Ransomware Payments Decline While Data Exfiltration Payments Are On The Rise



ransomware-kav-580x438The latest data from Coveware shows a slowing of attack efficacy, a decrease in ransom payments being made, and a shift in initial access tactics.

According to Coveware’s Q2 2024 Ransomware Quarterly Report, we see a few interesting trends:

  • Threat actors are no longer being “brand loyal” to a particular ransomware brand, and appear to be running their operations in a more unaffiliated manner. This means organizations need to focus on common threat actions rather than specific attack patterns of a given group.
  • The percentage of organizations paying the ransomware payment has dwindled from 85% of victim organizations in Q1 of 2019 to just 36% last quarter
  • Average ransomware payments continue to increase, likely in response to less organizations paying the ransom

A new data point brought to light this quarter is the data exfiltration only (DXF) payment trend, which is relatively flat despite fluctuating between 53% in Q1 of 2022 when tracking began, down to a low of 23% in Q1 of this year.

The decline of ransom payments based on encrypting data and the rise of DXF payments is an indicator of what to expect with ransomware attacks. The only way to stop these attacks is through great detection and mitigation – something achieved with users who enroll in continual security awareness training to stop phishing-based attacks.

I doubt we’ll see the use of XSS end anytime soon, but do expect to see improved uses of it in ways that users will fall for, making it imperative that they be taught now instead of after a successful attack.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.


Free Ransomware Simulator Tool

Threat actors are constantly coming out with new strains to evade detection. Is your network effective in blocking all of them when employees fall for social engineering attacks?

KnowBe4’s "RanSim" gives you a quick look at the effectiveness of your existing network protection. RanSim will simulate 24 ransomware infection scenarios and 1 cryptomining infection scenario and show you if a workstation is vulnerable.

RansIm-Monitor3Here's how it works:

  • 100% harmless simulation of real ransomware and cryptomining infections
  • Does not use any of your own files
  • Tests 25 types of infection scenarios
  • Just download the install and run it 
  • Results in a few minutes!

Get RanSim!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/ransomware-simulator



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews