A third of businesses have fallen victim to a ransomware attack or data breach

security
(Image credit: Shutterstock)

New research has found ransomware attacks have affected more than a third of businesses worldwide over the last 12 months.

A report from IDC found that companies that fall victim once, are highly likely to fall victim again, with businesses in the manufacturing and finance industries having the highest ransomware incident rates. At the other end of the spectrum are those in the transportation, communications, and utilities/media industries.

Despite law enforcement agencies and cybersecurity experts warning against paying the ransom, as it only fuels the greed and makes ransomware operators more dangerous, many organizations still decide to pay up. In fact, IDC says only 13% of firms reported being attacked and not paying up.

The average ransom payment was almost a quarter of a million dollars, IDC says, adding that a few bigger ransom payments (north of $1 million ) skewed the average. 

When it comes to defending against ransomware, American companies seem to be doing a somewhat better job than the rest of the world, as the incident rate in the US was 7%, compared to the global average of 37%.

Drilling deeper into how different organizations respond to ransomware, IDC found that many review and certify security and data protection/recovery practices with partners and suppliers. Some periodically stress-test their cyber-response procedures, while others tend to share as much info with threat intelligence agencies and government firms as possible. 

Ransomware evolves

Finally, IDC found that companies further along their digital transformation road were less likely to fall victim to a ransomware attack. 

"As the greed of cyber miscreants has been fed, ransomware has evolved in sophistication, moving laterally, elevating privileges, actively evading detection, exfiltrating data, and leveraging multifaceted extortion,” said Frank Dickson, Program Vice President, Cybersecurity Products at IDC. “Welcome to digital transformation's dark side!"

As long as they can expect a payment, ransomware operators don’t really care much about the target’s size. Businesses of all sizes, from SMBs to large enterprises, are equally interesting to them, and with employees being at the front lines (and usually the weakest link in the security chain), organizations need to ensure proper cybersecurity and awareness training.

As Dickson said, ransomware has evolved. At the start, the premise was simple: encrypt all of the data on the target network and demand payment in cryptocurrencies in exchange for the decryption key. Once businesses started deploying backups instead of paying up, ransomware operators began to steal data as well, and threaten to release it online should the ransom not be paid.

Nowadays, many operators throw DDoS into the mix, threatening to paralyze a company's services until their demands are met.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Bad news - businesses who pay ransomware attackers aren’t very likely to get their data back
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Less than half of ransomware incidents end in payment - but you should still be on your guard
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
More reports claim 2024 was the worst year for ransomware attacks yet
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
A computer being guarded by cybersecurity.
The impact of the cyber insurance industry in resilience against ransomware
Hands typing on a keyboard surrounded by security icons
35 years on: The history and evolution of ransomware
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand