Ransomware persists because it is organised as an industry rather than as individual mischief. The structure explains both its scale and why disrupting one group changes little.
The work is divided among specialists
Different groups handle different stages. Some obtain initial access and sell it, others develop the encryption software, and others operate the intrusion itself.
This division means an operator does not need to be capable of finding a way in, and someone who finds a way in does not need to run an extortion campaign.
Each role can therefore be filled by a specialist, which lowers the skill required to participate and raises the overall volume of activity.
Access is bought rather than earned
A substantial share of intrusions begin with credentials purchased from a broker, harvested earlier through phishing or from software that stole them from an infected machine.
Remote access services exposed to the internet without a second factor remain a common entry point, because the credential alone is sufficient.
The result is that many victims were compromised weeks before anything visible happened, while access sat waiting for a buyer.
Encryption is no longer the only lever
Because organisations improved their backups, encryption alone stopped being reliable leverage. Operators responded by copying data out before encrypting anything.
The threat then becomes publication rather than loss, and a restored backup does not address it.
This is why an incident is now a disclosure event as much as an availability event, with regulatory and contractual consequences that outlast the technical recovery.
Negotiation follows a script
Operators run structured negotiation processes, often with dedicated staff, published portals and predictable discounting from an initial demand.
Demands are frequently scaled to the victim's apparent size, sometimes informed by financial documents taken during the intrusion.
The professionalism serves a purpose. A reputation for restoring data after payment is what keeps future victims willing to pay, so operators have a commercial interest in delivering working decryption.
That reputation is also fragile, which is why groups whose tooling corrupts data during recovery tend to lose standing quickly and rebrand.
Why disruption has limited effect
Law enforcement action against a group removes the brand and the infrastructure but not the people, who typically reappear under a new name.
The underlying supply of access, tooling and payment channels is unaffected, so the capacity to operate persists after any single takedown.
Durable reduction comes from removing the entry points: enforced second factors, restricted remote access and offline backups that an intruder cannot reach.