New data showcasing the state of ransomware shows that while organizations are likely getting better at recovery (and not paying the ransom), cybercriminals are shifting focus to ensure the make money.
It was inevitable; if the basic story of a ransomware attack was to stay static – environment is infected, data and systems are encrypted, victim needs to pay to decrypt – organizations eventually would simply find a less costly way to put their environment back into a known-good state via backups.
I reported last year how less organizations were paying the ransoms last year, which aligns with the data we’re seeing in the latest Quarterly Ransomware Report from ransomware response company Coveware.
According to their data, a few trends are occurring:
- Less Payments – only 41% of victims paid the ransom in comparison to 78% back in 2019
- More Backups – specifically immutable backups that can’t be deleted by threat actors, or at least that’s the theory based on the massive uptick in searches for the term immutable backup
- Higher Ransoms – The average ransom payment is now $404K, a 58% increase from the previous quarter and the highest ever reported by Coveware
- Larger Victims – The median target company size of a ransomware attack is now 275, up 10% from the previous quarter
In summary, ransomware gangs are having more difficulty collecting the ransom, so – in addition to adding and/or switching to extortion tactics – they are both increasing the average ransom and going after larger organizations that (in theory) have the ability to pay.
An organization of 275 employees is the median number – meaning it’s the middle number of all sizes of victim organizations. And with ransom amounts trending upward, it means that organizations need to be on their toes with every part of their security strategy that is focused on stopping phishing attacks – the number on initial attack vector last quarter, according to Coveware. This means you also need to include your users in the defense by enrolling them in continual Security Awareness Training designed to educate users on how to remain vigilant when at work when it comes to interacting with unexpected or unfamiliar email.