Law enforcement scored some big recent successes against ransomware groups: the FBI significantly disrupted ALPHV/BlackCat’s infrastructure at the end of December, just months after Ragnar Locker watched as Europol did the same across Europe. However, that doesnโt mean the ransomware threat is over. Far from it, as two new pieces of analysis reveal.
First with the statistics is Comparitech, specifically its Map of Worldwide Ransomware Attacks. This shows that the number of data records stolen by ransomware groups increased dramatically between 2022 and 2023.
“Over 102.4 million records were breached via ransomware attacks on tech companies in 2023 โ a staggering 2,300 per cent increase on 2022โs figure of 4.26 million,โ Rebecca Moody, Head of Data Research at Comparitech, says. โItโs also the highest number recorded across any industry since we began tracking confirmed ransomware attacks in 2018.โ
That said, the MOVEit attack accounted for more than 90 million of those records. Exploiting one vulnerability that left numerous organisations unprepared opened the door to multiple large enterprises across almost every industry sector.
The more data on the table, the higher the total ransom payday and the keener victims are to pay a negotiated price.
Average ransomware demand in 2023
What was the average ransom demand in 2023, I hear you ask? Let me answer by saying that, according to the Comparitech numbers, it was a hefty $3 million across 2022. In 2023, that rose, although rocketed might be a better word, to $27.4 million.
This is based on ransoms that were initially demanded and known about. However, those figures are likely to be magnitudes higher than those paid after negotiations and flat refusals are factored in.
Meanwhile, NCC Groupโs Threat Intelligence team has reported today that December ransomware attacks fell by 12% compared to November, which is the good news. The bad news is that it represented a 45% increase from December 2022. Year on year, NCC saw an 84% increase in 2023 attacks compared to the year before.
New ransomware attackers?
Perhaps the most interesting detail to emerge from this analysis is the part that new ransomware groups played last year.
It should be pointed out that new groups donโt necessarily mean new players. The data suggests that the Hunters group, for example, which ended the year accounting for 6% of attacks according to NCC, is thought to be the rebranded Hive gang that was disrupted by law enforcement earlier in the year.
Another group, WereWolves, also featured in the top ten list but is thought to be a LockBit affiliate.
โClosing 2023 with over 4,000 global ransomware attacks is reflective of the sharp rise of cyber-criminal activity compared with 2022,โ says Matt Hull, Global Head of Threat Intelligence at NCC Group.ย
โOver the year weโve seen the development of sophisticated attack methods, allowing both new and old threat groups to exploit vulnerabilities of victims across a range of sectors and in particular, present threats to healthcare where weโve seen notable successful attacks over the last 12 months with vast volumes of data being compromised.โ
With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.