Powered by MOMENTUM MEDIA
cyber daily logo

Breaking news and updates daily. Subscribe to our Newsletter

Breaking news and updates daily. Subscribe to our Newsletter X facebook linkedin Instagram Instagram

The weekly ransomware report, Thursday, 25 January

LockBit outdoes itself, with 20 victims claimed in the last seven days, as the overall number of ransomware attacks skyrockets.

user icon David Hollingworth
Thu, 25 Jan 2024
The weekly ransomware report, Thursday, 25 January
expand image

In what we sincerely hope is not a trend likely to continue, ransomware attacks have increased by 89 per cent above last week, with 89 ransomware attacks reported by threat-tracking service FalconFeeds.io.

What’s fascinating is if we zoom out a little, the current 30-day period is down 40 per cent on the previous one, with only 239 attacks observed. The same goes for the last three months, though the downward trend is slighter, at only 8 per cent down on the previous three months.

Regardless, this week has seen a sharp increase, and once again, the US has borne the brunt, with 50 ransomware attacks impacting entities in the US – 56 per cent of the total. France was the second-most impacted nation, with eight attacks; the United Kingdom suffered seven, with Canada ranking next with four attacks, and Mexico rounding out the top five with two.

============
============

One Australian company appears to have fallen victim, an online cycling retailer that the 8Base ransomware gang claiming the scalp. We’re still investigating this one, so watch this space.

The manufacturing sector was hit hardest this week, with eight companies hit by attacks. Six law firms fell victim to ransomware attacks globally, followed by five entities in the financial services sector. The non-profits and civil engineering sectors each tallied four victims. It’s a very different selection of victim industries this week, a perfect example of how opportunistic ransomware operators are.

Once again, LockBit was the most active group over the last seven days, with its ransomware-as-a-service operation targeting 20 discrete organisations – 22 per cent of the 89 incidents reported, which is actually down on last week’s figure, when the gang was responsible for 26 per cent of attacks.

Black Basta bumps out 8Base this week for number two, with 12 attacks compared to 8Base’s eight, and ALPHV and Hunters International both claimed seven victims. That figure is significantly higher than even the second-most prolific gangs last week, an indicator of just how active ransomware operators have been.

The total yearly figure now rises from 3,478 total ransomware findings last week to 3,607 this week, and no new groups have popped up – we’re still tracking 56 operators.

And yes, we are a day early with these figures, which does mean a slight statistical overlap with last week’s reporting, but we still feel the figures tell quite a story. Cyber Daily, along with the rest of Momentum Media, will be taking the day off for Australia Day.

See you next Friday.

Just the numbers

Eighty-nine attacks in the last seven days, up 56 per cent from last week

Threat actors

  • LockBit – 20 ransomware attacks, 22 per cent of total
  • Black Basta – 12
  • 8Base – 8
  • ALPHV – 7
  • Hunters International – 7

Countries impacted

  • USA – 50 organisations targeted
  • France – 8
  • United Kingdom – 7
  • Canada – 4
  • Mexico – 2

Industries

  • Manufacturing – 8, which is 9 per cent of the total
  • Law firms – 6
  • Financial services – 5
  • Non-profits and other social organisations – 4
  • Civil engineering – 4

A total of 3,607 ransomware findings so far this year.

Fifty-six threat actors monitored so far this year.

David Hollingworth

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.

cd intro podcast

Introducing Cyber Daily, the new name for Cyber Security Connect

Click here to learn all about it
newsletter
cyber daily subscribe
Be the first to hear the latest developments in the cyber industry.