Ransomware attackers are targeting inside help

ID theft
(Image credit: Future)

Cybercriminals are increasingly turning towards employees to try and establish a foothold in a target company. 

A report from Hitachi ID surveying 100 large IT enterprises in North America found that there’s been a 17% rise in the number of employees who’d been offered money, in the form of cryptocurrency (bitcoin) to help ransomware operators breach the company network since November 2021.

Between December 7, 2021, and January 4, 2022, 65% of companies confirmed their employees had been approached. 

Downplaying insider threats

Most of the time, initial contact is done either by social media or email, but in some cases (27%), ransomware operators just call employees on the phone. 

Usually, targets wukk be offered less than $500,000 in Bitcoin for their efforts, but in some cases, these malicious actors made seven-figure proposals. 

Turning them down means very little, though, as, in half of the cases, the malicious actors do end up breaching the company, anyway. For Hitachi, that means that once a firm is perceived as a ransomware candidate, the method isn’t that important. 

But what makes this avenue particularly dangerous is the fact that insider threats are generally ignored, underrated, and not accounted for during cybersecurity planning. Polling IT pros on internal threats, just above a third (36%) said they were more concerned about external threats, while 3% were not concerned at all. 

Less than half of employees approached by cybercrooks reported it to the police. While a slim majority of executives (51%) feel moderately prepared to prevent a ransomware attack, just 4% consider themselves “most prepared”. At the same time, most decision-makers confirmed they rely mostly on perimeter defense (45%). Some (6%) exclusively use perimeter defense. 

The good news is that most companies (63%) have an insurance policy that covers ransomware attacks.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Concept art representing cybersecurity principles
How to combat exfiltration-based extortion attacks
A computer being guarded by cybersecurity.
The impact of the cyber insurance industry in resilience against ransomware
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
Hands typing on a keyboard surrounded by security icons
Infostealers on the rise: the latest concern for organizational defenses
ransomware avast
AI is helping hackers get access to systems quicker than ever before
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Bad news - businesses who pay ransomware attackers aren’t very likely to get their data back
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'