NCC Group on Wednesday published its threat for December 2024 and noted that the number of ransomware attacks observed at the end of the year is the highest of any month since it began tracking such activity in 2021.
See also: UK public sector: Ban on paying ransoms to ransomware groups?
The cybersecurity firm saw 574 ransomware attacks in December 2024, with a new threat group called FunkSec accounting for more than 100 attacks, or 18% of the total.

The group, whose members are likely inexperienced hackers, appears to be involved in both hacktivism and cybercrime.
FunkSec was the most active ransomware group in December 2024, followed by Cl0p, Akira, and RansomHub.
See also: Romanian man jailed for his involvement in NetWalker ransomware
According to NCC data, nearly a quarter of ransomware attacks observed last month targeted the industrial sector, followed by the consumer discretionary, IT, financial and healthcare sectors.

More than half of the ransomware attacks observed in December targeted organizations , followed by entities in Europe and Asia.
See also: Play Ransomware claims data theft from Krispy Kreme
“Since 2021, we have seen a decline in the number of ransomware attacks in December, likely due to the holiday season. This year, however, we have seen a break from tradition with the highest numbers recorded for December, highlighting the evolving and increasingly aggressive nature of ransomware threats,” the NCC said in report .
Source: securityweek
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
