Ransomware-as-a-Service
Ransomware-as-a-Service (RaaS) is a criminal business model in which the people who write ransomware sell or rent it to other criminals who then carry out attacks. This arrangement lets people with little technical skill launch ransomware attacks, because the specialized malware is supplied by others. It works much like a legitimate software subscription, but for illegal purposes.
RaaS is a cybercrime business model in which ransomware developers (operators) create, maintain, and license ransomware code or infrastructure to third-party actors (often called affiliates), who conduct the actual intrusions and deployments. Arrangements described in the evidence include subscription-based access, outright sale, or leasing of ransomware variants, with operators and affiliates collaborating to execute attacks. This model lowers the technical barrier to entry, enabling less-skilled actors to carry out ransomware campaigns using tooling developed by others. Note that RaaS is a threat concept, not an insurance or resilience term; the availability of insurance coverage for losses arising from a RaaS-enabled incident (such as first-party cyber extortion, business interruption, or data restoration, or third-party liability) depends entirely on the specific policy wording, endorsements, exclusions, and jurisdiction, and is not addressed by the evidence provided here.
Why it matters
Ransomware-as-a-Service matters because it fundamentally changes the shape of the threat facing insureds. By separating the people who write ransomware from the people who deploy it, the RaaS model lowers the technical barrier to entry and allows less-skilled actors to launch attacks using tooling developed and maintained by others. From a risk perspective, this means the population of potential attackers is broader and more diverse than it would be if each threat actor had to build capability from scratch, which complicates efforts to model likelihood and to reason about who might target a given organization.
For risk managers and underwriters, RaaS is a threat concept rather than a coverage concept, and that distinction is important. Whether losses arising from a RaaS-enabled incident are insured depends entirely on the specific policy wording, endorsements, exclusions, conditions precedent, and jurisdiction. A RaaS-driven attack might give rise to first-party exposures such as cyber extortion, business interruption, or data restoration costs, and to third-party exposures such as privacy liability or regulatory defense, but the mere fact that an attack used a RaaS variant tells you nothing about whether any of those losses would be covered. Coverage turns on the terms of the contract, not on the criminal business model behind the incident.
RaaS also reinforces why risk transfer through insurance is not a substitute for risk mitigation and resilience. Because the model makes ransomware campaigns more accessible to a wider range of actors, controls that reduce likelihood and impact, alongside tested recovery capabilities measured against recovery time and recovery point objectives, remain central to managing the exposure. Insurance can transfer a portion of the financial consequences subject to policy terms, but it does not reduce the probability that a RaaS affiliate attempts an intrusion and does not by itself constitute resilience.
Who it's relevant to
Inside RaaS
Common questions
Answers to the questions practitioners most commonly ask about RaaS.