During the last 12 months, we have witnessed the rise of ransomware, with hundreds of thousands of devices infected, countless dollars spent to recover lost files, emergency investments to improve security measures and devastating reputational damage. These factors make ransomware one of the most dangerous cyberthreats to both businesses and individual users.

Alarmingly, this threat is growing. In fact, Symantec uncovered 101 new ransomware families in 2016 and detected 36 percent more infections than the previous year, according to the firm’s “Internet Security Threat Report.” In addition, antivirus tools picked up 846 ransomware infections per day at the beginning of the year, and that figure ballooned to 1,539 per day by the year’s end.

What’s Driving the Rise in Ransomware?

The two main contributors to the rapid growth of this threat are ransomware-as-a-service (RaaS), an emerging trend in which would-be cybercriminals with little to no technical expertise purchase tools and services created by malware developers to launch their own ransomware attacks, and the underground economy.

The Symantec report described two factions of cybercriminals: traditional fraudsters who seek to launch massive attacks through phishing campaigns without using exploit kits (EKs) and cybergangs that focus on more sophisticated attacks. Both subscribe to the concept of living off the land, or sharing certain pieces of code or features with other ransomware families. Bad Rabbit, for example, shares elements of its ransom note and propagation technique with NotPetya.

The most popular vehicle for ransomware is phishing, which relies on social engineering more than sophisticated cybercriminal techniques. Emails are distributed by bots and designed to look like a legitimate message from a trusted sender. Another common threat vector is exploit kits, which take advantage of vulnerabilities in outdated or unpatched software to redirect traffic to an exploit server kit hosted on a legitimate website.

The underground economy is typically associated with stolen credit card or other personal information, but the focus has largely shifted to commercial malware. Just like you go to the supermarket to buy your groceries, cybercriminals search the Dark Web for readily packaged, user-friendly ransomware and distributed denial-of-service (DDoS) kits. The increasing availability of these threats to actors who would otherwise lack the skills to carry out a cyberattack foreshadows tremendous consequences for the security community.

Who Is Most Vulnerable?

The truth is that everybody is at risk, but certain industries and companies are more attractive to fraudsters than others. Health care organizations such as hospitals, for example, are particularly vulnerable due to the high value of patient data. When fraudsters lock up historical medical data, health care professionals are unable to render crucial medical services and thus more likely to pay a ransom to recover their stolen data.

Government institutions are also top cybercriminal targets due to the high sensitivity of their data, especially data that relates to critical infrastructure, such as electricity, oil and gas, and transportation. Similarly, the value of legal data, much of which could incriminate or embarrass high-profile clients, puts law firms at risk. The most obvious target, however, is the financial sector, due to the millions of dollars in transactions that occur on banks’ networks daily and the growing popularity — and lagging security — of mobile banking apps.

Why Are Ransomware Attacks So Effective?

There are countless factors contributing to the ever-increasing popularity of ransomware among cybercriminals. Below are six of the most significant.

  1. Willingness to pay ransoms: Many people are willing to pay the ransom to recover their lost files, which makes ransomware a profitable business for fraudsters.
  2. Vulnerable software: Lack of patch management processes that identify critical systems and prioritize patches based on severity leaves software exposed to attacks.
  3. Failure to test disaster recovery and business continuity plans: In case of a cyber incident, it’s crucial to devise a plan to continue operations during the incident response process or, at least, re-establish service as soon as possible after a data breach. Failure to regularly review and test these plans puts organizations at increased risk.
  4. Lack of backup plans: If an organization’s backup and restore strategy is not aligned with its overall disaster recovery and business continuity plans or tested regularly, it may fail unexpectedly when a cyberattack hits.
  5. Lack of security awareness training: An educated employee is the security team’s best ally. By conducting thorough and regular security training, your company will be less exposed to cyberthreats. It doesn’t matter how strong your security infrastructure is if your users fail to follow best practices.
  6. The underground economy: The availability of cybercriminal tools in underground forums and marketplaces puts ransomware in the hands of nontechnical fraudsters who would otherwise lack the know-how to carry out attacks.

To combat this growing threat, users should leverage resources such as No More Ransom, which offers tools and expertise to help ransomware victims recover their files without paying their attackers. Individuals and businesses can also take advantage of the IBM X-Force Exchange for up-to-date threat intelligence, as well as IBM’s Ransomware Response Guide.

Download the Ransomware Response Guide from IBM INCIDENT RESPONSE SERVICES

More from Data Protection

Cybersecurity 101: What is Attack Surface Management?

There were over 4,100 publicly disclosed data breaches in 2022, exposing about 22 billion records. Criminals can use stolen data for identity theft, financial fraud or to launch ransomware attacks. While these threats loom large on the horizon, attack surface management (ASM) seeks to combat them. ASM is a cybersecurity approach that continuously monitors an organization’s IT infrastructure to identify and remediate potential points of attack. Here’s how it can give your organization an edge. Understanding Attack Surface Management Here…

Six Ways to Secure Your Organization on a Smaller Budget

My LinkedIn feed has been filled with connections announcing they have been laid off and are looking for work. While it seems that no industry has been spared from uncertainty, my feed suggests tech has been hit the hardest. Headlines confirm my anecdotal experience. Many companies must now protect their systems from more sophisticated threats with fewer resources — both human and technical. Cobalt’s 2022 The State of Pentesting Report found that 90% of short-staffed teams are struggling to monitor…

The Importance of Modern-Day Data Security Platforms

Data is the backbone of businesses and companies everywhere. Data can range from intellectual property to critical business plans to personal health information or even money itself. At the end of the day, businesses are looking to grow revenue, innovate, and operationalize but to do that, they must ensure that they leverage their data first because of how important and valuable it is to their organization. No matter the industry, the need to protect sensitive and personal data should be…

Meeting Today’s Complex Data Privacy Challenges

Pop quiz: Who is responsible for compliance and data privacy in an organization? Is it a) the security department, b) the IT department, c) the legal department, d) the compliance group or e) all of the above? If you answered "all of the above," you are well-versed in the complex world of compliance and data privacy! While compliance is a complex topic, the patchwork of regulations imposed by countries, regions, states and industries further compounds it. This complexity has turned…