Five ransomware groups were responsible for 40% of all cyberattacks in the third quarter of 2024, according to research by Corvus Insurance .

The insurance company's findings showed that websites data breach. This represents an increase of 0.7% from the second quarter of the year (1,248 victims).
Of the ransomware attacks, 40% have been attributed to the following five groups:
- RansomHub
- PLAY
- LockBit 3.0
- MEOW
- Hunters International
However, more and more gangs are appearing on the threat landscape, according to the research. Currently, there are 59 active groups.
See also: BianLian ransomware now focuses on data theft
The report states that law enforcement operations, such as Operation Cronos that affected LockBit, can transform the ransomware ecosystem.
The RansomHub team quickly filled the void left by LockBit and has targeted more than 290 individuals/organizations, across various sectors in 2024. In October, Symantec research also noted that RansomHub is now the leading ransomware operation in terms of successful attacks.
Corvus said that LockBit 3.0 activity has declined sharply. In the second quarter, there were 208 victims, while in the third quarter, only 91.
See also: Akira Ransomware: 30 victims in one day on leak site
The company also noted that ransomware groups are increasingly targeting VPNs. Cybercriminals are exploiting vulnerabilities in VPNs and weak passwords to gain initial access and deploy the malware.
Corvus explained that the use of common usernames like “admin” or “user” and the lack of multi-factor authentication (MFA) make accounts vulnerable to automated brute-force attacks. This allows malicious actors to gain access to the network with minimal effort.
“Attackers are looking for the path of least resistance to launch an attack, and in Q3, that entry point was the VPN,” said Jason Rebholz, CISO at Corvus.
See also: New 'Helldown' Ransomware Targets VMware and Linux Systems

Ransomware Protection
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using solutions email security for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Stay up to date on the latest ransomware trends and tactics used by attackers
Source:www.infosecurity-magazine.com
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
