This year has seen a rapid increase in ransomware attacks around the world. Some industry statistics suggest that ransomware attacks have increased by 200% to 400% this year. That's a staggering increase.
The United States remains the number one target for ransomware attacks. Canada and the United Kingdom come in second and third place respectively. Without a doubt, the United States represents a target-rich environment for hackers.
Over the past few months, attacks have become more targeted. Local governments, higher education, NGOs and service providers have all been targeted. This week, the dental industry was targeted by hackers.

Why are ransomware attacks increasing in frequency? They represent a crime. Most attacks are perpetrated by criminal elements, as these types of attacks are relatively easy to spread and can be very profitable for the perpetrator. If you’re not familiar with what ransomware is, and I’m not sure how you wouldn’t be, just imagine a hacker breaking into a computer and installing ransomware on an employee. The ransomware then encrypts all the data it can find, rendering it unusable. When employees on the infected network try to access their data, they’ll see a pop-up message on their screen, informing them of exactly what happened and asking them to pay a ransom to restore their access to the data.
At this point, affected organizations typically have one of three options: 1) rebuild their network and all of their data from scratch. This is usually impractical for a variety of reasons. 2) restore data from clean, uninfected backups. This is the best possible outcome, as long as it hasn’t been too long or the backups haven’t been compromised. 3) pay the ransom and regain access to data . While this may only make the hackers excited, many affected organizations have chosen this route, as it is often the quickest and least expensive route to returning to normal operations.
The targeting of these attacks is somewhat new. Municipal governments are often an easy target. Municipalities focus their budgets on providing services to citizens. Often, information security is not a high-priority budget item. As a result, cybersecurity awareness training is often non-existent or rare. This makes municipal employees more vulnerable to these attacks. Once infected, municipalities are often not equipped to quickly detect and contain the spread, making recovery difficult, time-consuming, and expensive.
In terms of targeting MSPs (Managed Service Providers), this makes sense, as MSPs have access to literally thousands of computer systems, and if a hacker can penetrate an MSP, they can potentially use it as a point to hit more organizations with greater speed, efficiency, and impact. If such a company is hit by ransomware, it will likely have to respond, at least in part, to one or more external IT partners to recover.
It's still unclear why dental offices were targeted in the latest ransomware outbreak. There are many theories as to why, but nothing conclusive has been released so far.
The important thing is that you need to establish your culture around cyber. You need to train your staff so that they are aware of what to look out for. You need to budget for cyber security and perhaps even IT in general, so that you have the opportunity to defend yourself. You also need to talk to your business partners. Anyone who can access your network remotely could be considered a risk. You should audit these organizations, ask to see their internal cyber security policies, and certify their systems’ security so that you know they won’t be a potential threat to your company.
The spread of ransomware is a complex issue. Education is the best defense, along with a multi-layered approach to IT security, so you have a chance to catch any event before it has a wide-ranging impact. You should be able to look to industry resources for help, as well as IT . Just do something. Don’t wait until you fall victim to any ransomware. Get informed to make sure you don’t become one of the victims.
