromise organisations, there is little incentive to redesign it. They resemble badly run tech startups as opposed to research labs.
Innovation only occurs when it increases profit or restores profitability after measures (such as increased resilience) systematically reduce returns. Most cybercriminals are not innovators but followers. Money – not technology – is the primary driver of change within the cybercrime ecosystem, and there is little financial benefit in taking the time and risk of innovating when you already have something that works.
The History of Ransomware as a Lesson for the Future
In the case of ransomware, it is also instructive that when innovation has occurred, it is largely through new business strategies rather than technical capabilities. Early attempts at cyber extortion failed to generate significant revenues until the right economic opportunities aligned with the adoption, by cybercriminals, of new strategies and business models to exploit. The rise of the modern ransomware threat as a cybercriminal business model in the late 2010s was not driven by novel technical capabilities – attacks relied on many elements common to banking malware that had been around for nearly a decade.
While cybercriminals will likely continue to experiment with such agents, widespread adoption is unlikely unless existing methods significantly decrease in profitability
Instead, ransomware was driven by profit focused factors, including:
- A pivot from targeting individuals to targeting organisations, who could afford larger ransoms.
- Having cybercriminals actively running attacks (‘human operated’ ransomware) and tailoring activity, such as what data to steal and initial ransom demands, to the victim.
- The specialisation of threat actors into certain elements of the business model, resulting in the commoditisation of capabilities and productivity gains.
- Adopting organisational structures sometimes resembling businesses allowed scaling.
- The emergence of cryptocurrencies, providing a reliable, direct, cheap and scalable way to cash out profits.
- Developing distinct brands to build both notoriety and establish trust when negotiating with victims.
In short, innovation in ransomware has largely come not from technical developments, but from how cybercriminals organise themselves and operationalise the access they have to victims.
AI Improves But Does Not Revolutionise the Ransomware Business Model
This has not prevented significant speculation about AI turning ransomware into something even more harmful and widespread than it already is. One example of this is fear of a vulnerability apocalypse – or ‘vulnpocalypse’ – overwhelming cyber security defenders and giving criminals access to a swathe of victims. However, the potential opportunities from the technical vulnerabilities that can be identified by AI tools such as Mythos, for example, are unlikely to cause a significant shift in ransomware victimisation, given access to potential victims is not a limiting factor on the current, profitable, business model. For example, when the Cl0p ransomware group exploited the MOVEit vulnerability to compromise data relating to over a thousand victims in one go, there were indications that managing the volume of victims generated operational challenges for the group.
There have also been recent reports of agentic AI ransomware, such as JADEPUFFER, but this was not an end-to-end automated operation; a human is still directing target selection, building the infrastructure and overseeing attacks at every stage. While cybercriminals will likely continue to experiment with such agents, widespread adoption is unlikely unless existing methods significantly decrease in profitability.
At present, then, there is little evidence that AI has changed the operating models of cyber extortionists or will in the short- to medium-term future. Most observed use is, like much of cybercrime, far more mundane. AI is being utilised to optimise the different steps in the cybercriminal business model. It increases the productivity of some steps in a ransomware operation, but not the business model itself. BlackBasta's leaked internal chats show the group discussing ChatGPT use for phishing, debugging persistence tools and verifying stolen email addresses. In other words, for the kind of mundane tasks that software developers or project managers may use such tools for.
The idea of autonomous ransomware and AI reducing organisational constraints that currently limit ransomware operations should not be dismissed. However, there is currently limited evidence that ransomware groups are successfully deploying AI in this manner. It is more likely to augment existing ransomware operations than fundamentally transform them in the near term. The more important question is where it might alter the economics of ransomware instead.
The Potential Impact of AI on Ransomware Business Models
If access was never a constraint, the question is where AI will have an impact. Historically, it has been hard for ransomware groups to clean and exploit the data they have stolen in ransomware attacks. Attacks have routinely hoovered up entire databases using automated scripts resulting in massive repositories of unstructured data that they lack the resources and knowledge (including English language skills) to review. Critical intellectual property or personally identifiable information is often buried within vast quantities of less valuable data. In the short-term, rather than replacing cybercriminals with agentic AI end-to-end capabilities, the greatest scope for innovation is around integrating AI into new ransomware business models and exploiting the access that criminals already have to their victims. There are two specific areas of risk, with some emerging evidence that this is already happening to some extent. Both concern how to more effectively monetise data stolen by ransomware criminals.
The first is using AI to better exploit stolen data and to more effectively extort victims. A recent GuidePoint Security report showed how the FulcrumSec ransomware group, who primarily operate a data-exfiltration and extortion business model, used an LLM to analyse stolen data for leverage directly in the negotiation engagement with the victim. Should this prove effective in improving payment rates and values, there is the potential this could become another specialised role within the cybercrime ecosystem and offered as-a-service.
The second is using AI to monetise stolen data beyond the initial attack. Ransomware groups have stolen a huge volume of data in ransomware attacks, especially since data exfiltration became the norm in double extortion attacks around 2022. It is unlikely they have deleted this data – storage is cheap, and the NCA showed in their disruption of LockBit in 2024 that even for victims who paid, stolen data was never deleted. Cybercriminals see value in it. However, in March 2026 a specialized cybercriminal dark-web marketplace launched called Leak Bazaar, which is designed to monetise data stolen in ransomware attacks, adding a second level of victimisation on top of the victim of the original attack. If platforms like this prove sustainable, they could create a significant secondary market for stolen data.
Conclusion
There is limited evidence of widespread adoption of these applications. It remains more profitable to run ransomware operations with proven business models, which explains why AI adoption by cybercriminals has and will continue to be incremental. Analysts and policymakers should therefore resist speculative visions of AI-driven cybercrime and focus instead on where AI is actually easing friction in the existing business model. The clearest signal so far is downstream from the point of access. AI’s impact on ransomware may be felt first in helping cybercriminals better exploit stolen data in their attacks, and then monetising the huge backlog of stolen data as opposed to acquiring more of it.
© RUSI, 2026.
The views expressed in this Commentary are the authors', and do not represent those of RUSI or any other institution.
For terms of use, see Website Terms and Conditions of Use.
Have an idea for a Commentary you'd like to write for us? Send a short pitch to commentaries@rusi.org and we'll get back to you if it fits into our research interests. View full guidelines for contributors.
WRITTEN BY
Will Lyne
Guest Contributor
Jamie MacColl
Senior Research Fellow
Cyber and Tech
- Jim McLeanMedia Relations Manager+44 (0)7917 373 069JimMc@rusi.org






