HomeYoutubeReduction in ransomware attacks in April (+ most significant incidents)

Reduction in ransomware attacks in April (+ most significant incidents)

Ransomware attacks saw a significant drop in April , according to new analysis from Comparitech . The company largely attributes this development to operational issues at the criminal group RansomHub , which appear to have affected its activity.

Comparitech, which specializes in educating consumers about cybersecurity issues, recorded a total of 479 ransomware incidents during April. This is a significant decrease compared to previous months. There were 530 attacks recorded in January, 973 in February and 713 in March.

It is worth noting that of the 479 recorded incidents in April, only 39 were confirmed by the targets of the attacks themselves, either through press releases or data breach notifications.

See also: Ukrainian extradited to the US for Nefilim ransomware attacks

ransomware attacks

According to Comparitech, a key factor in the decline appears to have been the sudden shutdown of the RansomHub group, which reportedly ceased all activity on March 31.This was also confirmed by an analysis by cybersecurity firm Group-IB, which reported on April 30 that RansomHub had suffered a major outage on the last day of March.

Shortly afterwards, the administrator of the Qilin, known by the pseudonym “Haise”, appeared on the RAMP platform, advertising a new ransomware variant and DDoS extortion features. Group-IB estimates that several members or associates of RansomHub may have transferred their activities to Qilin.

Comparitech recorded a significant increase in Qilin gang attacks in April, which rose to 67 from 45 in March, which reinforces the hypothesis of a shift in activities.

At the same time, the RansomHub data breach website remained dormant in April, with no new victims posted.

Notably, according to a report by NCC Group, RansomHub was one of the most active ransomware gangs in March, with 62 attacks in that month alone. According to Comparitech data, Qilin took first place as the most prolific ransomware criminal organization for April, followed by Akira (62 attacks), Play (50), Lynx (32) and NightSpire (22).

See also: Hitachi Vantara: Problems due to Akira ransomware attack

Major Ransomware Attacks in April

April saw several ransomware incidents that attracted public attention due to the size or nature of their targets. Among them was the attack on British retailer Marks & Spencer, which was allegedly linked to the notorious cybercrime group Scattered Spider.

Another serious attack was recorded on German recycling company Eu-Rec GmbH, which was targeted by the SafePay. The effects were so severe that they allegedly contributed to the company's financial collapse, leading it to file for bankruptcy.

Equally concerning was the Rhysida attack on the Oregon Department of Environmental Quality (DEQ). While the agency refused to pay the $2.7 million ransom, there was no clear response to the cybercriminals’ claims that they had extracted over 2.5 terabytes of data from its systems.

Reduction in ransomware attacks in April (+ most significant incidents)

Overall, ransomware attacks recorded in April had a wide range of targets. Specifically, 24 attacks targeted government agencies, 22 targeted healthcare organizations , and 14 targeted educational institutions. The remainder – 425 incidents – were attributed to various business activities, according to the Comparitech report.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Interlock ransomware behind DaVita attack

Ransomware protection

  • Implement multi-factor authentication (MFA) for all user accounts
  • Enable firewall on all devices connected to the network
  • Encryption of sensitive data
  • Updating devices and systems with the latest security patches
  • Conducting regular security audits and penetration testing
  • Using strong, unique passwords 
  • Limiting user access to only necessary systems and information
  • Use solutions email security for additional protection against phishing attacks
  • Recovery plan for quick recovery

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS