{"id":4806,"date":"2020-12-07T11:29:48","date_gmt":"2020-12-07T11:29:48","guid":{"rendered":"https:\/\/blog.gridinsoft.com\/?p=4806"},"modified":"2022-12-05T15:46:39","modified_gmt":"2022-12-05T15:46:39","slug":"ransomware-facts","status":"publish","type":"post","link":"https:\/\/gridinsoft.com\/blogs\/ransomware-facts\/","title":{"rendered":"Ransomware &#8211; Facts at The Edge of 2022"},"content":{"rendered":"<p style=\"text-align: justify\">It is hard to imagine something more harmful than ransomware. Besides the danger for your files and PC, it also deals a significant damage to quite a material thing &#8211; your wallet. <strong>$500, $1000, or even $5-7k<\/strong><span id='easy-footnote-1-4806' class='easy-footnote-margin-adjust'><\/span><span class='easy-footnote'><a href='https:\/\/gridinsoft.com\/blogs\/ransomware-facts\/#easy-footnote-bottom-1-4806' title='About &lt;a href=&quot;https:\/\/howtofix.guide\/doppelpaymer-ransomware-attacked-the-delaware-county-government\/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;DOPPELPAYMER&lt;\/a&gt; &amp;#8211; ransomware with the increased requests'><sup>1<\/sup><\/a><\/span> ransom for separate corporations. In this article we will talk about the modern ransomware trends, facts about the spreading of ransomware, and statistics that make the hair move.<\/p>\n<h2>5 facts about ransomware spreading<\/h2>\n<h4>IT security succeeded in counteraction to ransomware<\/h4>\n<p style=\"text-align: justify\">A lot of companies who suffered from ransomware reported about increasing the security <strong>in all eight functional areas<\/strong>. But such improvements were also reported in the corporations that had no experience in ransomware attacks. Is it a reason to call ransomware the global stimulus for cyber security rise? Maybe, but <strong>the price of such a \u201clesson\u201d can be very high.<\/strong><\/p>\n<h4>The carelessness of people is the biggest problem<\/h4>\n<p style=\"text-align: justify\">The biggest share of ransomware attacks are done with the \u201chelp\u201d of the workers <strong>who know nothing about cybersecurity<\/strong> or even internet hygiene. They are clicking the dubious links in the email, opening the attachments without any doubt and sharing the confidential information, like corporate emails. Such people are able to multiply by zero any cybersecurity shield, because the main assumption is that <strong>there is no information leaks from the inner part<\/strong> of the corporation.<\/p>\n<h4>Ransomware developers are more active than they have ever been<\/h4>\n<p style=\"text-align: justify\">2020 is a year when <strong>75% of the planet population started working online<\/strong>. And the more information is moving through the common network instead of corporate, the bigger the chances to steal something valuable and then ask for the ransom <strong>to keep this information away from the public<\/strong>. And besides the data leak risks, there is also a great opportunity for malware distributors to inject the ransom trojan. Last will inject the hacktool, which will crack the passwords of the whole network, and then launch the ransomware.<\/p>\n<figure id=\"attachment_4810\" aria-describedby=\"caption-attachment-4810\" style=\"width: 771px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/work-from-home.jpg\" alt=\"Working from home stats\" width=\"771\" height=\"384\" class=\"size-full wp-image-4810\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/work-from-home.jpg 771w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/work-from-home-300x149.jpg 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/work-from-home-768x383.jpg 768w\" sizes=\"auto, (max-width: 771px) 100vw, 771px\" \/><figcaption id=\"caption-attachment-4810\" class=\"wp-caption-text\">Working from home statistics in 2020<\/figcaption><\/figure>\n<h4>Artificial intelligence as a new cybersecurity trend<\/h4>\n<p style=\"text-align: justify\">Through 2019, AI usage in cybersecurity at all and in breach analysis in particular rose 58%<span id='easy-footnote-2-4806' class='easy-footnote-margin-adjust'><\/span><span class='easy-footnote'><a href='https:\/\/gridinsoft.com\/blogs\/ransomware-facts\/#easy-footnote-bottom-2-4806' title='Artifical Intilligence &lt;a href=&quot;https:\/\/www.balbix.com\/insights\/artificial-intelligence-in-cybersecurity\/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;usage in cybersecurity&lt;\/a&gt;'><sup>2<\/sup><\/a><\/span>, and kept going in 2020. Corporations show <strong>the enormous interest in the machine learning systems<\/strong>, that gives the ability to detect and protect the security breaches before it can be used by cyber burglars. And, as practice shows, security solutions based on the AI are able to detect the vulnerabilities <strong>much faster and more correct<\/strong> than the cybersecurity experts do.<\/p>\n<h4>Rise of cyber burglars appetites<\/h4>\n<p style=\"text-align: justify\">As it was mentioned, <strong>cybercriminals became enormously active in 2020<\/strong>. But stats are so bad only for solitary users. Corporations were under attack since 2017, scoring about 50-55% of attacked companies among ones which took part in the poll. Nowadays, the <strong>share of corporations under attack rose to 68%<\/strong> (compared to 56% in 2019), together with the corresponding increase in the average ransom paid by the single company &#8211; <strong>up to $8.1k in 2020<\/strong>, compared to $5.9k in 2019 and $4.3k in 2018.<\/p>\n<h2>Saying about the statistics<\/h2>\n<p style=\"text-align: justify\">The main harm ransomware does is neither file encryption nor data leak. The biggest cost that appears because of ransomware attack is <strong>the cost for downtime<\/strong>. Workers are not able to do their job when the files they need are encrypted and readme.txt files are everywhere. Nonetheless, corporations are <strong>still obligated to pay the salary<\/strong> to their employees, and pay the penalty for the delays in goods or services delivery. Some little companies were literally buried by such consequences of ransomware activity. Here is the graphic which shows the average downtime costs:<\/p>\n<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/downtime-costs.png\" alt=\"Statistics of downtime costs\" width=\"1119\" height=\"557\" class=\"aligncenter size-full wp-image-4812\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/downtime-costs.png 1119w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/downtime-costs-300x149.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/downtime-costs-1024x510.png 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/downtime-costs-768x382.png 768w\" sizes=\"auto, (max-width: 1119px) 100vw, 1119px\" \/><\/p>\n<p style=\"text-align: justify\">It is also interesting that <strong>ransomware developers have their favourite targets<\/strong>. No, not corporations &#8211; the whole countries and sectors of economy. Such targeting is likely caused by the payability of the local business &#8211; the more money is rolling in the corporations of this sector &#8211; the bigger the chance that <strong>the ransom will be paid<\/strong>. Of course, low level of cybersecurity development is also a reason for such statistics, but this factor is likely complementary then initial.<\/p>\n<figure id=\"attachment_4814\" aria-describedby=\"caption-attachment-4814\" style=\"width: 1107px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/ransomware-attacks-rate.png\" alt=\"Share of the corporations attacked by ransomware\" width=\"1107\" height=\"497\" class=\"size-full wp-image-4814\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/ransomware-attacks-rate.png 1107w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/ransomware-attacks-rate-300x135.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/ransomware-attacks-rate-1024x460.png 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/ransomware-attacks-rate-768x345.png 768w\" sizes=\"auto, (max-width: 1107px) 100vw, 1107px\" \/><figcaption id=\"caption-attachment-4814\" class=\"wp-caption-text\">Share of the medium and large companies attacked by ransomware<\/figcaption><\/figure>\n<p style=\"text-align: justify\">As you can see, the biggest share of companies under attack to total companies is in the Saudi Arabia. The second place is after Turkey, which has <strong>significantly less share of attacked companies<\/strong>; China is on the 3rd place. All other countries in the list has the shares which differ on 2-5%, so such a big gap for Saudi Arabia is likely <strong>caused by the complex activity of mentioned factors<\/strong> &#8211; low cybersecurity level, great interest of ransomware developers and large turnover.<\/p>\n<p style=\"text-align: justify\">Unfortunately, the detailed statistics about the sectors that are favourite among the ransomware developers is available only for the USA. Here it is:<\/p>\n<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/companies-under-attack.png\" alt=\"Ransomware attacks on economy sectors\" width=\"1119\" height=\"517\" class=\"aligncenter size-full wp-image-4816\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/companies-under-attack.png 1119w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/companies-under-attack-300x139.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/companies-under-attack-1024x473.png 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/companies-under-attack-768x355.png 768w\" sizes=\"auto, (max-width: 1119px) 100vw, 1119px\" \/><\/p>\n<p style=\"text-align: justify\">Government organizations and large part of the real sector of the economy is under attack. The last place with the share that is <strong>3 times less than the governmental companies has<\/strong> is after financial services. It means that the cybersecurity level in last ones is much higher than in governmental structures: both financials and government have a lot of valuable information and money supply, so the chance of getting the ransom as well as blackmailing with the threats of selling the confidential information is equal.<\/p>\n<p style=\"text-align: justify\">Ransomware penetration statistics is also available only for Northern America. As it was mentioned at the beginning of the article, the <strong>reason for the majority of attacks is low level of cybersecurity knowledge<\/strong> among users. Using the PC without understanding of all hazards is like smoking near the opened gasoline barrel. But while gasoline barrel explosion can harm you and, maybe, someone who was unlucky to be close to you, <strong>cyber attack will harm the whole corporation<\/strong> in the described way.<\/p>\n<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/ways-of-ransom-injection.png\" alt=\"Ways of ransomware injection\" width=\"776\" height=\"444\" class=\"aligncenter size-full wp-image-4819\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/ways-of-ransom-injection.png 776w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/ways-of-ransom-injection-300x172.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/ways-of-ransom-injection-768x439.png 768w\" sizes=\"auto, (max-width: 776px) 100vw, 776px\" \/><\/p>\n<p style=\"text-align: justify\">The way ransomware spreads through all computer networks is worth <a href=\"https:\/\/howtofix.guide\/mimikatz-hacktool\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">a separate article<\/a>. Saying short, it acts together with other viruses and hack tools, <strong>cracking the passwords of the whole corporate network<\/strong>, and then injecting the ransomware with a backdoor in every PC it can reach. At the same time, ransomware developers <a href=\"https:\/\/gridinsoft.com\/blogs\/ransomwares-doesnt-always-delete-stolen-data-after-paying-the-ransom\/\">steal confidential information<\/a> (if such is present on the attacked computers) <strong>and sell it in the darknet<\/strong>.<\/p>\n<h3>Popular types of ransomware<\/h3>\n<p style=\"text-align: justify\">This characteristic is <strong>unusually stable in the constantly-changing computer environment<\/strong>. Old-but-gold WannaCry<span id='easy-footnote-3-4806' class='easy-footnote-margin-adjust'><\/span><span class='easy-footnote'><a href=\"https:\/\/gridinsoft.com\/blogs\/ransomware-facts\/#easy-footnote-bottom-3-4806\" title=\"The most famous &lt;a href=&quot;https:\/\/en.wikipedia.org\/wiki\/WannaCry_ransomware_attack&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;WannaCry attack&lt;\/a&gt;\"><sup>3<\/sup><\/a><\/span> has been moved to the second place by the CryptoLocker family only this year; in 2019, first one <strong>was leading with a significant gap<\/strong>. Third and fourth places have quite small shares &#8211; the total share of CryptoWall and Locky together is less than CryptoLocker share. Petya, CryptXXX and notPetya have the shares that are close by size, but compared even to the Locky their activity is weak.<\/p>\n<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/shares-families.png\" alt=\"Shares of successful cyberattacks by families\" width=\"774\" height=\"394\" class=\"aligncenter size-full wp-image-4820\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/shares-families.png 774w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/shares-families-300x153.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/shares-families-768x391.png 768w\" sizes=\"auto, (max-width: 774px) 100vw, 774px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It is hard to imagine something more harmful than ransomware. Besides the danger for your files and PC, it also deals a significant damage to quite a material thing &#8211; your wallet. $500, $1000, or even $5-7k ransom for separate corporations. In this article we will talk about the modern ransomware trends, facts about the [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":4840,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[15],"tags":[416,55],"class_list":{"0":"post-4806","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security-news","8":"tag-darknet","9":"tag-ransomware"},"featured_image_src":"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2020\/12\/ransomware-featured-copy.png","author_info":{"display_name":"Stephanie Adlam","author_link":"https:\/\/gridinsoft.com\/blogs\/author\/adlam\/"},"_links":{"self":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/4806","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/comments?post=4806"}],"version-history":[{"count":2,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/4806\/revisions"}],"predecessor-version":[{"id":7494,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/4806\/revisions\/7494"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media\/4840"}],"wp:attachment":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media?parent=4806"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/categories?post=4806"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/tags?post=4806"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}