2023 was a very good year for ransomware, even though law enforcement around the world managed to “hit” many of them.

Palo Alto Networks’ Unit 42 team has seen a 49% increase in victims reporting to ransomware gang data leak sites. In total, 4,000 posts were found on these sites by different hacking groups. The researchers attributed the increase to the huge impact of attacks exploiting zero-day vulnerabilities. For example, last year, a vulnerability in the MOVEit Transfer used by many companies was particularly exploited. The US government has linked the exploitation of the vulnerability to the ransomware gang CL0P. According to CISA, the attacks compromised more than 3,000 organizations based in the US and 8,000 worldwide.
See also: Ransomware Survey: 94% of Companies Would Pay
Nearly half of the ransomware victims Palo Alto Networks identified were in the U.S. The industries most affected are construction, professional and legal services, and technology .
Researchers identified 25 new data breach sites last year that offered ransomware as a service. However, at least five appear to have been shut down.
Additionally, it is worth noting that some ransomware groups have been more active than others and have attracted the attention of law enforcement, who in some cases have managed to destroy the hackers’ infrastructure. For example, authorities managed to take down the Hive and Ragnar Locker in 2023. Hive extorted $100 million in ransom payments, according to the US Department of Justice, and caused major disruptions. Ragnar Locker had attacked critical infrastructure, including a Portuguese national airline and an Israeli hospital.
See also: Interpol: Identified 1300 IP addresses related to phishing and ransomware attacks

The researchers are also following up on findings from Chainalysis, a blockchain data firm that recently published its own report on ransomware trends. While the firm found a decline in the overall value of illicit crypto activity in 2023, ransomware revenue increased. Chainalysis suggested that “ransomware attackers have adapted to cybersecurityimprovementsorganizations ’.”
Protection measures
- Use of reliable and advanced antivirus software
- Create backups, especially for essential files
- Regularly update systems, applications and antivirus programs
- Training employeesto recognize suspicious emails
- Using filters to automatically block suspicious emails
- Use of firewalls and VPNs
- Network segmentation
The above security practices can protect users and businesses to a certain extent from various cyber attacks. However, in the event that someone falls victim to a ransomware attack, the key point is one. Do not pay the ransom and contact the competent authorities. The attackers are not people anyone can trust. Even if the ransom is paid, it is not guaranteed that the criminals will not leak the stolen data or that they will give the victim the decryption key.
See also: White Phoenix: New online version of ransomware decryption tool
Ransomware attacks are very popular precisely because they offer large sums of money to criminals. If victims stop paying the ransom, then only we can hope for a decrease in these attacks!
source: www.theverge.com
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
