Bad actors looking to commit ransomware attacks no longer need to be technologically savvy to be successful — Ransomware-as-a-Service, a growing criminal phenomenon, provides end-to-end solutions that allow nearly anyone to carry out these attacks.
Software-as-a-Service (SaaS) has been making its mark since the mid-2000s, allowing companies to implement solutions that are created and maintained by third-party vendors so they can focus on their core business and leave the software to the experts.
The SaaS model has been so effective that bad actors have patterned Ransomware-as-a-Service (RaaS) on it. Like SaaS, RaaS operations offer complete hacking and ransom capabilities.
RaaS “is an automated service that allows criminal syndicates to extort ransoms from any type of institution, providing all the tools for that,” Lenny Gusel, North American head of fraud solutions at fraud mitigation service provider Feedzai, told FinAi News.
A person planning a ransomware attack would “obviously need a lot of technical know-how,” Gusel said, but RaaS eliminates that need.
“Ransomware-as-a-Service is: Criminals have decided how they’re going to make money is to provide all of that technical infrastructure and technical capability to other criminals, since there’s lots of businesses and individuals to exploit with ransomware.”
Growing problem
Just as SaaS has been around for decades, RaaS is not a new problem, but it is “a growing phenomenon,” Navin Balakrishnaraja, chief executive of cybersecurity company Fortuna Cysec, told FinAi News.
Belarusian national Maksim Silnikau, 40, was sentenced to 16 years in prison on Aug. 5 for creating and operating Ransom Cartel, an RaaS operation, according to a release from the U.S. Attorney’s Office, Eastern District of Virginia.
From 2021 to 2023, Ransom Cartel clients executed ransomware attacks on at least 18 companies around the world. Silnikau’s RaaS ceased operation in July 2023 when Silnikau was arrested, according to the release.
Law enforcement agencies have identified RaaS victims across the globe in multiple sectors, including financial services. When issuing alerts about RaaS activity, these agencies do not name victim organizations.
U.S. organizations reported losing more than $32 million to ransomware attacks in 2025, according to the FBI’s Internet Crime Complaint Center 2025 annual report.
The financial services industry was the third most targeted sector by cyberattackers in the first six months of 2026, trailing technology in first place and consulting and professional services in second, according to cybersecurity firm CrowdStrike’s 2026 Threat Hunting Report, released Aug. 3. Ransomware is a type of cyberattack.
FIs saw an 11% increase in intrusive activity compared with the first half of 2025, the report said.
Criminals target FIs because they hold significant financial assets, including cryptocurrency, as well as high-value data on businesses and customers, according to CrowdStrike.
Be vigilant
This month the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and FBI, along with other agencies in the United States and South Korea, issued an alert about Gunra, an RaaS enterprise that emerged in April 2025 on the dark web for bad actors, aka Gunra “affiliates,” to use.
Gunra affiliates use a double-extortion model in which they encrypt and exfiltrate sensitive data to create two forms of leverage for collecting ransom. They demand ransom via a secure portal — supported by Gunra — and threaten to publish the stolen data on a dedicated leak site — also run by Gunra — if they are not paid, according to CISA.

Gunra’s software can also disable an organization’s data backup features, CISA said. In one case, Gunra prevented a victim from restoring encrypted data by deleting the victim’s backup and archived data stored at primary data and disaster recovery centers.
CISA and the FBI issued another alert on Aug. 18 warning against Medusa, an RaaS variant identified in June 2021. As of April, Medusa affiliates have attacked more than 500 victims across multiple critical infrastructure sectors, including financial services. Medusa also uses a double-extortion model.
Some of the other most prevalent and harmful RaaS operators, according to cybersecurity and networking firm Fortinet, are:
- Egregor, which is based on the defunct Maze RaaS, the first ransomware to use the double-extortion model;
- LockBit, which quickly encrypts the systems of big businesses, making it more difficult for IT teams to locate and eradicate the ransomware before it causes harm;
- REvil, which infects computers by taking advantage of unpatched Citrix and Pulse Secure VPNs; and
- Ryuk, which Fortinet believes is to blame for nearly one-third of ransomware attacks and has resulted in an estimated $150 million in losses.
More RaaS enterprises are likely to spring up as AI equips bad actors with sophisticated hacking tools, Fortuna Cysec’s Balakrishnaraja said.
“This is going to grow much more with AI because now you don’t need much information [to initiate an attack] because AI is providing all the tools that you need,” he said. “The [bad actors] then package this and sell it on the dark web much more easily.”
Crime goes corporate
Cybercriminals are organized just like members of any other industry, leading them to outsource when necessary and operate as efficiently as possible, Lionel Litty, chief information security officer at browser security company Menlo Security, told FinAi News.
“We’re seeing that some attack groups specialize maybe more in browser exploits [and] some other attack groups are going to specialize in the phishing component of an attack and setting up websites that are believable and doing a good job of doing credential harvesting,” he said. “And then some other group is going to focus more on the extortion part of things.
“Ransomware-as-a-Service can offer all these specialties in one package,” Litty said.
Though RaaS appears corporatized and is modeled on the successful and legitimate SaaS model, RaaS is illegal. CrowdStrike identifies four common RaaS models for third-party revenue:
- A monthly subscription for a flat fee;
- Affiliate programs with a subscription fee and a percentage of the ransom going to the ransomware developer;
- A one-time license fee with no profit sharing; and
- Pure profit sharing.
In exchange for payment, these RaaS clients receive end-to-end service.
“That’s what Ransomware-as-a-Service is, including customer support for your ransomware and training for how to use,” Feedzai’s Gusel said.
Sophisticated RaaS operations offer portals similar to online orders. They allow subscribers to view the status of attacks, total payments, total files encrypted and more, according to CrowdStrike. RaaS subscribers might have access to customer support, communities, service updates and other benefits mirroring those received by subscribers to legitimate SaaS providers.
Some RaaS operators also run marketing campaigns, issue whitepapers and are active on social media, according to CrowdStrike.
Preventing ransomware attacks
As ransomware becomes more sophisticated and accessible, organizations should shore up their systems for the maximum level of protection, a Fortinet spokesperson told FinAi News. Organizations should:
- Backup data regularly and in multiple locations, including external hard drives rather than relying solely on cloud;
- Update software regularly since new versions often patch vulnerabilities and fix bugs;
- Train staff regularly to recognize, report and quarantine potentially harmful messages, especially from social engineering and phishing; and
- Deploy endpoint protection and threat detection technologies.
CISA advises organizations to run regular diagnostics for vulnerabilities, then patch them in a timely manner. CISA also advises segmenting networks to restrict lateral movement from infected devices to other devices and filtering network traffic by preventing unknown or untrusted sources from accessing remote services on internal systems.
Still, RaaS will likely continue to grow, Gusel said.
“Fraud is a very large business, a very sophisticated business, very well organized,” Gusel said. “You have organized crime syndicates, transnational crime syndicates, who are making it their job.”
Register here for the FinAi Lending Summit, set for Oct. 7-8 in Las Vegas. This inaugural event will include speakers from Fifth Third and Capital One, as well as a fireside chat with Piermont Bank founder and Chief Executive Wendy Cai-Lee.





