After the WannaCry attack, no fewer than five threat research companies pounced on the fact that the ransomers were demanding to be paid in bitcoin. However, they completely glossed over the concept behind the malware itself. Within days, theorists came out of the woodwork to characterize the attack as some kind of subtle terrorist or government-backed operation. However, it’s worth considering the complexities of bitcoin and ransomware before spewing speculative notions.

Bitcoin and Ransomware

According to SonicWall’s “2017 Annual Threat Report,” the worldwide volume of ransomware attacks rose from 3.2 million in 2014 to 3.8 million in 2015. In 2016, the firm reported an astounding 638 million ransomware incidents. So far this year, the WannaCry ransomware alone accounted for 213,000 attacks in more than 100 countries.

CNN reported that cybercriminals extorted businesses to the tune of $209 million in the first three months of 2016. If that is correct, assuming that ransomware demands kept a steady pace during each quarter of 2016, the total amount of money collected through ransomware for the year should be equal to or greater than $836 million.

So far in 2017, the average number of bitcoin demanded with each infection of ransomware is 300. As of June 19, the bitcoin (XBT)-to-U.S. dollar exchange rate was 1 XBT = $2,531.61. Therefore, a single ransom payment in U.S. dollars, assuming the ransom is paid in bitcoin, would total $759,300.00.

This provides valuable insight into the ransomers’ thought process — namely, that there is no thought process at all. Rather, fraudsters seem to demand payment in bitcoin simply because the digital currency is trendy.

Money Is No Object

One bitcoin is worth more than a single ounce each of gold, palladium, platinum and rhodium, the most commonly traded metals on the commodities market. That exchange rate is more or less a flat exchange rate in the market economy, which does not take into account exchange fees, transaction fees, brokers or any value change that takes effect when bitcoin is spent on black market goods and services.

Time for a bit of speculative math: If ransomware criminals netted a total of $836 million dollars in profit, how much bitcoin could they buy using a digital currency exchange? Using the simplest equations:

  • Potential ransomware profit in 2016 = $836 million;
  • Transaction fee + conversion fee on a digital currency exchange = 50 cents per U.S. dollar;
  • $836 million x .50= $418 million in remaining profit;
  • 1 XBT = $2,531.61;
  • $418 million / $2,531.61 = 165,112.3198 bitcoin.

Now, all this simplistic math assumes at least one of three very important premises:

  1. The person or company held hostage by the ransomware knows what bitcoin is.
  2. The company or individual knows how and where to get bitcoins.
  3. The company or individual knows how to mine for bitcoins.

Considering the rate at which the ransom demands produce bitcoin payments, it is safe to say that those three premises are not always true. This tells astute researchers that the ransomware creators either failed to do their homework, do not understand the market to which they are pushing their malware, or rely on statistical averages to make their dreams of wealth and world domination come true.

Where Is the Money Going?

So where is all this money going? Popular theories claim that terrorist organizations, military agencies and illegal drug manufacturers purchase illicit supplies and equipment primarily in bitcoin. There are a few other areas, however, where individuals or organizations might benefit from dealing in the digital currency.

Lithium, for example, is priced between $39 and $45 per ingot (about 11 pounds). Lithium deposits are found in a handful of places on our planet. Considering that lithium ion batteries can power smartphones, laptops, tablets and electric cars, using bitcoin to purchase this material would be an investment both inside and outside of the black market.

Furthermore, citizens of countries whose currency has been devalued can use bitcoin to purchase essential items and services such as food, clothing, shelter, medicine, transportation and education. Likewise, bitcoin can be valuable in the event of an economic collapse, inflation, governmental dissolution or other large-scale catastrophe.

The $2,531.61 Question

It would be wonderful to conduct research into the life cycle of a bitcoin on the black market. Perhaps we could find answers to questions such as: Who is using it? When and where are they using it? What are they buying? How often are transactions made? How many times does a single bitcoin change hands? Is it being traded or kept as a potential new backing standard like gold? Is it being used to create not just a black market, but a secondary economy?

Answers to these questions would surely yield some fascinating insights into the relationship between bitcoin and ransomware. Until then, security analysts, individuals and organizations should become well-versed in basic ransomware prevention techniques.

Download the Ransomware Response Guide from IBM Incident Response services

More from Data Protection

Vulnerability resolution enhanced by integrations

2 min read - Why speed is of the essence in today's cybersecurity landscape? How are you quickly achieving vulnerability resolution?Identifying vulnerabilities should be part of the daily process within an organization. It's an important piece of maintaining an organization’s security posture. However, the complicated nature of modern technologies — and the pace of change — often make vulnerability management a challenging task.In the past, many organizations had to support manual integration work to get different security systems to ‘talk’ to each other. As…

Cost of a data breach 2023: Geographical breakdowns

4 min read - Data breaches can occur anywhere in the world, but they are historically more common in specific countries. Typically, countries with high internet usage and digital services are more prone to data breaches. To that end, IBM’s Cost of a Data Breach Report 2023 looked at 553 organizations of various sizes across 16 countries and geographic regions, and 17 industries. In the report, the top five costs of a data breach by country or region (measured in USD millions) for 2023…

Cost of a data breach 2023: Pharmaceutical industry impacts

3 min read - Data breaches are both commonplace and costly in the medical industry.  Two industry verticals that fall under the medical umbrella — healthcare and pharmaceuticals — sit at the top of the list of the highest average cost of a data breach, according to IBM’s Cost of a Data Breach Report 2023. The health industry’s place at the top spot of most costly data breaches is probably not a surprise. With its sensitive and valuable data assets, it is one of…

Cost of a data breach 2023: Financial industry impacts

3 min read - According to the IBM Cost of a Data Breach Report 2023, the global average cost of a data breach in 2023 was $4.45 million, 15% more than in 2020. In response, 51% of organizations plan to increase cybersecurity spending this year. For the financial industry, however, global statistics don’t tell the whole story. Finance firms lose approximately $5.9 million per data breach, 28% higher than the global average. In addition, evolving regulatory concerns play a role in how financial companies…