Ransomware Attacks Leaped 13% In 2021

Share post:

According to the Verizon Data Breach Investigations Report, the use of ransomware to extort money increased by 13% in 2021 compared to 2020. The report examined 23,896 incidents that led to 5,212 confirmed data breaches.

For Alex Pinto, senior manager for security research at Verizon, the reason for the increase in the use of ransomware has to do with its profitability.

DDoS (denial-of-service) attacks remained the most common type of malicious attack with 46% of all incidents, followed by backdoors and command and control malware with 17%.

Human error remains the main strategy used by attackers to successfully carry out their attacks. 82% of breaches are due to the “human element,” as employees continue to fall victim to phishing emails.

Misconfiguration errors by IT administrators are another threat vector that is used by attackers. Attacks that exploit unpatched versions of Microsoft’s remote desktop protocol also enjoyed great popularity. This strategy accounted for 40% of successful ransomware attacks.

Web application (56%) and email servers (28%) are the two most common attack points for hackers. Software vulnerabilities accounted for 7% of breaches in 2021. 80% of web-facing server breaches involved stolen credentials.

“With regard to breaches, attackers are frequently exfiltrating personal data, including email addresses, since it is useful for financial fraud. There is also a large market for their resale, which means they are truly the ‘gift’ that keeps on giving,” the report says.

The sources for this piece include an article in TechRepublic.

SUBSCRIBE NOW

Related articles

CrowdStrike faces backlash over $10 “apology” voucher

CrowdStrike is facing criticism after offering a $10 UberEats voucher to apologize for a global IT outage that...

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

Security company accidentally hires a North Korean state hacker: Cybersecurity Today for Friday, July 26, 2024

A security company accidentally hires a North Korean state actor posing as a software engineer. CrowdStrike issues its...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways