During the last 12 months, we have witnessed the rise of ransomware, with hundreds of thousands of devices infected, countless dollars spent to recover lost files, emergency investments to improve security measures and devastating reputational damage. These factors make ransomware one of the most dangerous cyberthreats to both businesses and individual users.

Alarmingly, this threat is growing. In fact, Symantec uncovered 101 new ransomware families in 2016 and detected 36 percent more infections than the previous year, according to the firm’s “Internet Security Threat Report.” In addition, antivirus tools picked up 846 ransomware infections per day at the beginning of the year, and that figure ballooned to 1,539 per day by the year’s end.

What’s Driving the Rise in Ransomware?

The two main contributors to the rapid growth of this threat are ransomware-as-a-service (RaaS), an emerging trend in which would-be cybercriminals with little to no technical expertise purchase tools and services created by malware developers to launch their own ransomware attacks, and the underground economy.

The Symantec report described two factions of cybercriminals: traditional fraudsters who seek to launch massive attacks through phishing campaigns without using exploit kits (EKs) and cybergangs that focus on more sophisticated attacks. Both subscribe to the concept of living off the land, or sharing certain pieces of code or features with other ransomware families. Bad Rabbit, for example, shares elements of its ransom note and propagation technique with NotPetya.

The most popular vehicle for ransomware is phishing, which relies on social engineering more than sophisticated cybercriminal techniques. Emails are distributed by bots and designed to look like a legitimate message from a trusted sender. Another common threat vector is exploit kits, which take advantage of vulnerabilities in outdated or unpatched software to redirect traffic to an exploit server kit hosted on a legitimate website.

The underground economy is typically associated with stolen credit card or other personal information, but the focus has largely shifted to commercial malware. Just like you go to the supermarket to buy your groceries, cybercriminals search the Dark Web for readily packaged, user-friendly ransomware and distributed denial-of-service (DDoS) kits. The increasing availability of these threats to actors who would otherwise lack the skills to carry out a cyberattack foreshadows tremendous consequences for the security community.

Who Is Most Vulnerable?

The truth is that everybody is at risk, but certain industries and companies are more attractive to fraudsters than others. Health care organizations such as hospitals, for example, are particularly vulnerable due to the high value of patient data. When fraudsters lock up historical medical data, health care professionals are unable to render crucial medical services and thus more likely to pay a ransom to recover their stolen data.

Government institutions are also top cybercriminal targets due to the high sensitivity of their data, especially data that relates to critical infrastructure, such as electricity, oil and gas, and transportation. Similarly, the value of legal data, much of which could incriminate or embarrass high-profile clients, puts law firms at risk. The most obvious target, however, is the financial sector, due to the millions of dollars in transactions that occur on banks’ networks daily and the growing popularity — and lagging security — of mobile banking apps.

Why Are Ransomware Attacks So Effective?

There are countless factors contributing to the ever-increasing popularity of ransomware among cybercriminals. Below are six of the most significant.

  1. Willingness to pay ransoms: Many people are willing to pay the ransom to recover their lost files, which makes ransomware a profitable business for fraudsters.
  2. Vulnerable software: Lack of patch management processes that identify critical systems and prioritize patches based on severity leaves software exposed to attacks.
  3. Failure to test disaster recovery and business continuity plans: In case of a cyber incident, it’s crucial to devise a plan to continue operations during the incident response process or, at least, re-establish service as soon as possible after a data breach. Failure to regularly review and test these plans puts organizations at increased risk.
  4. Lack of backup plans: If an organization’s backup and restore strategy is not aligned with its overall disaster recovery and business continuity plans or tested regularly, it may fail unexpectedly when a cyberattack hits.
  5. Lack of security awareness training: An educated employee is the security team’s best ally. By conducting thorough and regular security training, your company will be less exposed to cyberthreats. It doesn’t matter how strong your security infrastructure is if your users fail to follow best practices.
  6. The underground economy: The availability of cybercriminal tools in underground forums and marketplaces puts ransomware in the hands of nontechnical fraudsters who would otherwise lack the know-how to carry out attacks.

To combat this growing threat, users should leverage resources such as No More Ransom, which offers tools and expertise to help ransomware victims recover their files without paying their attackers. Individuals and businesses can also take advantage of the IBM X-Force Exchange for up-to-date threat intelligence, as well as IBM’s Ransomware Response Guide.

Download the Ransomware Response Guide from IBM INCIDENT RESPONSE SERVICES

More from Data Protection

How to craft a comprehensive data cleanliness policy

3 min read - Practicing good data hygiene is critical for today’s businesses. With everything from operational efficiency to cybersecurity readiness relying on the integrity of stored data, having confidence in your organization’s data cleanliness policy is essential.But what does this involve, and how can you ensure your data cleanliness policy checks the right boxes? Luckily, there are practical steps you can follow to ensure data accuracy while mitigating the security and compliance risks that come with poor data hygiene.Understanding the 6 dimensions of…

Third-party access: The overlooked risk to your data protection plan

3 min read - A recent IBM Cost of a Data Breach report reveals a startling statistic: Only 42% of companies discover breaches through their own security teams. This highlights a significant blind spot, especially when it comes to external partners and vendors. The financial stakes are steep. On average, a data breach affecting multiple environments costs a whopping $4.88 million. A major breach at a telecommunications provider in January 2023 served as a stark reminder of the risks associated with third-party relationships. In…

Communication platforms play a major role in data breach risks

4 min read - Every online activity or task brings at least some level of cybersecurity risk, but some have more risk than others. Kiteworks Sensitive Content Communications Report found that this is especially true when it comes to using communication tools.When it comes to cybersecurity, communicating means more than just talking to another person; it includes any activity where you are transferring data from one point online to another. Companies use a wide range of different types of tools to communicate, including email,…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today