The FBI 's Cybercrime Division issued a public statement yesterday regarding ransomware attacks that are causing major damage to private and public organizations in the US. 
“Since early 2018, the frequency of ransomware campaigns has decreased, but losses from attacks have increased significantly, according to complaints received by the FBI,” the agency says.
He also said that in the United States, the main target of ransomware gangs is local governments, but attacks are also being made on healthcare services, industries and the transportation sector.
Attackers find various ways to infect victims' systems. They start with phishing campaigns, exploit vulnerabilities , etc.
Do not pay the ransom!
The FBI recommends that all users, individuals or businesses, not pay the ransom to the hackers but report the incident to the authorities as soon as possible.
Experts will advise you appropriately on how to proceed.
“Regardless of whether you or your organization has decided to pay the ransom, the FBI urges you to report ransomware incidents to law enforcement,” the FBI says.
“This gives researchers the critical information they need to identify ransomware attackers, apprehend them, and prevent future attacks.”.
In addition to reporting the incident, timing is also important. As we said above, the attack should be reported as soon as possible.
The FBI recommends the following practices for organizations to prevent a ransomware attack:
- Create backups
- Train employees
- Fix bugs in all systems
- Enable automatic updating to combat malware
- Use best practices for using RDP
- Perform continuous software checks
- Separate networks for different members of the organization
Targeting US hospitals and schools
Hospitals in the US are a frequent target of hackers. This week alone, three hospitals in West Alabama (DCH Regional Medical Center, Northport Medical Center, and Fayette Medical Center) were attacked . The ransomware attacks affected IT systems and allowed only limited access .
All three hospitals said they had to close and were only taking on emergencies.
According to various reports, US schools have also been targeted by hackers. Since the beginning of 2019, many schools have fallen victim to ransomware attacks
Beyond schools, over 60 attacks have also occurred at colleges and universities.
Emsisoft researchers claim that from the first to the third quarter of 2019, 491 ransomware attacks were carried out on healthcare services and another 68 on state, prefectural and municipal entities
Legislation to address ransomware attacks
In response to all these attacks, the Senate passed the “DHS Cyber Hunt and Incident Response Teams Act” last week. This is a law that allows the Department of Homeland Security (DHS) to deploy teams to respond to ransomware and general hacking incidents, in private and public agencies.
These teams of experts will advise and provide technical support to strengthen IT systems against ransomware and other attacks.
The FBI and law enforcement will also be available to victims of ransomware attacks.
