HomeSecurityRansomware attacks: What data do hackers really want?

Ransomware attacks: What data do hackers really want?

Analysts report that in ransomware attacks, hackers really want some specific data! What is it?

Ransomware is one of the most pressing and insidious threats facing organizations. These attacks have caused billions in damages across nearly every industry and around the world.

See also: ech0raix ransomware targets QNAP NAS devices again

ransomware data

Data theft and extortion has become a common – and unfortunately effective – part of ransomware attacks, where in addition to encrypting data and demanding a ransom payment for the decryption key, gangs steal information and threaten to publish it if the ransom is not paid.

These so-called double extortion attacks have become an effective tool in the arsenal of ransomware gangs, who leverage them to force victims to pay, even in cases where data could be restored from offline backups, because the threat of publishing sensitive information is so effective.

See also: QNAP "thoroughly investigating" new DeadBolt ransomware attacks

Any stolen data is potentially useful to ransomware gangs, but according to an analysis by researchers at cybersecurity firm Rapid7 of 161 ransomware incidents in which data was released, some data is considered more valuable than others.

According to the report, financial services is the sector most likely to have customer data exposed, with 82% of incidents involving ransomware gangs accessing and threatening to make this data public. The theft and publication of sensitive customer information would undermine consumer trust in financial services organizations: while the breach would initially be quite damaging, some business leaders may find it worthwhile to pay the ransom to avoid further damage caused by data breaches.

The second most leaked file type in ransomware attacks against financial services companies, comprising 59% of victim disclosures, is employee personally identifiable information (PII) and human resources-related data.

By targeting this information, attackers could undermine the trust that staff have in their employers, particularly if they believe that their personal information could be published and accessible to cybercriminals, who could use it for fraud and other cybercrime.

Another industry that is commonly targeted by ransomware gangs is healthcare and pharmaceuticals.

In this scenario, internal financial and accounting data is the data most frequently exposed in healthcare ransomware attacks, (71% of the incidents examined). Customer and patient information is most commonly exposed in ransomware attacks – researchers suggest this occurs in 58% of incidents.

ransomware data

Health data is extremely personal and something most people don’t want exposed online. Criminals know this fact and use it to pressure healthcare providers into paying ransoms.

The combination of the sensitive nature of this information, as well as the fact that hospitals and health services are vital and must operate, means that healthcare remains a frequent target for hackers.

Ransomware continues to pose a threat to organizations of all kinds, and researchers outline steps organizations can take to mitigate the threat.

See also: Africa's largest supermarket chain Shoprite hit by ransomware

According to Rapid7, these steps include regularly backing up data and storing it on offline systems, encrypting sensitive information , and implementing network segmentation.

Security measures such as using multi-factor authentication across the network and being able to detect potentially suspicious activity before damage is done can help protect organizations from ransomware and other cyberattacks.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS