The evolution of ransomware is creating a new category of non-state cyber power. Decentralized criminal organizations increasingly possess the organizational structures, financial incentives, international reach and negotiating capabilities once associated primarily with states and legitimate multinational organizations.
By Vladimir Tsakanyan, PhD | Director, Center for Cyber Diplomacy and International Security
The Criminal Organization That Does Not Need a Country
Cybercrime policy still tends to begin with a familiar assumption: somewhere there is a criminal, somewhere there is a victim, and somewhere there is a government responsible for enforcing the law.
The architecture of modern ransomware increasingly makes that assumption obsolete.
The most sophisticated ransomware operations do not necessarily resemble traditional criminal gangs. They resemble distributed enterprises.
They recruit affiliates. They acquire access to networks. They develop malware. They maintain infrastructure. They negotiate with victims. They publish information to create pressure. They divide revenue among participants. They replace disrupted personnel and infrastructure. And they can operate simultaneously across dozens of jurisdictions.
Qilin offers a particularly revealing example. A recent analysis reported that the group claimed 141 organizations across at least 25 countries during a 30-day period, more than twice the number attributed to the next-most-active operation in the same period. The analysis attributes part of this scale to its affiliate structure and its ability to absorb participants displaced by the disruption of other ransomware organizations.
DragonForce illustrates the same structural transformation from another direction. The group has operated a ransomware-as-a-service model in which affiliates receive a substantial share of ransom proceeds and has presented itself as part of a broader ransomware “cartel” model.
The important question is therefore no longer simply:
How do governments stop ransomware?
It is:
What exactly are governments trying to stop?
From Gang to Network
Traditional criminal organizations are generally understood through hierarchy.
A leader commands subordinates. A territory provides an operating environment. Money flows upward. Law enforcement attempts to identify the organization and remove its leadership.
The ransomware economy is different.
The contemporary model can distribute the functions of a criminal operation among independent participants:
Initial-access broker → affiliate → ransomware developer → infrastructure provider → negotiator → money launderer → data broker
The organization does not necessarily need a single headquarters.
It does not need a single nationality.
It does not even need permanent membership.
An individual capable of obtaining access to a corporate network can become economically useful to one ransomware operation today and another tomorrow.
That creates something resembling a transnational cyber labor market.
And this may be one of the most important developments in cyber policy.
The geopolitical system was built around states.
The digital criminal economy increasingly operates through networks.
The Economics of Decentralization
Ransomware-as-a-service changed the economics of cybercrime.
Instead of requiring every criminal organization to develop every capability internally, specialized actors can provide individual components.
One participant obtains access.
Another supplies malware.
Another negotiates.
Another manages infrastructure.
Another launders cryptocurrency.
The result is a form of cyber specialization.
It is similar to the division of labor that made legitimate multinational corporations scalable.
The difference is that the participants do not need to share the same physical location, legal identity or political allegiance.
This creates an unusual resilience.
Law enforcement may arrest an operator without eliminating the underlying capability.
An infrastructure provider can disappear while the affiliates move elsewhere.
A ransomware brand can collapse while its participants migrate to another operation.
A sanctions regime can target one organization while the economic incentives that produced the organization remain intact.
The organization therefore becomes less important than the market surrounding it.
This is the first major policy lesson.
Governments may be fighting companies when they need to disrupt markets.
The Negotiation Problem
There is another indication that ransomware is becoming more organizationally sophisticated: negotiation itself.
A recent academic study published in August 2026 examined ransomware negotiations and identified distinct stages including proof of life, bargaining and support, while documenting strategic shifts by both attackers and victims during the process.
This matters because negotiation transforms the attack.
The victim is no longer simply confronting malicious code.
The victim is interacting with an organization capable of:
- establishing credibility;
- providing evidence of compromise;
- setting deadlines;
- adjusting demands;
- responding to bargaining;
- applying psychological pressure;
- managing reputational threats.
The ransomware operator therefore becomes, in effect, a negotiating entity.
That does not make the organization legitimate.
But it does make the interaction structurally different from conventional cybercrime.
The attacker is exercising influence.
And influence is the foundation of political power.
When Criminal Power Becomes Strategic Power
This is where the distinction between cybercrime and cyber conflict becomes increasingly difficult.
Imagine an organization capable of simultaneously:
- compromising hundreds of companies;
- disrupting critical economic sectors;
- extracting hundreds of millions of dollars;
- operating across multiple countries;
- recruiting internationally;
- negotiating with multinational corporations;
- exploiting geopolitical tensions;
- and surviving the arrest or disappearance of individual members.
At what point does the organization become strategically relevant?
Not politically legitimate.
Not a state.
But strategically relevant.
This distinction matters.
A ransomware group does not need an army, territory or diplomatic recognition to create consequences that governments normally associate with hostile political actors.
It can affect hospitals.
It can interrupt manufacturing.
It can disrupt transportation.
It can compromise government contractors.
It can expose sensitive information.
It can create diplomatic pressure between the country where the victim is located and the country where investigators believe the attackers operate.
The organization may therefore possess effects without sovereignty.
That may be the defining characteristic of the next generation of non-state cyber power.
The Sovereignty Gap
International law is fundamentally comfortable with states.
States have territory.
States have jurisdiction.
States have recognized governments.
States can enter treaties.
States can be sanctioned.
States can be held responsible for internationally wrongful acts.
Cybercriminal organizations fit none of these categories neatly.
The attacker may reside in one country.
The infrastructure may be located in another.
The victim may be in a third.
The cryptocurrency may move through a fourth.
The stolen data may be stored somewhere else entirely.
And the organization itself may have no permanent physical existence.
This creates what might be called a sovereignty gap.
The cyber operation has consequences across borders, but there is no single sovereign authority capable of addressing the entire organization.
That gap is one reason cyber diplomacy increasingly overlaps with cybercrime enforcement.
The State Behind the Criminal?
There is an even more difficult problem.
Some criminal cyber organizations operate in environments where governments may tolerate, exploit or selectively suppress their activities.
That does not mean every ransomware group is a state proxy.
It does mean that the traditional distinction between criminal activity and state activity can become difficult to maintain when infrastructure, personnel and interests overlap.
A state does not necessarily need to command a criminal group.
It may benefit simply by allowing the group to operate against foreign targets.
This produces a spectrum:
Independent criminal → tolerated criminal → strategically useful criminal → state-enabled actor → state-directed operation
The boundaries between these categories are rarely visible from the outside.
That ambiguity is strategically valuable.
A government can deny responsibility.
A criminal organization can deny political motivation.
And the victim is left with the consequences.
The Problem With Treating Every Actor as a State
There is a danger in the opposite direction.
Cyber policy sometimes treats every sophisticated cyber operation as evidence of state involvement.
That is equally problematic.
Criminal organizations have become remarkably capable without requiring government command.
The development of professional cybercrime markets means that capabilities once associated primarily with intelligence services are increasingly available to private criminal networks.
Initial access can be purchased.
Malware can be rented.
Infrastructure can be obtained.
Stolen credentials can be acquired.
Victims can be selected through data.
Negotiations can be professionalized.
The result is an uncomfortable strategic reality:
The capabilities of the state are no longer necessarily exclusive to the state.
This is one of the most important transformations occurring in cyberspace.
A New Category of Cyber Power
Cyber policy has traditionally focused on three broad categories:
State actors.
Private companies.
Criminal actors.
The boundaries are becoming less useful.
A more accurate model may be:
State power
Corporate power
Criminal power
Networked power
The fourth category is increasingly important.
Networked power does not require sovereignty.
It requires connectivity.
An organization can assemble capabilities from individuals and businesses distributed across jurisdictions without creating a conventional institution.
Its strength comes from the network itself.
That is why dismantling one ransomware brand may not dismantle the ecosystem that produced it.
The Diplomatic Question
This creates a difficult question for cyber diplomacy:
Can states negotiate with organizations they refuse to recognize?
The answer is already complicated.
Companies negotiate with ransomware operators.
Incident-response teams communicate with attackers.
Law enforcement sometimes uses intermediaries.
Governments issue warnings directly to criminal organizations.
Sanctions identify individuals associated with cybercrime.
Intelligence agencies attempt to map their networks.
None of these actions constitutes diplomatic recognition.
But they all acknowledge the same reality:
The organization has become an actor with whom someone must interact.
This is not diplomacy in the traditional sense.
It is something closer to operational diplomacy with non-state cyber actors.
And that concept deserves considerably more attention.
The Future May Not Be About Eliminating Ransomware
The strategic objective of cybersecurity policy has often been framed as elimination.
Eliminate the group.
Seize the infrastructure.
Arrest the operators.
Disrupt the cryptocurrency.
Patch the vulnerability.
But the resilience of decentralized cybercrime suggests a different objective may be necessary.
Governments may need to target the ecosystem rather than the organization.
That means disrupting:
- access markets;
- criminal infrastructure;
- cryptocurrency laundering;
- recruitment channels;
- exploit markets;
- data monetization;
- affiliate networks;
- hosting providers;
- brokerage systems.
The objective becomes economic and organizational disruption.
Not merely technical disruption.
That is a fundamentally different policy model.
The Cybercriminal as a Strategic Actor
The emergence of networked ransomware organizations does not mean cybercriminals have become states.
They have not.
They do not possess sovereignty.
They do not possess legitimate political authority.
They do not possess recognized territorial jurisdiction.
But some of them increasingly possess something else:
the ability to generate strategic consequences across borders without possessing a state.
That is precisely why they matter to cyber diplomacy.
The international system was designed around sovereign actors.
Cyberspace has created actors that can exercise influence without sovereignty.
Ransomware may therefore be only the most visible example of a much larger transformation.
The future cyber environment will not be divided simply between governments and hackers.
It will increasingly contain networks capable of organizing capital, technology, intelligence and coercion independently of traditional political structures.
The central question for governments will no longer be only how to defend against them.
It will be how to classify, deter, disrupt and, when necessary, interact with actors that exist outside the conventional architecture of international relations.
That is the real transition.
Ransomware is becoming less interesting as a category of malware.
It is becoming more important as a model of decentralized power.
And once cyber power can exist without sovereignty, the architecture of international security begins to change.


Leave a comment