There were more ransomware attacks last month than any other on record

Conceptual art of a computer system being hacked.
Due hacker ci hanno mostrato quanto sia semplice attaccare le infrastrutture critiche (Image credit: Getty Images)

Thanks to the Clop ransomware group and its exploit of a flaw in Fortra’s GoAnywhere MFT secure file transfer tool, March 2023 was a record-breaking month for ransomware attacks.

New figures from NCC Group claim there had been 459 ransomware attacks recorded in March 2023 - up 91% compared to February, and up 62% compared to the same month in the previous year. 

Records were broken mostly because Clop, allegedly a Russian threat actor, discovered a zero-day in GoAnywhere MFT, a secure file transfer tool from Fortra, which was in use by some major corporate names. By abusing the zero-day, now tracked as CVE-2023-0669, the hackers managed to steal data and deploy ransomware on dozens of organizations. 

Dethroning LockBit 3.0

After leaking data from its first victim, Clop said 130 organizations were compromised, which isn’t wide of the mark given NCC Group’s assessment of 129 recorded attacks. The researchers said this makes clop “the most active ransomware gang” for the first time in its operational history.

Clop even managed to dethrone the infamous LockBit 3.0, which conducted 97 attacks in the same timeframe. Other notable mentions for March 2023 include Royal ransomware, BlackCat (AKA ALPHV), Bianlian, Play, Blackbatsa, Stormous, Medusa, and Ransomhouse. 

“Industrials” - construction, engineering, transport services, commercial and professional services, and more - were the most popular targets, with 147 (32%) ransomware attacks. “Consumer Cyclicals” - construction suppliers, hotels, media, and more - were second-placed, NCC Group said. Other notable mentions include technology, healthcare, financials, and educational services.

NCC Group also mentions that ransomware operators don’t really care who they’re attacking. Every incident is opportunistic, rather than targeted, despite the fact that some industries suffered more than others. Almost half of all attacks (221) happened in North America, with Europe following in second-place with 126 incidents. Asia rounds off the top three with 59 attacks.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
More reports claim 2024 was the worst year for ransomware attacks yet
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
Cl0p ransomware group says it was behind Cleo attacks
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Less than half of ransomware incidents end in payment - but you should still be on your guard
Hands typing on a keyboard surrounded by security icons
35 years on: The history and evolution of ransomware
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough
Brad Pitt looks over his right shoulder with 'F1' written behind him
Apple Original Films will take you behind-the-scenes of a racing cockpit in this new thrilling F1 movie trailer
AI writer
Coding AI tells developer to write it himself
Reacher looking down at another character from the Prime Video TV series Reacher
Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavyweight
Finger Presses Orange Button Domain Name Registration on Black Keyboard Background. Closeup View
I visited the world’s first registered .com domain – and you won’t believe what it’s offering today
Image showing detail of the Leica D-Lux 8
Still can't get a Fujifilm X100VI? This premium Leica compact costs less, and it's in stock