This provides the best overall picture of ransomware activity, but the true number of attacks is far higher.
While some ransomware trends hardly changed over the last year, such as LockBit's continued dominance, ransomware criminals also challenged our fundamental assumptions on how ransomware gangs work, such as by exploiting zero-day vulnerabilities.
Through thec onsistenciess and evolutions over the last year, one fact remains clear: 2023 broke records with its total number of 4475 ransomware attacks, a 70% increase from 2022.
LockBit was responsible for a 22% of all ransomware attacks in 2023, over half as much as the next top five gangs combined.
Breaking 2023 ransomware attacks by sector reveals that 23% of all attacks were directed against the Services sector.
The USA was by far the most attacked country in 2023, with a whopping 45% of all ransomware attacks targeting the country.
We've sifted through the backlog of our 2023 ransomware reviews to find the most important stories and trends from the last year.
Here are five key takeaways from the ransomware world in 2023.
LockBit remained the most prolific ransomware gang throughout 2023, responsible for several high-profile attacks.
Despite 2023 being the worst ransomware year on record, law enforcement notched notable successes in taking down big-name groups, including the FBI's shutdown of the Hive ransomware group and the seizure of ALPHV's infrastructure.
Ransomware gangs, including Cl0p and ALPHV, aggressively exploited zero-day vulnerabilities to launch attacks on a unprecedented scale.
Critical infrastructure took a beating in 2023, with sectors such as logistics, manufacturing, healthcare, and education accounting for almost 30% of all ransomware attacks in 2023.
Besides an increased focus on exploiting zero-days, ransomware gangs introduced other new tactics in 2023 such as CL0P's use of torrents for distributing stolen data and innovative social engineering techniques by groups like Scattered Spider.
2023 was a whirlwind year for ransomware: Attacks spiked by 70%, law enforcement landed key victories, gangs pivoted to exploiting zero-day vulnerabilities, and much more.
Going into 2024 it's safe to say that the threat of ransomware looms large for all organizations-especially those with shrinking security budgets and overtaxed IT teams, organizations located in the US, critical infrastructure sectors like education.
Fighting off ransomware gangs requires a layered security strategy.
For the ultimate assurance of uptime -choose an EDR solution with ransomware rollback to undo changes and restore files so that productivity continues.
ThreatDown Bundles take a comprehensive approach to ransomware.
ThreatDown automatically quarantining LockBit ransomware.
For resource-constrained organizations, select ThreatDown bundles offer Managed Detection and Response services, providing expert monitoring and swift threat response to ransomware attacks-without the need for large in-house cybersecurity teams.
This Cyber News was published on www.malwarebytes.com. Publication date: Fri, 09 Feb 2024 16:13:05 +0000