Ransomware remains a huge threat to businesses

(Image credit: Carlos Amarillo / Shutterstock)

Cybercriminals have changed their tactics when launching ransomware attacks after finding that those targeting businesses offer a much higher return on investment than attacks against consumers, according to new research from Malwarebytes.

In the past year, business ransomware detections increased by 365 percent with Ryuk and Phobos increasing by 88 percent and 940 percent respectively. GandCrab and Rapid ransomware attacks on businesses also increased during the same period with Rapid up by 319 percent and GandCrab up by just five percent.

Malwarebytes' report shows how cybercriminals can reap “serious benefits” by ransoming organizations over individuals as consumers only have a few personal files which could be used for extortion or identity theft while businesses have much more sensitive data they would be willing to pay to regain access to.

In terms of countries most targeted by ransomware, the US took the top spot at 53 percent of all detections followed by Canada at 10 percent and the UK at nine percent. In the UK, Manchester had the most ransomware detections followed by Royal Kensington and Chelsea, Reading, Harrow and Leeds.

Ransomware resurgence

Although there was a respite in ransomware after the peak in 2017, Malwarebytes' report shows that the threat has come back in a big way as cybercriminals have switched from mass consumer campaigns to highly targeted attacks on businesses.

Director of Malwarebytes Labs, Adam Kujawa provided further insight on the recent resurgence of ransomware and how organizations can protect themselves from this growing threat in a blog post, saying:

“This year we have noticed ransomware making more headlines than ever before as a resurgence in ransomware turned its sights to large, ill-prepared public and private organizations with easy to exploit vulnerabilities such as cities, non-profits and educational institutions. Our critical infrastructure needs to adapt and arm themselves against these threats as they continue to be targets of cybercriminals, causing great distress to all the people who depend on public services and trust these entities to protect their personal information.” 

The firm's researchers predict that “manual” ransomware infections which leverage already-breached networks will increase in the future as attackers can disable security tools and launch ransomware of their own from within these networks. They also expect to see an increase in ransomware attacks that combine downloaded threats from a command and control (C&C) server with worm-like functionality that allows it to spread and Trojan elements that allow the ransomware to avoid detection on corporate networks.

There is good news for consumers however as Malwarebytes expects consumer-focused ransomware attacks to virtually disappear in favor of more lucrative attacks against organizations.

Ransomware isn't going away any time soon and the firm stressed that businesses need to continue to take the ransomware threat seriously or risk falling victim to an attack themselves.

Via Computer Weekly

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
A collage of Ellie and Joel in The Last of Us season 2
The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro Pascal's Joel, but the big moment I'm waiting for is still being held back
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 10 (game #1141)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 10 (game #372)