LockBit 3.0’s eight-month streak as the leading ransomware threat actor has come to an end, with the group now accounting for fewer than half of the attacks it was responsible for in March.
This comes on the back of a significant downturn in ransomware numbers, with a 15% decrease in attacks compared to the previous month, according to NCC Group’s April Threat Pulse report.
The total number of attacks dropped from 421 to 356, continuing a trend observed since 2023. However, despite this monthly decline, year-on-year comparisons show a 1% increase in attacks, rising from 352 in April 2023 to 356 in April 2024. This slight uptick is attributed in part to the takedown of LockBit 3.0 earlier in the year.
“The year-on-year rise in ransomware attacks is likely linked to the explosion of AI, revolutionising how threat actors can operate. However, it’s not all doom and gloom. We should be adopting AI to fight against these threats. But we need to act quickly so we don’t end up playing catch up to these threat actors,” said Matt Hull, global head of threat intelligence at NCC Group.
LockBit 3.0, which had held the title of the most prominent threat actor for eight consecutive months, experienced a dramatic decline in April, with a staggering 60% drop in attacks following its takedown in February. This shift marked a significant shake-up in the ransomware landscape, paving the way for new players to emerge.
“Despite the successful takedowns of major groups like LockBit, now is not the time to slow down efforts to protect against cyber threats,” continued Hull.
“The continuous rise of new and equally menacing threat actors, alongside constant development of AI and emerging technologies, poses a unique risk to society that we must collaborate globally to mitigate.”
Taking the lead in April was the Play ransomware group, which executed 32 attacks, accounting for 14% of observed incidents. Play has risen in prominence by employing double extortion tactics, threatening victims with data exposure alongside system encryption to coerce payment.
Recommended reading
- LockBit Ransomware Group Leader Exposed
- Lockbit Tries to Relaunch Following Global Police Takedown
- Ransomware Payments Soar 500% in the Last Year
Another notable player in April was the Hunters ransomware group, which surged from 8th position in March to become the second most prolific threat actor, carrying out 29 attacks, marking a 61% increase. Hunters’ ascent was fueled by its acquisition of infrastructure and source code from the now-defunct Hive ransomware group.
Rounding up the top three was Ransomhub, responsible for 27 attacks. Known for its strict affiliate conduct rules, Ransomhub aims to maximise payments from victims by leveraging the fear of data exposure.
Regionally, North America and Europe continued to experience the highest concentration of ransomware attacks, comprising over 80% of total incidents. While North America saw a slight decrease in attacks, Europe experienced a notable 35% drop compared to March 2024.
In terms of targeted sectors, Industrials maintained their position as the most vulnerable, with 34% of attacks directed towards this industry. Consumer Cyclicals followed closely behind, comprising 18% of targeted attacks.





