Attacks/Breaches

9/21/2016
06:05 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Education Now Suffers The Most Ransomware Attacks

New data shows ransomware rates worldwide doubling and tripling in past 12 months.

When you think ransomware victim, most likely your first thought is a hospital. But a new survey of ransomware's spread among different industry sectors shows that education is actually the biggest target right now.

BitSight, which rates the security posture of organizations based on external data showing malicious activity surrounding them, in a new report today found that education is hit most by ransomware attacks, followed by government, healthcare, energy/utilities, retail, and finance.

The firm's analysts studied ransomware activity at some 20,000 organizations and found that one in 10 education organizations had been hit with malware on their networks, followed by 6% of government entities; 3.5% of healthcare organizations; 3.4% of energy/utilities; 3.2% of retailers; and 1.5% of financial organizations. According to BitSight, the rate of ransomware attacks has doubled or tripled among various industries in the past 12 months.

BitSight's ransomware data is based on traffic by the malware; for instance, as it communicates to its command-and-control servers. It shows infected victim machines in those organizations, but doesn't necessarily mean the victims were unable to retrieve their data from backups, for example.

A recent Osterman Research survey found that both phishing and ransomware attacks had jumped several hundred percent per quarter in the past 12 months. That survey, commissioned by DomainTools, also named ransomware in the top three concerns for IT and security pros.

Law enforcement has been relatively vocal about noticeable spikes in ransomware of late: the FBI issued a public service announcement late last week urging ransomware victims to report attacks to the agency. This, after an FBI official told attendees of a Federal Trade Commission (FTC) event to immediately contact the FBI or IC3.gov if they suffer a ransomware infection, and not to pay any ransom fees.

"People have to remember that ransomware does not affect just one person or one business," Will Bales, supervisory agent for the FBI's Cyber Division, said. "It will more than likely move on and affect somebody else. And for those who pay the ransom, it only encourages them to extort the next person."

One ransomware variant infected 100,000 computers in just one day, the FBI noted in its announcement. "Cyber security companies reported that in the first several months of 2016, global ransomware infections were at an all-time high," the alert said. The FBI also noted that it needs to get a better handle on the actual number of victims, hence the call for reporting to them.

Stephen Boyer, co-founder and CTO of BitSight, says he and his team were surprised that education tops healthcare in ransomware attacks. "Protections in higher ed are lower" he says, given universities' open culture and complex user environment, for example.

To date, healthcare organizations—namely hospitals—have been the most high-profile ransomware victims, from Hollywood Presbyterian Medical Center in Los Angeles, Calif., to Washington, DC-area MedStar. Hollywood Presbyterian ultimately ponied up with $17,000 to the attackers to release its systems. MedStar had to temporarily shut down its computers, email system, and large record database to inhibit its spread to other locations in the region, and reportedly did not pay the attackers any ransom.

Ransomware By Industry Sector
Source: BitSight
Source: BitSight

More unnerving is that BitSight's new data represents just a snapshot of the attacks, Boyer says. "We know we're not seeing all of the ransomware" here, Boyer says. "But we're seeing hundreds of companies in just about every sector."

BitSight also found that two particular ransomware variants were the most prevalent: Nymaim and Locky. More than 11% of education organizations were hit by Nymaim, and 4%, with Locky, which came on the ransomware scene about eight months ago. Nymaim hit about 4% of the government entities, and 3%, Locky.

"Another important fact to note is that Nymaim, although typically associated with ransomware, is actually a Trojan that can be used to install a variety of malware," the report said.

The big takeaway from the BitSight data on ransomware: "No sector is immune," Boyer says.

 

Related Content:

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
High Stress Levels Impacting CISOs Physically, Mentally
Jai Vijayan, Freelance writer,  2/14/2019
Valentine's Emails Laced with Gandcrab Ransomware
Kelly Sheridan, Staff Editor, Dark Reading,  2/14/2019
New Free Tool Scans for Chrome Extension Safety
Dark Reading Staff 2/21/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-1944
PUBLISHED: 2019-02-21
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-For...
CVE-2018-1945
PUBLISHED: 2019-02-21
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click act...
CVE-2018-1946
PUBLISHED: 2019-02-21
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the stronges...
CVE-2018-1947
PUBLISHED: 2019-02-21
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi...
CVE-2018-1948
PUBLISHED: 2019-02-21
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to...