Crime with a Support Desk
What a ransomware gang's customer service reveals about everything built to protect you
The email arrived at 3.17 in the morning.
Sam hadn’t slept. They’d been sitting at their kitchen table for four hours watching the progress bar on their screen crawl — file after file locked, folder after folder gone dark. The attack had started somewhere in the accounts system, spread quietly through the network, and by midnight the company’s billing platform, its customer database, and eighteen months of project files were encrypted behind a key Sam didn’t have.
Then the email came. It was polite. It opened with an acknowledgement that this was a difficult situation. It explained, clearly and without technical jargon, what had happened and what the options were. It included a link to a payment portal with step-by-step guidance. It offered a live chat facility for anyone who needed help navigating the process. At the bottom, there was a note that a support representative was available around the clock and would typically respond within the hour.
Sam had never received customer service this good from anyone.
The support desk that worked
This is not an unusual story. The criminal organisations behind ransomware attacks have built support infrastructures that would be impressive in any legitimate technology business — documentation in multiple languages, and in some documented cases a rating mechanism through which affiliates — the criminal operators who carry out attacks on behalf of the platform — could evaluate the service they received.
They have done this because it works. A victim who cannot navigate the payment process is a victim who might not pay. Friction costs money. They removed it.
The DarkSide group, responsible for the 2021 attack on Colonial Pipeline in the United States, operated with the organisational structure of a funded technology company. They developed proprietary tools, leased their capabilities to vetted affiliates who carried out attacks on their behalf, and maintained a support function specifically to guide victims through the payment and decryption process. The attack locked down the billing and operational systems of the largest fuel pipeline on the US East Coast, triggered fuel shortages and panic-buying across multiple states, and prompted a federal emergency declaration. Colonial Pipeline’s CEO, Joseph Blount, confirmed to the Senate Homeland Security Committee that the company had paid the ransom — 75 bitcoin, approximately $4.4 million at the then-exchange rate. The ransom note had demanded approximately five million dollars.¹ The support desk was open the entire time.
The question this raises is not primarily about the criminals. Their logic is coherent. They are running a revenue model and they have optimised it. The question is about what their model reveals about everything else.
What the legitimate system was built to do
A person dealing with a digital crime — whether ransomware, fraud, or identity theft — typically encounters a response system that was designed for a different era and a different scale of problem. The bank’s fraud line connects them with an adviser working from a script that was written before this kind of crime existed in its current form. The police non-emergency line takes a report and assigns a reference number. The relevant government body sends an acknowledgement within five working days.
Each of these institutions is staffed by people trying to help within a structure that was not built to help at speed, at scale, or at the point of maximum need.
The criminal support desk is better not because criminals are more talented. It is better because it was designed entirely around what the paying customer needs at the moment they need it. That is a design choice. The legitimate systems were designed around something else — compliance, liability, institutional process, historical precedent — and the human being in distress is not at the centre of any of it.
“The ransomware gang had better customer service than the bank that was supposed to help you recover from them.”
When a fraud line or a government body responds to a digital crime victim, the response is designed to help that person complete a process — file a report, receive a reference number, trigger a workflow. That is not the same as helping them do what they actually need to do. The paper trail grows. The problem does not. And the response does not adapt: it does not know where this specific person is right now — technically, emotionally — and it was never built to find out.
The criminal support desk was built around exactly that question. Not because of any ethical commitment, but because its commercial success depends on it. That is the uncomfortable mirror it holds up. The legitimate system, by contrast, was designed to be defensible. That is an institutional virtue. It is not the same as a human one.
The Colonial Pipeline attack disrupted fuel markets across multiple states for six days, driving fuel prices above three dollars a gallon for the first time since 2014 and prompting panic-buying across the south-east of the United States.² The polite emails were in service of extortion.
What the comparison reveals
The argument is that something in the legitimate system has been designed wrongly, and that the criminal model makes the wrongness visible by contrast. When a fraud victim gets better guidance from the people who defrauded them than from the institution that holds their money, that is not an anomaly. It is a diagnostic. The system that was built to protect and assist that person has, somewhere in its design, prioritised something other than them.
That matters because the design is not inevitable. It is a series of choices, made by people, in institutions, at particular moments in time.
My Opinion
Cyber crime is not the work of individuals in dark rooms. It is a structured business model, operated by organised criminals with the discipline and infrastructure of any revenue-generating enterprise. The support desk is not absurd — it makes complete commercial sense. Once you accept that framing, the question for every organisation changes. Not “could this happen to us?” but “what is our blast radius, and what do we have in place to recover?” This is not going to become simpler or rarer. Crime now operates at the speed of code. Our response still runs at the pace of policy and procedure. That is an asymmetric challenge, and naming it is the first step to treating it seriously.
This is the territory that The Shadow System covers in its opening section — the professionalisation of the criminal economy, and what that professionalisation reveals about the failures of the legitimate one.
Your experience is part of this
These patterns are not abstract. The design failures described here accumulate in individual moments — a fraud call that went nowhere, a report that produced only a reference number, a process that kept moving while the person at the centre of it stood still. If you’ve encountered any part of this, your account is relevant evidence.
Does this story relate to you — have you ever found the process of reporting a digital crime or fraud more difficult than the crime itself deserved?
If you have your own experience of how institutions responded when something went wrong digitally, share it. These patterns only become visible when enough people name them.
If you could redesign the response a fraud or ransomware victim receives from legitimate institutions, what would be the first thing you would change?
And the harder question: is this a technology failure, a culture failure, or an incentive failure — and does the answer change what we should do about it?
Authors Note
Sam is a fictional character. Their story is drawn from a combination of professional observation and personal proximity to real events. The experiences described are real. The person is not.
References
¹ Joseph Blount, CEO, Colonial Pipeline — Senate Homeland Security and Governmental Affairs Committee testimony, 8 June 2021. Blount confirmed the payment was 75 bitcoin (approximately $4.4 million at the time of payment); the original ransom demand was approximately $5 million. The FBI subsequently recovered approximately $2.3 million by seizing 63.7 Bitcoin (the value had fallen since the date of payment). Sources: CNBC; Nextgov/FCW; Department of Justice press release, 7 June 2021.
² Colonial Pipeline shut down 7 May 2021, restarted 12 May 2021. Fuel price and disruption data confirmed across multiple sources; note that a University of Kansas study (December 2021) found the longer-term gas price impact was more localised than early reporting suggested. Sources: CISA retrospective; University of Kansas study.
You’re reading The Next Evolution by Neil Catton, articles that explore the human world and the intersection of technology, they try and ask difficult questions - not to scare - but to inform. If someone forwarded this to you, you can subscribe free at neilcatton.substack.com.
Neil Catton is the author of The Next Evolution, The Cognitive Crucible and The Shadow System - available on Amazon, and writes at the intersection of technology, ethics, and human purpose.


