Ransomware attacks double in Q2

Criminal groups change strategies to maximise impact.

  • Friday, 16th August 2024 Posted 1 year ago in by Phil Alsop

Dragos has revealed that ransomware incidents almost doubled in the second quarter of 2024 compared to the first quarter, indicating a significant resurgence of the ransomware threat.

The threat intelligence team at Dragos analysed ransomware data from various sources, including public reports and dark websites, to provide insights into the trends, patterns, and observations of ransomware activity targeting industrial sectors.

They found that the industrial sector remains a prime target for criminal groups due to the critical nature of its operations and the potentially high impact of disruptions. Ransomware's impact on industrial organisations has also increased, with ransomware groups focusing on high-impact operators to maximize their profits.

Some key developments this quarter include:

The number of ransomware incidents almost doubled in the second quarter compared to the first quarter, with 312 observed incidents globally.

Ransomware groups demonstrated significant resilience and adaptability, with some groups rebranding and others emerging with new tactics and techniques.

The manufacturing sector was the most affected, with 210 observed incidents, accounting for approximately 67 percent of all ransomware incidents.

The Lockbit group was behind most attacks against industrial organizations, with approximately 21 percent (or 66 incidents) of observed ransomware events.

Approximately 26 percent of global ransomware incidents (82 in total) impacted Europe.

Among the 86 ransomware groups known for targeting industrial organizations, 29 remained active in the second quarter compared to 22 ransomware groups in the first quarter of 2024. However, the second quarter saw a resurgence with several rebranded groups and new entrants in the ransomware landscape. Groups such as BlackSuit (formerly Royal ransomware) and RansomHub (previously Knight ransomware) have shown notable activity, leveraging sophisticated tactics and techniques to enhance their operations.

The team at Dragos also provided recommendations for industrial organisations to enhance their cybersecurity posture and mitigate the risk of ransomware attacks, such as implementing the five critical controls recommended by the SANS Institute.

Cato Networks joins Westcon-Comstor's AWS Marketplace

Posted 2 days ago by Sophie Milburn
Westcon-Comstor has added Cato Networks to its AWS Marketplace programme, expanding cloud procurement options for partners.

Atlassian introduces AI-powered 'Remix' for confluence

Posted 2 days ago by Sophie Milburn
Atlassian Corporation has introduced new AI features in Confluence that enable content to be transformed into formats such as charts, infographics,...
Cynomi has enhanced its platform with AI Insights and co-worker Agents, aimed at supporting cybersecurity service delivery for MSPs and MSSPs.

DXC Technology and ServiceNow forge AI partnership

Posted 2 days ago by Sophie Milburn
DXC Technology and ServiceNow have announced a collaboration to integrate AI into enterprise operations across global business functions.

Cloudera updates hybrid data and AI platform capabilities

Posted 2 days ago by Sophie Milburn
Cloudera has announced updates to its hybrid data and AI platform aimed at supporting enterprise data environments.
WatchGuard Technologies has launched a new endpoint security portfolio that introduces changes to traditional EDR licensing models.

SonicWall reveals 2026 Cyber Protect Report

Posted 2 days ago by Sophie Milburn
SonicWall's latest report identifies the 'Seven Deadly Sins of Cybersecurity', focusing on protection outcomes crucial for small and medium-sized...
Hammer AI Works is an end-to-end ecosystem designed to support AI adoption across organisations.