How do ransomware groups choose their targets? An empirical analysis
Tyler Moore,
Neil Gandal and
Dmytro Kashchuk
No 21661, CEPR Discussion Papers from Centre for Economic Policy Research
Abstract:
Ransomware groups vary in the types of organizations they compromise, yet little empirical work has examined whether these differences extend to the technology stacks of victims. We analyze 5,190 ransomware incidents across 151 groups, linking each victim to its observed technology stack from the SWDB Company Intelligence database. We find that some enterprise software is associated with greater ransomware risk than others, and that this association is often stronger for technologies carrying more known vulnerabilities. Next, by analyzing leaked chat logs of leading ransomware groups, we present direct evidence that some groups choose their victims based on observed technology use and revenue data gathered through opensource intelligence. Finally, examining the full population of victims, we find that some groups concentrate on particular technologies and revenue profiles, while others appear more opportunistic, with a victim profile close to the overall population.
Keywords: Empirical; analysis (search for similar items in EconPapers)
JEL-codes: D00 D22 (search for similar items in EconPapers)
Date: 2026-06
References: Add references at CitEc
Citations:
Downloads: (external link)
https://cepr.org/publications/DP21661 (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:cpr:ceprdp:21661
Ordering information: This working paper can be ordered from
https://cepr.org/publications/DP21661
Access Statistics for this paper
More papers in CEPR Discussion Papers from Centre for Economic Policy Research 33 Great Sutton Street, London EC1V 0DX, UK.
Bibliographic data for series maintained by CEPR ().