---
title: The Top 5 Most Famous Ransomware Attacks
description: Read our top five picks for the most famous ransomware attacks to date, categorized by type and dollar amount, and why they earned a spot on the list.
image: https://www.mitnicksecurity.com/hubfs/Top%20Ransomware%20Attacks.jpg
---

# The Top 5 Most Famous Ransomware Attacks

[Ransomware](https://www.mitnicksecurity.com/blog/tag/ransomware)

[ Mitnick Security| ](https://www.mitnicksecurity.com/blog/author/mitnick-security)  09.30.2021| 4 MIN READ TIME

Cybercriminals everywhere are demanding thousands to millions of dollars to unlock the technology they’ve attacked and compromised. This type of malware attack earned itself the name* *[*ransomware*](https://www.mitnicksecurity.com/blog/what-is-a-ransomware-attack) for the high ransoms bad actors require to release devices, applications, or data.

But to name “the most famous ransomware attacks,” it’s important to understand how subjective that statement is. We could be talking about the scale of the attack, in terms of the amount or sensitivity of data stolen. Or the severity of the repercussions the attack had on the victim, its customers or other connecting partners. What about the price of the ransom itself?

Let’s look at some of the most notable ransomware attacks to date, categorized by type and dollar amount, and discuss some reasons they earned a spot on the list:

## Most Famous Ransomware Attacks By Type:

Ransomware is a type of malicious software designed to restrict access to a computer system until a payment is made. The key here is… it’s software. While cybercriminals often use a similar foundation to their software code, the most evolved ransomware is a custom form of malware.

Here are some of the top ransomware types and why they were — or still are — so dangerous:

### WannaCry

Flashback to 2017. A form of ransomware called [WannaCry](https://usa.kaspersky.com/resource-center/threats/ransomware-wannacry) spread like wildfire through vulnerable SMB ports and [phishing attacks](https://www.mitnicksecurity.com/blog/spear-phishing-targeted-email-scams-what-you-need-to-know-about-this-hacking-technique), infecting 7,000 computers within the first hour of its release. Within a day, it [infected more than 230,000 computers](https://en.wikipedia.org/wiki/WannaCry_ransomware_attack) in over 150 countries. The attack affected leaders in various industries, such as the car giant Honda and thousands of NHS hospitals across the UK, seizing control of industrial processes until the ransom was paid. 

### TeslaCrypt

In 2016, video gamers faced a form of Trojan ransomware called [TelsaCrypt](https://usa.kaspersky.com/resource-center/threats/teslacrypt), which infected game saves, user profiles, recoded replays, etc. This gamer ransomware affected 40 different games, such as the Call of Duty series, World of Warcraft and Minecraft — searching for 185 file extensions. Newer variants of the malware also affected encrypted Word, PDF, JPEG and other files. This ransomware made our list for the extent of its spread and the depth of its affected files. In May 2016, the ransomware spread came to a halt when [the malware developers shut down the ransomware](https://en.wikipedia.org/wiki/TeslaCrypt) and released the master decryption key. 

### Petya and NotPetya

[Petya](https://www.mcafee.com/enterprise/en-us/security-awareness/ransomware/petya.html#petya-notpetya) emerged in 2016 but in 2017, it began spreading internationally as ransomware. On July 27th, 2017, it targeted more than 80 companies in France, Germany, Italy, Poland, the United Kingdom, the United States, Russia, and Ukraine. It affected Windows servers, PCs, and laptops, exploiting a vulnerability in Microsoft’s implementation of the Server Message Block protocol — asking victims to conduct a system reboot, after which the system is locked. The newer variant called NotPetya has distinctive malware behavior. It uses different keys for encryption, has unique reboot styles, displays and notes, and was [designed by the Russian government.](https://en.wikipedia.org/wiki/Petya_(malware)) 

### REvil, AKA Sodinokibi

The modern-day Russian-based hacking group [Ransomware Evil (REvil),](https://en.wikipedia.org/wiki/REvil) also known as Sodinokibi, is a unique ransomware-as-a-service (RaaS) operation. These bad actors developed a subscription-based model that enables affiliates to use already-developed ransomware tools to launch their own ransomware attacks, wherein REvil [receives a portion of the profit every time it’s deployed](https://us-cert.cisa.gov/ncas/alerts/aa21-131a). In 2021, the group breached the tech powerhouse Apple, stealing information on their upcoming products. They’re also behind the recent [Kaseya](https://www.mitnicksecurity.com/blog/an-overview-of-kaseya-the-biggest-ransomware-attack-on-record) and [JBS](https://www.mitnicksecurity.com/blog/an-overview-of-the-2021-jbs-meat-supplier-ransomware-attack) ransomware attacks. They made our list for their present relevancy — REvil’s attacks are only becoming more frequent, severe, and widespread — and because of their infamy of commercializing ransomware as a service, especially towards supply chains.

### DarkSide

Another present-day RaaS operation is [DarkSide](https://en.wikipedia.org/wiki/DarkSide_(hacking_group)). This hacking group located in  Eastern Europe targets victims using their own unique form of ransomware, believed to resemble the software used by REvil, as a possible partner of the Russian attackers. They were the bad actors behind the recent [Colonial Pipeline cyberattack.](https://us-cert.cisa.gov/ncas/alerts/aa21-131a) Their malicious software earned its place on our top five most famous ransomware list for how destructive the program can be. The software deletes files in the recycle bin one by one, uninstalls security and backup software programs, and terminates security processes to allow access to data files.  
 

## Most Famous Ransomware Attacks, By Payout:

Ransomware attacks are also made famous for how financially crippling they were. Oftentimes, bad actors target companies and industries that are vital, so they must remain fully operational at all times. Freezing access to even certain operations or files for a few days could have a monumental impact on the company’s surrounding economy and customer base at large. When this happens, these major corporations often pay the ransom, knowing that a few days of downtime could account for much more damage and loss than the unlocking fee. Here’s a round-up of the most costly payouts to date:

### 5. Brenntag

Amount paid: $4.4 million

### 4. Colonial Pipeline

Amount paid: $4.4 million

 

### 3. CWT Global

Amount paid: $4.5 million

### 2. JBS

Amount paid: $11 million

### 1. CNA Financial

Amount paid: $40 million

 

## Reduce Your Likelihood of Ransomware Attacks

Over the last few years especially, [ransomware attacks](https://www.mitnicksecurity.com/blog/main-types-of-ransomware-differences) have been growing both in frequency and severity — becoming more rampant and complex in the depth of information stolen. 

As the attacks continue to increase, it’s more important than ever to make sure your company’s security is airtight. 

Download our* *[*5-1/2 Easy Steps to Avoid Cyber Threats*](https://www.mitnicksecurity.com/lp-easy-steps-to-avoid-cyber-threats)* *ebook to make instant improvements to your security infrastructure today. 

[![New call-to-action](https://no-cache.hubspot.com/cta/default/3875471/7f9b1de1-cf7c-4700-8892-cdf9402b32cf.png)](https://cta-redirect.hubspot.com/cta/redirect/3875471/7f9b1de1-cf7c-4700-8892-cdf9402b32cf)

# Related Resources

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/included-in-pentesting-report.jpeg?width=350&name=included-in-pentesting-report.jpeg)

by Mitnick Security  | 06.30.2026  | 8 min

#### What Does a Pentest Report Look Like? Inside the Results

If your last pentest report was a spreadsheet of CVE numbers with color-coded severity ratings, here is an uncomfortable truth: you did not get a penetration test. You got a vulnerability scan with a ...

 Continue Reading

Global Ghost Team, Penetration Testing 

](https://www.mitnicksecurity.com/blog/penetration-test-report)

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Mitnick-Security-071-Enhanced-NR-Copy1.jpg?width=350&name=Mitnick-Security-071-Enhanced-NR-Copy1.jpg)

by Mitnick Security  | 06.08.2026  | 8 min

#### Choosing a Pentesting Company That Thinks Like an Adversary

5 Questions to Vet Any Penetration Testing Company Finding a pentesting partner that can produce a deep dive pentest is harder than knowing what one should look like. When evaluating vendors, seasoned...

 Continue Reading

Penetration Testing 

](https://www.mitnicksecurity.com/blog/best-penetration-testing-company)

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Person%20reading%20book.jpeg?width=350&name=Person%20reading%20book.jpeg)

by Mitnick Security  | 05.11.2026  | 5 min

#### 4 Essential Cybersecurity Books to Harden Your Mindset (and Your Network)

Offense is the best defense. If you want to stop a hacker, you have to read like one.

 Continue Reading

Cyber Security 

](https://www.mitnicksecurity.com/blog/best-cybersecurity-books)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Mitnick Security",
    "url" : "https://www.mitnicksecurity.com/blog/author/mitnick-security"
  },
  "dateModified" : "2022-05-20T17:25:53.400Z",
  "datePublished" : "2021-09-30T20:06:40.000Z",
  "headline" : "The Top 5 Most Famous Ransomware Attacks",
  "image" : [ "https://www.mitnicksecurity.com/hubfs/Top%20Ransomware%20Attacks.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.mitnicksecurity.com/blog/top-5-most-famous-ransomware-attacks",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.mitnicksecurity.com/hubfs/Mitnick-Security-Logo-White-H.png"
    },
    "name" : "Mitnick Security Consulting, LLC"
  }
}
```