CISA and FBI release holiday ransomware alert
The agencies have observed an increase in 'highly impactful' ransomware attacks during the holidays, ahead of the Labour Day holiday taking place this weekend
 
 
The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have published an alert stating they have observed an increase in “highly impactful” ransomware attacks during holidays and weekends ahead of the upcoming Labour Day holiday.
The two agencies said that they do not “currently have any specific threat report indicating a cyber attack will occur over the upcoming Labour Day holiday”. Instead, they said are sharing information on how to combat ransomware attacks “to provide awareness to be especially diligent in your network defence practices in the run-up to the holidays and weekends”.
The warning states that cyber actors have conducted increasingly impactful attacks against US entities on or around holiday weekends over the last several months. The agencies state that cyber actors may view this time period as attractive as it gives them a “head start” to conduct network exploitation and the propagation of ransomware as network defenders and IT support of organisations are “at limited capacity for an extended time”.
The agencies provided examples of these attacks, such as the DarkSide ransomware attack which occurred in May 2021, leading into Mother’s Day weekend, the JBS Sodinokobi/REvil attack which occured in May 2021 over Memorial Day weekend, and another Sodinokobi/REvil attack that occurred in July 2021 over the Fourth of July holiday weekend.
Cyber security expert Kevin Beaumont posted on Twitter that he expects to see “a spate of ransomware incidents in coming weeks” although doubts that any will take place during the Labour Day holiday weekend. Beaumont highlighted that he’s seen “big game ransomware groups” on Exchange honeypots recently, using web shells planted weeks ago based upon the tools and tactics they’ve been using.
The FBI also revealed that from January to July 31, 2021, its Internet Crime Complaint Center (IC3) had received 2,084 ransomware complaints with over $16.8 million in losses, a 62% increase in reporting and a 20% increase in reported losses compared to the same time frame in 2020. It added that the two most prevalent initial access vectors to infect victims with ransomware was done through phishing and brute-forcing unsecured remote desktop protocol endpoints.
The two agencies also suggested that organisations engage in preemptive threat hunting on their networks to deal with these threats and also highlighted they “strongly discourage” paying a ransom to criminal actors”.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
- 
 Enterprises can’t keep a lid on surging cyber incident costs Enterprises can’t keep a lid on surging cyber incident costsNews With increasing threats and continuing skills shortages, AI tools are becoming a necessity for some 
- 
 UK software developers are still cautious about AI, and for good reason UK software developers are still cautious about AI, and for good reasonNews Experts say developers are “right to take their time” with AI coding solutions given they still remain a nascent tool 
- 
 Volkswagen confirms security ‘incident’ amid ransomware breach claims Volkswagen confirms security ‘incident’ amid ransomware breach claimsNews Volkswagen has confirmed a security "incident" has occurred, but insists no IT systems have been compromised. 
- 
 The number of ransomware groups rockets as new, smaller players emerge The number of ransomware groups rockets as new, smaller players emergeNews The good news is that the number of victims remains steady 
- 
 Teens arrested over nursery chain Kido hack Teens arrested over nursery chain Kido hacknews The ransom attack caused widespread shock when the hackers published children's personal data 
- 
 NCA confirms arrest after airport cyber disruption NCA confirms arrest after airport cyber disruptionNews Disruption is easing across Europe following the ransomware incident 
- 
 Cyber professionals are losing sleep over late night attacks Cyber professionals are losing sleep over late night attacksNews Hackers are biding their time and launching attacks when businesses can’t respond 
- 
 Prolific ransomware operator added to Europe’s Most Wanted list as US dangles $10 million reward Prolific ransomware operator added to Europe’s Most Wanted list as US dangles $10 million rewardNews The US Department of Justice is offering a reward of up to $10 million for information leading to the arrest of Volodymyr Viktorovych Tymoshchuk, an alleged ransomware criminal. 
- 
 Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attackNews The attack on Jaguar Land Rover highlights the growing attractiveness of the automotive sector 
- 
 Ransomware attack on IT supplier disrupts hundreds of Swedish municipalities Ransomware attack on IT supplier disrupts hundreds of Swedish municipalitiesNews The attack on IT systems supplier Miljödata has impacted public sector services across the country 
