Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

At Infosecurity Europe 2025, UK National Crime Agency (NCA) cyber intelligence head Will Lyne identified a ransomware ecosystem with lower barriers to entry, less rigid group structures and a growing reliance on data-theft extortion instead of encryption. His account also makes clear why disruption increasingly depends on cooperation across law enforcement, government, business and academia.

Why the NCA treats ransomware as a national-security problem

Lyne described ransomware as the UK’s highest-priority cybercrime threat. In a 2 June 2025 Computer Weekly report previewing his Infosecurity Europe panel, he said ransomware had shifted from a niche cybercrime issue in the late 2010s to a national-security concern. The 2021 Colonial Pipeline attack was one moment that brought the threat to wider public attention.

Lyne, who had more than 15 years of law-enforcement experience at the time of the report, said: “Ransomware is the most pernicious of cyber crime threats.” The report also notes his contributions to cases involving EvilCorp and Operation Destabilise, and his doctoral research at the University of Cambridge on the ransomware ecosystem.

What is changing in ransomware operations?

Lyne’s account describes changes in who can participate, how groups organize, what they steal and how criminals find one another. It is more useful to view ransomware as an ecosystem of actors and capabilities than as a single cartel.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Dimension Earlier pattern Trend Lyne described
Who can enter Greater dependence on specialist skills, including advanced coding and language capabilities. Cheaper, easier-to-obtain offensive tools reduce some skill and language barriers.
Group structure More centralized or hierarchical models. Loosely organized groups that can resemble minimally managed technology startups.
Extortion method Double extortion: encrypting systems and threatening to release stolen data. Encryption-less theft-and-extortion: stealing data and threatening disclosure without encrypting systems.
Criminal interactions Centralized marketplaces. More peer-to-peer trading.

Why is ransomware easier for new groups to enter?

Lower-cost, accessible offensive tools let operators rely less on building sophisticated capabilities themselves. Lyne summarized the shift in Computer Weekly’s report: “We’re seeing lower barriers to entry.” The point is not that ransomware requires no skill, but that some operations can be assembled without every participant being an expert coder or specialist.

Looser organization also changes how the ecosystem works. Rather than relying only on a tightly controlled hierarchy, groups may coordinate capabilities and activity more flexibly. That makes it harder to understand the threat by focusing on a single organization or assuming that every participant has the same role.

Is ransomware moving beyond Russian-speaking gangs?

Lyne’s account points to a broader mix of operators, not an end to Russian-speaking groups. Scattered Spider is cited as an Anglophone example involving young operators who may not have advanced coding skills. It illustrates that language and technical background are no longer reliable shortcuts for describing who may participate in ransomware activity.

What does encryption-less extortion mean?

In double extortion, attackers both encrypt systems and threaten to publish data they have stolen. In encryption-less extortion, they steal information and use the threat of disclosure to pressure the victim, without needing to encrypt systems. This means an organization should not assume that the absence of locked files means there is no extortion incident.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For defenders, the practical implication is to prepare for data theft and disclosure threats as well as service disruption. Identity and access controls, incident readiness, and clear escalation routes matter in either scenario. These are general implications of the trend, not a substitute for security advice tailored to a particular organization.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How is the ecosystem changing after law-enforcement takedowns?

Lyne’s emphasis on looser groups and peer-to-peer trading suggests that disrupting one centralized marketplace or organization may not remove the capabilities or connections used by the wider ecosystem. Criminal interactions can shift toward less centralized relationships, while actors can reorganize around available tools and services.

That is why the report stresses cooperation among law enforcement, government, private companies and academia. For organizations, useful preparedness includes sharing relevant intelligence through appropriate channels and maintaining relationships with incident-response providers and law enforcement before an incident occurs. These measures support response and disruption; they do not guarantee prevention.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.