Site navigation

Repeat Ransomware Attacks Common, Even if You Paid Up

Michael Edgar

,

Repeat Ransomware NCC LockBit report
Many organisations who pay cyber-ransom demands are hit by a second attack, says a new report. 

This revelation comes from a recent study by Cybereason called Ransomware: The Cost to Business Study 2024. The study also found that of the four in five (78%) of organisations who pay ransom demands and are hit by a second attack, 36% of perpetrators were the same threat actor. 

On top of that, nearly two thirds (63%) of these organisations were then asked to pay more the second time. And over half (56%) of the surveyed organisations experienced more than one ransomware incident within the last 24 months, highlighting the persistent and growing menace posed by cyber-criminals.

The study, which involved input from over 1000 cybersecurity professionals, revealed that an alarming 84% of organisations ultimately opted to fulfil ransom demands following a breach. However, the outcomes were far from reassuring, with less than half (47%) successfully recovering their data and services uncorrupted. 

“This is problematic on several levels. It’s no guarantee that your data and systems will be returned uncorrupted, that attackers won’t sell your data on the black market, or that you won’t be attacked again,” said Greg Day, global field CISO (VP) at Cybereason.

The decision to pay a ransom was influenced by various factors cited by respondents, including the threat of sensitive information disclosure, fear of business loss, perceived expediency of payment, staffing limitations during holidays or weekends, and, in some cases, concerns for lives at stake or lack of backup files.

The financial ramifications of ransomware attacks are substantial, with nearly half (46%) of victims estimating business losses going up to £7.8 million, and 16% reporting losses exceeding  £7.8 million. 

Despite the escalating risks and financial toll of ransomware attacks, only 41% of organisations feel adequately equipped to manage future attacks, while uncertainty looms over the extent of cyber insurance coverage.

“This year’s research shows that, while most businesses have a ransomware strategy in place, many are incomplete. They’re either missing a documented plan or the right people to execute it. As a result, we see that many organisations are paying the ransom. Likewise, whilst many have cyber insurance, too many simply don’t know if or to what degree it covers them for ransomware attacks,” said Day. 


Recommended reading


Furthermore, the study underscored a concerning shift towards sophisticated “low-and-slow” ransomware tactics, aimed at infiltrating networks extensively to maximise ransom payments. 

Shockingly, over half (56%) of organisations failed to detect breaches for 3-12 months, with ransomware actors exploiting supply chain breaches, direct infiltration, and insider assistance to gain unauthorised access.

The researchers also noted the increasing efficacy of ransomware actors, facilitated by the use of generative AI tools to craft persuasive social engineering messages tailored to diverse linguistic audiences.

Tags: ,

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data