Ransomware: a sophisticated criminal franchise
PhD research image: Getty Images on Unsplash
Ransomware has become an industry, complete with developers, hired operators, access brokers, and even victim helpdesks. Criminologist Sifra Matthijsse examined how ransomware attacks unfold, negotiations with cybercriminals are conducted, and the difficult choices for victims.
In 2025, cyber criminals gained access to medical and personal data of around 485,000 Dutch women who had taken part in the national cervical cancer screening campaign. According to reports, the laboratory involved paid a ransom. Investigative journalism platform Follow the Money cited failings in the laboratory's cybersecurity measures. A ransomware attack is no longer the work of a lone hacker operating from their bedroom. In its Jaarbeeld Ransomware 2025 (Ransomware Annual Report), the Dutch National Police and the Public Prosecution Service estimated that around 2.5 million people in the Netherlands fell victim to cybercrime or online fraud in that year. Meanwhile, Dutch companies continue to report new ransomware incidents.
Large organisations are not the only targets of these attacks. Self-employed people and small and medium-sized enterprises (SMEs) are also affected. When entrepreneurs were asked what they would do if they became victims of cybercrime, more than 90% said they would contact the police. Yet among those who have actually fallen victim, the proportion is much lower: only 18% contacted the police, and of those, just 26% actually officially reported a crime.
A criminal franchise
Ransomware is a form of malicious software that encrypts files. ‘These days, those files are often stolen as well, after which the perpetrators demand a ransom in exchange for access being restored,’ Matthijsse explains. For her PhD research, she mapped out the entire process step by step, resulting in a surprisingly long list of actors involved. At its core is a central group that develops the malware, but increasingly the work is outsourced to independent hackers and criminal groups.
‘Other parties, known as affiliates, are given access to victims and carry out the attack. In return, they receive a share of the proceeds.’ For major ransomware groups, this can involve anywhere from 40 to as many as 100 individuals in total. Even access to computer systems is now bought and sold, provided by criminal actors who specialise in gaining and trading such access.
Once inside a system, perpetrators try to penetrate as deeply as possible, ideally gaining administrative privileges. This makes it much more difficult for the victim to recover their systems independently. In many cases, organisations do not realise anything is wrong until they receive the ransom demand. Those who pay are usually able to regain access to their files. ‘It seems contradictory, given that these are criminals. But there is a genuine customer service element to it,’ says Matthijsse. ‘If it becomes known that paying the ransom does not result in the return of your data, why would any future victim choose to pay?’ One ransomware group even emphasised that it had been operating for six years and that not a single ‘customer’ had failed to recover their data after making a payment.
'It seems contradictory, given that these are criminals. But there is a genuine customer service element to it'
Victims not turning to the police
Matthijsse’s research analysed leaked chat conversations which revealed that negotiations with perpetrators are common in ransomware cases around the world. In the case of small Dutch businesses, however, such contact is rare: only 7% of the victims examined for the research reported communicating with the attackers.
The most striking finding is the gap between intention and practice when it comes to reporting incidents to the police. Victims often say that the police are not the right party to turn to, that they cannot provide the help needed, or that the issue was resolved internally or with the assistance of a cybersecurity firm. Mathijsse says she can understand this to some extent. ‘When your files have been encrypted, your business effectively grinds to a halt. You need an immediate solution, and that’s usually not something the police can provide.’
Nevertheless, she also emphasises that, while the police may not be the first organisation victims think of turning to, reporting incidents remains extremely important. Criminal investigations often take time and are complex because of both the technical nature and the cross-border character of these offences, but that does not mean the police are unable to do anything.
'We all tend to think, it won't happen to me, until it does'
The Melissa Project
For example, in 2022 the ransomware group DeadBolt encrypted files on tens of thousands of network-attached storage (NAS) devices, including at least a thousand in the Netherlands. In response, the police took a remarkable step. They paid the ransom to the DeadBolt gang, obtained the decryption keys, and subsequently reversed the payments. By outsmarting the ransomware group, everyone in the Netherlands who had officially contacted the police was able to recover their files free of charge.
Tracking down perpetrators takes time, especially as they are often based abroad. In the Melissa Project set up in the Netherlands, the police, the Public Prosecution Service, the National Cyber Security Centre (NCSC), and cybersecurity companies pool their knowledge and expertise on ransomware, which would otherwise remain fragmented and dispersed. They share information about attacks, analyse incidents jointly, and coordinate action against perpetrators. The Qakbot network, which was used worldwide to facilitate ransomware attacks, was dismantled with the help of this collaboration. The initiative was subsequently analysed by Leiden University. ‘There is definitely room to increase willingness to report these crimes to the police.’
It won't happen to me
While it may be impossible to prevent every attack, businesses can take steps to reduce both the likelihood and the impact of becoming a victim. They can maintain reliable backups, identify where their vulnerabilities lie, and ensure that not all employees have access to all files and information.
Matthijsse points to the population screening laboratory as an example: if they’d had better safeguards in place, both the likelihood of an attack and the resulting damage could have been reduced. ‘We all tend to think it won’t happen to me, until it does,’ she says. ‘But given how professionally these operations are organised, it’s far better to assume that it could.’
Sifra Matthijsse will defend her dissertation ‘Falling victim to ransomware: on the unfolding of attacks, victim-offender interactions and decision-making’ on 7 Octber at 16.00 in the Academy Building. The lay talk of the disseration is available here and you can follow the livestream of the defence via this link.