Blog

6 Ransomware Myths Debunked: How to Prepare Your Security Team

6 Ransomware Myths Debunked: How to Prepare Your Security Team
Ransomware doesn't spare small businesses, hospitals, or paying victims. SecurityScorecard debunks six myths with real incident data.

Ransomware has evolved from a noisy IT headache into a sophisticated, multi-billion-dollar business model built on continuous exploitation. Yet despite soaring cybersecurity budgets, threat actors continue to successfully compromise organizations at an alarming rate. Despite this reality, many security programs are still designed around legacy assumptions about ransomware behavior — believing that small company sizes, non-profit statuses, or regional locations provide natural immunity.

Threat actors actively exploit these assumptions. To defend against extortion tactics, security teams must dismantle the myths that still so often dictate risk registers and boardroom decisions. Here are six persistent ransomware myths costing companies millions of dollars and the real-world incidents that expose their flaws.

Myth 1: We’re too Small to be a Target

The belief:

Attackers chase Fortune 500 payouts. A small- to mid-sized business isn’t worth their time.

The reality:

Ransomware has moved down market, not up. According to Verizon’s 2026 Data Breach Investigations Report (DBIR), threat actors used ransomware in 83% of breaches at small- and mid-sized businesses compared to 48% across all organization sizes combined. Small companies aren’t overlooked; they’re preferred. They run the same internet-facing Remote Desktop Protocol (RDP) and Virtual Private Network (VPN) appliances as everyone else, and often with less monitoring, no dedicated security staff, and less ability to survive a week of downtime.

Our STRIKE Threat Intelligence team supported this year’s DBIR findings by contributing exploitation timeline analysis and exposed asset data, surfaced through SecurityScorecard’s TITAN AI platform and derived from the unique attack surface telemetry Driftnet collects daily across the global IPv4 and IPv6 space.

Example:

The clearest evidence here is the math. According to findings in the Sophos State of Ransomware 2025 Report, the average recovery cost for mid-sized organizations (100–250 employees) reached $638,536 USD — excluding any ransom payment made. For many mid-sized businesses, an unexpected loss exceeding six figures poses an existential threat to cash flow, and threat actors rely on that financial pressure to force a rapid payout. 

Takeaway:

Size may determine your ransom demand, not attackers’ interest in targeting you.

Myth 2: Ransomware Gangs Don’t Attack Hospitals or Charities

The belief:

Major ransomware syndicates publish and follow rules prohibiting attacks on healthcare, nonprofits, and critical infrastructure, leaving these organizations safe from attack. 

The reality:

These “rules” are purely theatrical. They exist to avoid immediate law enforcement heat, prevent affiliates from defecting over bad press, and project a professional image. Enforcement is entirely retroactive. More importantly, criminals can shift their guidelines without warning, turning innocent organizations into geopolitical leverage.

The evolution of LockBit’s targeting policy is the clearest proof that criminal terms of service are meaningless.

Example:

In December 2022, a LockBit affiliate encrypted systems at the Hospital for Sick Children (SickKids), a pediatric teaching hospital in Toronto, disrupting lab results and delaying critical patient care. At the time, LockBit’s stated policy barred attacks on life-saving medical institutions. To protect their brand, the group publicly apologized, expelled the allegedly rogue affiliate, and released a free decryptor. This arrived nearly two weeks after the hospital had already begun its own recovery efforts.

The reality:

LockBit later proved that those “protections” were entirely disposable. They didn’t just change the rules — they used them as a direct extortion tactic against law enforcement. In their updated policy, the group declared: “these permits remain in force until an agreement is negotiated between the FBI and LockBit to not attack certain categories. If you are reading this and these rules have not changed, it means that the FBI has not yet approached us for this agreement, and they are fine with allowing attacks on the above categories of organizations.”

Source: LockBit’s public data exfiltration leak website

Takeaway:

Any appearance of criminal “ethics” is just another form of leverage. If your cybersecurity strategy relies on a ransomware gang’s goodwill, you don’t have a strategy, you have a gamble.

Myth 3: We’re in a Post-Soviet Country, so Ransomware Won’t Touch Us

The belief:

Russian-speaking ransomware operations hard-code the Commonwealth of Independent States (CIS) exclusions. Many strains genuinely do check keyboard layout, system locale, or installed language packs and exit if they find post-Soviet languages. 

The reality:

Regional exclusions may be a safe-harbor arrangement between criminals and the jurisdiction that shelters them, as it may protect the operators from local police attention. It was never a promise to the victim, and it can evaporate the moment politics change.

Example:

The moment when Russia invaded Ukraine in 2022 marked a critical turning point in which ransomware operations became directly tied to geopolitical conflict. Threat groups quickly took sides, most notably when the Conti ransomware gang pledged its allegiance to the Russian government and threatened retaliatory attacks against the critical infrastructure of any nation opposing the war. 

Concurrently, as the physical invasion began, CISA documented threat actors deploying HermeticRansom (PartyTicket) ransomware alongside destructive wipers against Ukrainian networks, proving that threat actors actively weaponized ransomware as a strategic decoy to mask data destruction. Further emphasizing this trend, CERT-UA observed the financially motivated operators behind Cuba ransomware targeting Ukrainian state organizations, signaling a clear, structural shift as cybercriminals transitioned from financial extortion to geopolitical disruption.

Takeaway:

The CIS exclusion is a political alliance, not a defensive shield. Assume your region is always a valid target because criminal loyalties change as fast as the geopolitical climate.

Myth 4: If We Pay, It’s Over

The belief:

Payment secures data deletion and closes the incident.

The reality:

You are paying a criminal for a promise with no verification and no enforcement. According to research cited by CNiC Solutions (referencing Halcyon and Fortinet research), 84% of organizations that paid a ransom failed to fully recover their data, and 80% were attacked again within 12 months. 

Example:

The cyberattack on Change Healthcare perfectly illustrates the trap of double extortion and the severe risks associated with single points of failure in third-party supply chains. Initiated by the BlackCat/ALPHV ransomware group, the breach forced the disconnection of over 100 systems, halting claims processing and costing some hospitals millions of dollars a day in lost revenue. Despite allegedly paying a $22 million USD ransom to close the incident, Change Healthcare did not get the resolution it paid for. Instead, the company faced double extortion when a second group, RansomHub — reportedly involving former BlackCat members — emerged with 4TB of the stolen data and threatened to leak it unless the company paid an additional ransom. 

Takeaway:

Paying a ransom signals to threat actors that an organization has liquid funds and is willing to pay to protect its customers’ information, often making them a highly desirable target for repeat extortion attempts.

Myth 5: “That Group Was Taken Down, so the Threat Is Gone”

The belief:

Law enforcement seized their infrastructure, confiscated their servers, and sanctioned the operators. That specific ransomware group is dead, so its associated threat is retired.

The reality:

Ransomware brands are disposable. The developers, the affiliates, and the underlying code are not. When law enforcement disrupts a ransomware group or when the group shuts down due to a damaged reputation, the operation rarely ends. Instead, the criminals adapt through three primary survival tactics:

  • Selling Their Code: A group’s source code remains highly valuable, even if law enforcement has shared the decryption keys. Buyers can retool the software to generate new keys or modify it for pure data theft and extortion.
    • Example: In January 2023, law enforcement successfully seized the Hive ransomware operation’s payment and data leak sites. However, just nine months later, a new Ransomware-as-a-Service (RaaS) group called “Hunters International” emerged, claiming to have purchased the encryptor source code directly from the original Hive developers, effectively resurrecting the threat.
  • Rebranding Under a New Name: Ransomware groups commonly rebrand following a law enforcement takedown. These reborn groups are no less dangerous. They often return smarter and with a more strategic approach. They frequently reuse parts of their original source code but adapt their tactics, such as limiting their affiliate numbers or shifting to pure data extortion.
    • Example: After the highly disruptive attack on Colonial Pipeline in 2021, the DarkSide ransomware gang faced intense global law enforcement scrutiny and fund seizures. To evade the heat, the group simply rebranded as BlackMatter.
  • Criminal Mergers: Disrupted ransomware factions frequently join forces with other cybercriminal syndicates to restore their business operations. These mergers create highly resourceful adversaries, forcing defenders to deal with shifting, unpredictable attack tactics.
    • Example: When ALPHV’s dark web infrastructure went offline, the administrator of the LockBit ransomware group immediately began recruiting the coder behind the ALPHV encryptor. Furthermore, LockBit released a ransomware variant called “LockBit Green” that uses a Conti-based encryptor, indicating active cooperation and code-sharing between LockBit and former members of the dismantled Conti syndicate.

Takeaway:

Ransomware groups operate like agile tech startups. When disrupted, they often pivot, rebrand, merge, or sell their assets to competitors.

Myth 6: “Our Security Is Strong”

The belief:

Comprehensive internal controls like Endpoint Detection and Response (EDR), Multi-Factor Authentication (MFA), network segmentation, and tested backups fully secure organizations against ransomware.

The reality:

Internal security controls only govern your own perimeter. They do not protect against compromised supply chain software, managed service providers, or third-party vendors holding standing administrative credentials into your network. According to SecurityScorecard’s most recent Global Third-Party Breach Report, 41.4% of ransomware attacks involve third-party access, and 98% of organizations maintain active relationships with at least one third party that has been breached in the last two years.

Example:

The ransomware group Cl0p perfectly demonstrates how threat actors exploit third-party software vulnerabilities to achieve massive scale. By targeting widely deployed managed file transfer platforms like MOVEit Transfer, as detailed in SecurityScorecard’s investigation into zero-day exploitation, Cl0p compromised servers across thousands of targets worldwide. The threat actors compromised mature organizations with strong internal defenses even though they did not experience direct perimeter breaches, such as when payroll provider Zellis was exploited via MOVEit, which cascaded into data exposure for downstream clients like British Airways and the BBC. By exploiting a single third-party software vector, Cl0p minimized its operational labor while turning compromised customer and vendor records into a strategic pressure point.

Takeaway:

You are only as secure as your vendors and your vendors’ vendors. Because ransomware actors rely on supply chain vulnerabilities to scale attacks and multiply extortion pressure, third-party risk management must be integrated directly into your ransomware defense strategy.

Stop Ransomware Before It Spreads: See Your Exposure the Way Attackers Do

Every myth above shares one flaw: it trusts an assumption instead of evidence. Attackers don’t care how big your company is, which region you operate in, or how strong you believe your controls are. They care about what is exposed, and that changes daily.

SecurityScorecard’s STRIKE Threat Research team closes that gap by continuously investigating active ransomware groups across dark web leak sites, command-and-control (C2) infrastructure, and global supply chain vectors. That research is powered by attack surface telemetry from Driftnet, which scans the global IPv4 and IPv6 space every day, and surfaced through the TITAN AI platform so security teams can prioritize the exposures attackers are most likely to exploit, including those sitting in your vendors’ environments.

See what attackers see. Explore SecurityScorecard Internet Intelligence and connect with the STRIKE team to uncover your exposed assets, third-party risk, and active ransomware threats before they become incidents.