HomeSecurityRansomware: Changes tactics to put more pressure on victims

Ransomware: Changes tactics to put more pressure on victims

Ransomware didn’t just grow in the US in 2023, it evolved, with the frequency of ransomware incidents increasing by 64% from the previous year, according to At-Bay. This was largely driven by an explosion in “indirect” ransomware incidents, which increased by more than 415% in 2023 compared to 2022. Remote access tools accounted for 58% of ransomware attacks. Double-extortion ransomware attacks – those that use both data encryption and extortion– also increased by 51% in 2023, demonstrating that threat actors have changed their tactics to pressure more victims into paying ransom.

See also: Phorpiex botnet sent millions of emails distributing LockBit Black ransomware

ransomware tactics

The frequency of ransomware attacks is increasing

The frequency of ransomware attacks as a whole increased by 64%, mainly due to the explosion of “indirect” ransomware incidents, the frequency of which increased by 415%. The frequency of direct ransomware incidents increased by 17% in 2023. Attackers continued to exploit remote access technology, with 58% of direct ransomware incidents attributed to remote access vulnerabilities. In addition, attackers shifted their focus from RDP to targeting self-managed VPNs, which accounted for 63% of remote access ransomware incidents in 2023.

Organizations using self-managed VPNs from Cisco and Citrix were 11 times more likely to be victims of a direct ransomware attack than those using a cloud or no VPN at all. Unlike frequency, the severity of ransomware attacks decreased across At-Bay’s portfolio.

See also: INC Ransom: Is the ransomware source code being sold?

Likely due to more businesses successfully restoring from backups after an attack, the average cost of an immediate ransomware attack fell by 24% in 2023, to $370,000. The research found that companies that failed to restore data from backups were 3 times more likely to pay ransom than those that couldn’t. Business interruption costs were also lower.

Ransomware: Changes tactics to put more pressure on victims

The average ransom demand from attackers exceeded $1.26 million in 2023, although the average amount paid was $282,000, 77% lower than the initial average demand. The ransom payment was avoided in more than half (54%) of the incidents At-Bay saw.

A combination of data encryption and extortion was the most common direct ransomware tactic. This dual-extortion tactic was used in 51% of ransomware incidents and was also the most costly for businesses.

See also: Ascension: Systems are restored after ransomware

What protection strategies do experts recommend?

Experts recommend regularly updating and upgrading all software and systems a business uses to protect against ransomware. Updates often include security patches that can prevent ransomware attacks. Employee training is also critical. Employees should be aware of the latest methods used by attackers and know how to recognize suspicious emails and links. Creating and maintaining regular backups is essential. Backups should be stored in secure and isolated locations so that they are available in the event of an attack. Finally, using strong and unique passwords for all business systems and accounts is a key strategy. In addition, implementing multi-factor authentication (MFA) offers an additional layer of protection.

Source: helpnetsecurity

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS