
Robert Boyce at Accenture describes a new model for understanding extortion groups
The landscape of cyber-extortion is becoming increasingly complex and dangerous. Recent reports indicate a significant rise in ransomware attacks, with new groups emerging. High-profile attacks, such as those on healthcare providers like Synnovis, have caused widespread disruption and highlighted the urgent need for effective strategies to combat these threats.
To assist organisations in deciding if and how they should interact with cyber criminals during an extortion attack, a new model has been developed by Accenture Cyber Intelligence (ACI) that assess the credibility and stability of ransomware and data extortion groups: Extortion Group Maturity Model (EGMM).
Many extortion groups operate on a ransomware-as-a-service (RaaS) model, leasing or selling their malware to affiliates. Recently, two notorious RaaS groups, ALPHV-ng (a.k.a. BlackCat) and LockBit, faced law enforcement takedowns and accusations of defrauding their affiliates. This has led to speculation about the potential end of the RaaS model.
Recent events have increased the complexity of the extortion ecosystem, introducing new relationships between threat actors and a recruitment race among groups to hire malicious talent.
These events have also introduced new extortion techniques targeting C-suites, an increased propensity for harassing victims, and a heightened focus on the theft and leaking of highly sensitive personally identifiable information, such as healthcare data.
Consequently, data extortion and ransomware are expected to remain major threats to enterprises throughout 2024 and 2025.
As mentioned, there is a new model that help to provide a snapshot of a group’s stability and predictability during a ransomware or data extortion event, and help organisations prime their situational awareness prior to an event and better understand their adversaries.
The EGMM is an analytical tool that helps assess the credibility, stability, and anticipated behaviour of active ransomware and data extortion groups. When applied, the model can help decision-makers judge if and how they should interact with a malicious group.
The EGMM helps organisations assess a threat group’s predictability and stability based on 19 unique data points. The model then uses those data points to plot a group on a scatter graph along two axes: chaotic to stable, and predictable to unreliable. This approach effectively divides extortion groups into four categories—credible, reliable, volatile, and unreliable/unpredictable—each with individual risks and suggestions.
Figure 1. Key active ransomware and extortion groups on ACI’s EGMM
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543