Mikko Hyppönen of WithSecure marks a decade of corporate targeting ransomware with no end in sight as a $3.5B plus Acronis deal and a July attack surge show why distraction narratives miss the point.
Ten years after the first corporate-targeting ransomware wave, the attackers have stopped being a story and started being infrastructure. They run on a decade of capital, tooling, and tradecraft, and they do not need the news cycle to notice them. AI hype is the wrong explanation for why they keep winning.
Mikko Hyppönen, the WithSecure researcher who has tracked ransomware since the CryptoLocker era, marked the 10-year anniversary in The Register by saying he sees no end in sight. That is not panic language. It is the posture of someone who has watched a criminal category mature into permanent infrastructure while defenders have spent the same decade playing catch-up.
Ransomware surged in July after a Q2 lull, Infosecurity Magazine reported. That cadence is what a market looks like when it runs on attacker schedule rather than on whatever else the technology press is covering. Sophos's State of Ransomware 2025 and DeepStrike's 2025 payout statistics both show the same shape: ransom economics, recovery costs, and frequency are structural inputs, not news shocks.
EQT is acquiring a majority of Acronis at an equivalent $3.5B-plus valuation, with the size of the stake not disclosed, per The Register's coverage. The deal is a private-equity check on a category, not a banner quarter. It prices ransomware defense, backup, and recovery as durable infrastructure the way utilities get priced. Nobody calls a water utility "back" when it expands.
The falsifier is the prior trend line. Ransomware payments, downtime, and victim counts were already at category scale through 2019–2024, well before generative AI became the attention sink. The Comparitech news index and Sophos's annual report both show a baseline of permanent damage across that window. If looking away caused the surge, the surge would have started in 2023, not held steady through the entire prior half-decade.
Trend Micro's research on the Gentlemen ransomware actor describes a group that behaves like a small services business: defined roles, repeatable playbooks, and a willingness to take lower payouts from softer targets rather than swing for maximum damage. That is what mature criminal infrastructure looks like, and it lines up with the macro picture. The same pattern is showing up in the Microsoft on-prem SharePoint exploitation after a failed patch round, which The Register flagged in the same week.
He calls it a long, stable career bet for engineers willing to do the unglamorous, process-heavy work, and that posture is the agency-expanding read for security teams: the problem is a known quantity with a playbook. The defensive moves that actually move the needle are unglamorous: patch cadence, identity hygiene, tested backups, segmentation, and incident-readiness drills run on a calendar. None of those depend on what is trending in the technology press.
The next concrete checkpoint is the EQT/Acronis close and the Sophos State of Ransomware 2026 release, both of which will reprice the category against this summer's volume. If the July surge proves to be a normal seasonal pattern, the AI-distraction narrative will continue to age badly. If it does not, the structural case still does not need a new villain to explain it.