The cybercrime supply chain has five stages, each with a price
Modern ransomware attacks are orchestrated through a specialized supply chain comprising five distinct business functions: harvesters operating infostealer malware, brokers verifying and reselling access, ransomware-as-a-service operators providing toolkits, affiliates executing intrusions, and launderers handling proceeds. This structured ecosystem has replaced the outdated model of lone attackers, with each stage commanding specific costs within the cybercrime marketplace. Understanding this supply chain is critical for security professionals developing comprehensive defense strategies against organized ransomware operations.
The Gunra ransomware gang is actively exploiting unpatched VPNs and firewalls to infiltrate organizations, steal data, and encrypt systems for extortion purposes. The group has targeted victims across multiple critical sectors including healthcare, finance, and manufacturing. Security professionals should prioritize patching network perimeter devices to mitigate exposure to this threat.
Mid-sized companies with annual revenue between $10 million and $1 billion represented 73% of publicly disclosed ransomware and data-extortion incidents in North America and Europe from January 2023 through June 2026, according to analysis by Black Kite covering 13,336 incidents. This segment's share of attacks remained consistently between 72% and 75% throughout the period, indicating that ransomware operators are deliberately targeting the mid-market as a priority.