DYVE|TECH Latest
News

Ransomware Attacks Surge 20% in July: What You Need to Know

Ransomware attacks have seen a significant surge, with a nearly 20 percent increase in July, accordi

Ransomware attacks have seen a significant surge, with a nearly 20 percent increase in July, according to a report by UK. Dyve Tech intelligence on ransomwar...

More from Dyve Tech →

Ransomware attacks have seen a significant surge, with a nearly 20 percent increase in July, according to a report by UK firm Comparitech, which counted 799 incidents, up from 668 in June. This makes July the second-busiest month of the year for ransomware, just behind March, when the firm recorded 805 attacks. The rise in ransomware attacks is a concern for businesses and individuals alike, as it can lead to significant financial losses and disruption of critical services.

Ransomware Attack Trends and Targets

Of the 799 incidents reported in July, 51 had been confirmed by victims. The most interesting data after this surging month of attacks is the targets: While news of widespread cyberattacks targeting water infrastructure in the United States may be dominating security headlines lately, those attacks aren’t ransomware, and ransomware attacks on utility companies were actually down 44 percent last month. This decrease in attacks on utilities is a notable trend, as it suggests that attackers may be shifting their focus to other sectors.

In addition to a decline in attacks on utilities, legal firms and government agencies also became less attractive targets, with attacks on those sectors down 31 percent and 11 percent, respectively, Comparitech said. On the other hand, ransomware attacks increased most heavily in July against finance companies, tech firms, pharmaceutical companies, and medical billers, and the education sector, with rates up 71 percent, 62 percent, 46 percent, and 44 percent, respectively. This increase in attacks on these sectors is likely due to the high value of the data they hold, as well as the potential for significant financial gains for the attackers.

Why Certain Sectors Are More Vulnerable to Ransomware Attacks

Those numbers should come as no surprise given what pentesting firm DeepStrike reported about the most frequent payers of ransomware: Manufacturing, education, healthcare, and financial sector firms are the most likely to pay out a ransom, the firm says, with even the least likely (finance) still paying ransoms 51 percent of the time. This is because these sectors often have sensitive data and limited resources to dedicate to cybersecurity, making them ripe targets for attackers. Additionally, the potential consequences of a ransomware attack, such as disruption of critical services or loss of sensitive data, can be severe, making it more likely that these organizations will pay the ransom.

The United States was the most-targeted country, with 322 of the 799 attacks recorded last month, Comparitech said. Germany, in second place, saw just 40 incidents. This disparity in attacks between countries is likely due to a combination of factors, including the size and complexity of the target organizations, as well as the effectiveness of their cybersecurity measures.

Ransomware Gangs and Their Tactics

As for who’s doing the dastardly deeds, there’s a familiar name in the mix, but they’re competing with a relative newcomer who has quickly become prolific. Qilin, the ransomware gang behind the 2024 attack on pathology provider Synnovis that disrupted NHS services in the UK, claimed 125 ransomware victims in July. The Gentlemen, a relative newcomer that has quickly become one of the most prolific ransomware operations and earlier this year claimed responsibility for an attack on UK software consultancy Adaptavist Group, led July with 135 claimed victims. Between them, the two gangs accounted for nearly 33 percent of attacks logged last month.

As for how the crims keep getting in, Comparitech provided no information on ingress routes, but given what we know of the top-tier gangs, it could be simply using stolen credentials, as Trend Micro said of The Gentlemen’s methodology, or it could be abuse of zero-day vulnerabilities, as Qilin told The Register it abused to break into Synnovis in June of 2024. The use of stolen credentials and zero-day vulnerabilities are common tactics used by ransomware gangs to gain access to target organizations.

Protecting Against Ransomware Attacks

To protect against ransomware attacks, organizations should ensure that employees are using a second secure factor to log in, keep systems updated, and be sure you’re making regular backups. All eyes may be on what AI is doing to the security landscape, but old-school threats aren’t going away. By taking these steps, organizations can reduce their risk of being targeted by ransomware gangs and minimize the impact of an attack if it does occur.

In addition to these measures, organizations should also consider implementing a robust cybersecurity strategy that includes regular security audits, penetration testing, and employee training. This can help to identify and address vulnerabilities before they can be exploited by attackers, and ensure that employees are aware of the risks and know how to respond in the event of an attack.