FinCEN charts massive surge in ransomware activity reports in H1 2021

Quick Take

  • FinCEN, the Treasury’s AML office, finds that 2021 is on pace to beat 2020’s record year for ransomware.
  • There are, however, some issues with the presentation of FinCEN’s data, which may exaggerate the amount of money going to ransomware payouts. 
  • What may well be happening is an improvement in filing compliance. 

The U.S. anti-money laundering watchdog has put out a new report on a surge in ransomware payment activity in 2021. But is it a surge in ransomware or in reporting related to ransomware?

Published on October 15, the report on ransomware in the first half of 2021 comes from the Financial Crimes Enforcement Network (FinCEN). The report says we are in the midst of a bumper year:

"The total value of suspicious activity reported in ransomware-related SARs during the first six months of 2021 was $590 million, which exceeds the value reported for the entirety of 2020 ($416 million)."

FinCEN is the Treasury office that enforces compliance with the Bank Secrecy Act and other anti-money laundering law. Among a host of provisions, financial institutions operating in the U.S. are required to file suspicious activity reports, or SARs, whenever they encounter activity that is, well, suspicious. 

It is from its database of SARs that FinCEN compiled its data. The details are, however, tricky. As the office explained:

"The full data set consisted of 635 SARs reporting $590 million in suspicious activity. Of the 635 SARs filed during the review period, 458 report actual transactions that occurred during the review period worth $398 million. The remaining 177 SARs report transactions that occurred before 1 January 2021."

While 2021 ransomware payouts seem on track to exceed those of 2020, the rate of change is, consequently, not as significant as that of SAR filing. Visualized, that difference looks like this:

Source: FinCEN

THE SCOOP

Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

If you take the date of the actual attack rather than the filing, FinCEN's data shows $398 million in ransomware events, not $590 million. This may indicate an improvement in filing compliance, but it could also be the result of a commonplace lag time in identifying cryptocurrency addresses associated with ransomware attacks.

Another potential issue with this report is that FinCEN requires SARs reports from a number of financial operators that could act along a chain of a single ransomware payment, opening up the possibility of double-counting. 

In trends, FinCEN identified increased requests from ransomware actors for payouts in what the office calls "Anonymity-enhanced Cryptocurrencies." In the industry, these typically go by the name "privacy coin." The most famous privacy coin, Monero (XMR), received special attention. Data on XMR payouts are notoriously hard to come by and unreliable. 

As previous authorities have noted, however, FinCEN said that the principle means of cashing out ransomware is not tricky technologies, but rather centralized cryptocurrency exchanges operating either without regulation or in jurisdictions that do not require know-your-customer checks. 

High-profile ransomware attacks on U.S. infrastructure earlier this year catapulted the area to the top of the White House's national security agenda. Earlier this week, the Biden administration convened 32 countries to discuss regulation that would protect against future devastating attacks. 

In September, the U.S. Treasury sanctioned a crypto exchange for the first time. The exchange in question had been a vector for a number of ransomware payouts. 


© 2023 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

About Author

Kollen Post is a senior reporter at The Block, covering all things policy and geopolitics from Washington, DC. That includes legislation and regulation, securities law and money laundering, cyber warfare, corruption, CBDCs, and blockchain’s role in the developing world. He speaks Russian and Arabic. You can send him leads at [email protected].