Ransomware has emerged as one of the top concerns for just about every organisation in recent years – regardless of industry or business model.
After year-on-year increases in attack figures, competing sources have provoked debate on whether ransomware rose or fell as a risk in 2022.
From one perspective, there is a growing consensus and evidence to suggest that total attack rates may have lessened, substantiated by falling reported cryptocurrency revenues for threat actors.
Conversely, the narrative of exponential growth which has accompanied ransomware since 2019/2020 still carries significant momentum, with announcements that 2022 was the breakout year for ransomware, despite evidence that the year saw a less dramatic rise in activity.
While JUMPSEC‘s global 2022 data showed attacker reported ransomware rates experienced diminished growth compared to previous years, the UK saw attacks increased by a further 17% in 2022.
In the UK at least, statements about the diminished threat of ransomware should be met with a degree of caution, especially since early data for 2023 shows signs of an uptake in UK ransomware activity.
According to the report, new and emerging vulnerabilities are likely to increase the damage ransomware groups can inflict on organisations following discovery and exploitation.
While new vulernabilites like Spring4Shell, Follina, and ProxyNotShell were exploited in 2022, they were not taken advantage of to the degree as Log4j late in 2021.
Further, at no point in 2022 did total attack rates reach November/December 2021’s record high of 20 attacks over two weeks, largely due to the Log4j vulnerability.
Who are the Major Threat Actors?
Following the supposed disbandment of ransomware groups such as Conti and REvil, some of the largest ransomware players in 2021, new threat actors have gained prominence in the ransomware space.
While attacks fell in May after the decline of Conti, the major resurgence of LockBit saw attacks rise in Autumn.
Since their resurrection, LockBit have taken the mantel as the largest ransomware threat globally and in the UK, claiming over 52% of reported global ransomware attacks.
In just two weeks in September, LockBit registered 291 total attacks alone, the most recorded since ransomware started making waves in 2019.
Groups like Karakurt and BlackCat have also gained recognition as more prevalent threats in 2022, while Vice Society has maintained itself as a consistent threat.
Influencing FactorsÂ
Global trends have a massive influence on ransomware activities – the invasion of Ukraine by Russia saw an onslaught of Russian-backed hacktivist groups conducting DDoS attacks on global organisations.
For example, Killnet, a pro-Russian group, threatened action against the UK’s provision of anti-air missiles for Ukraine.
Payments have also transformed – Chainanalysis showed that total payments decreased in 2022, but this does not necessarily equate to less damage from attackers.
Victim organisations in 2022 were found to have lost revenue and customers as a result of a ransomware attack.
Investment into cybersecurity could also be impacting ransomware activities – the UK Cyber security sectoral analysis 2022 report shows organisations are making security a priority, with total annual UK revenue within the sector reaching £10.1 billion in 2022, an increase in 14% from the prior year.
Despite a problematic skills shortage, the industry also saw an increase in 6,000 security employee jobs.
Action from law enforcement had a major impact in previous years with the shutdown on Conti after a bounty was set, as well as a disruption operation against Hive ransomware.
Further, the UK’s Office of Financial Sanctions Implementation (OFSI) recently released a ‘Ransomware and Sanctions’ guide for organisations, stressing the impact of ransomware payments.
Recommended
- Glasgow Innovation Accelerator Progresses with £100m
- Glasgow Firm Softworx Eyes Tech Recruitment Market with New Agency
- The Drive to Enhance the Insurance Customer Experience
UK Sectors Targeted
Education was the most targeted sector of 2022, with over 20% of ransomware attacks.
Legal services faced just over 10% of all attacks, followed by Retail and Wholesale Trade with 10%.
Whats in Store for 2023?
While JUMPSEC’s report showed an uptick in UK attacks, these numbers are expected to fluctuate throughout the year.
Vulnerabilities will continue to be exploited, with early indicators that vulnerabilities affecting VMware ESXI servers are being actively exploited by groups.
Stricter insurance terms may restrict the ability of threat actors to extort organisations and insurers limit their exposer and financial support to victims.
Already, Hardbit ransomware have begun to request insurance details from victims so ransom demand can be adjusted to fall within the policy, according to the report.
Further, restrictions may be put into place on making payments – the UK have already explained that making a ransomware payment may be in breach of financial sanctions.
Cyber attacks may also continue to be a ‘grey-zone’ tactic for militaries seeking to interrupt state organisations without overt war.





