The UK’s National Cyber Security Centre (NCSC) has warned that increasingly sophisticated ransomware attacks are putting organisations at risk.
In a joint advisory with the Australian Cyber Security Centre (ACSC), the US Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA), the NCSC detailed 2021’s cybersecurity trends.
As the threat of malware escalates, the NCSC warned that attacks have targeted UK businesses, charities, the legal profession, and public services, with education being of the top hit UK sectors.
The US bodies added that 14 of the US’s 16 critical infrastructure sectors have been targeted, including the Defence Industrial Base, Emergency Services, and Food and Agriculture.
However, these major attacks brought attention on the cybercriminals and saw authorities disrupt their operations. As such, the FBI observed ransomware threat actors are redirecting ransomware efforts away from ‘big-game’ and toward mid-sized victims.
But the ACSC and NCSC noted that attacks continue to hit organisations of all sizes in their countries.
With incidents like the 2020 ransomware attack that hit the Scottish Environmental Protection Agency (SEPA) still affecting the organisation, the impact of a breach can have serious consequences. A report warned that SEPA is still rebuilding its computer systems and the full financial impact of the incident is still unknown.
Ransomware gangs are acting in an increasingly professional manner now that their ‘business model’ has matured. For example, the prevalence of the ransomware-as-a-service (RaaS) model, where hackers provide a services-for-hire, is growing.
Some gangs are hiring independent services to negotiate payments, assist victims with making payments, arbitrate payment disputes, and even offer 24/7 help centres to expedite ransom payment and restoration of encrypted systems or data.
The increasingly complex network of developers and affiliates also serves to complicate identifying the actors behind a ransomware incident, making it difficult to target and arrest suspects.
The advisory warns that hackers are also sharing victims’ information between each other and are diversifying the approaches they use to extort money. This sees one gang selling access to victims’ networks, allowing follow-on attacks.
Ransomware groups also increased the impact of their attacks by targeting cloud services and attacking industrial processes and the software supply chain. Some of the largest attacks of last year, such as Kaseya, Microsoft Exchange and Log4j, all involved compromising third-party software providers, hitting organisations that use their software.
In addition, increasingly sophisticated ransomware groups are timing their attacks to coincide with public holidays and weekends. This slows down the response to a breach as key personnel are unable to respond.
The three main vectors for ransomware infections in 2021 were phishing emails, RDP exploitation, and exploitation of software vulnerabilities. This was in part driven by the popularity of remote work and schooling, which expanded the remote attack surface and left network defenders struggling to keep pace with routine software patching.
Recommended
- Comment | Monitoring and surveillance in the workplace and beyond
- LendingCrowd raises £100m to support British SMEs
- Openreach to add 500 Scottish jobs in 2022
NCSC CEO Lindy Cameron said: “Ransomware is a rising global threat with potentially devastating consequences but there are steps organisations can take to protect themselves.
“To help ensure organisations are aware of the threat and how to defend themselves we have joined our international partners to set out the very latest threat picture alongside key advice.
“I strongly encourage UK CEOs and Boards to familiarise themselves with this alert and to ensure their IT teams are taking the correct actions to bolster resilience.”
Faced with growing sophistication of ransomware gangs, the NCSC and international partners are urging businesses and other organisations to take protective action.
The groups advised implementing a requirement for multi-factor authentication, Zero Trust architecture, and a user training programme with phishing exercises.
Ensuring that software is regularly updated and running the latest version is also important to make it harder for hackers to exploit known vulnerabilities.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





