CISA and FBI release holiday ransomware alert
The agencies have observed an increase in 'highly impactful' ransomware attacks during the holidays, ahead of the Labour Day holiday taking place this weekend


The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have published an alert stating they have observed an increase in “highly impactful” ransomware attacks during holidays and weekends ahead of the upcoming Labour Day holiday.
The two agencies said that they do not “currently have any specific threat report indicating a cyber attack will occur over the upcoming Labour Day holiday”. Instead, they said are sharing information on how to combat ransomware attacks “to provide awareness to be especially diligent in your network defence practices in the run-up to the holidays and weekends”.
The warning states that cyber actors have conducted increasingly impactful attacks against US entities on or around holiday weekends over the last several months. The agencies state that cyber actors may view this time period as attractive as it gives them a “head start” to conduct network exploitation and the propagation of ransomware as network defenders and IT support of organisations are “at limited capacity for an extended time”.
The agencies provided examples of these attacks, such as the DarkSide ransomware attack which occurred in May 2021, leading into Mother’s Day weekend, the JBS Sodinokobi/REvil attack which occured in May 2021 over Memorial Day weekend, and another Sodinokobi/REvil attack that occurred in July 2021 over the Fourth of July holiday weekend.
Cyber security expert Kevin Beaumont posted on Twitter that he expects to see “a spate of ransomware incidents in coming weeks” although doubts that any will take place during the Labour Day holiday weekend. Beaumont highlighted that he’s seen “big game ransomware groups” on Exchange honeypots recently, using web shells planted weeks ago based upon the tools and tactics they’ve been using.
The FBI also revealed that from January to July 31, 2021, its Internet Crime Complaint Center (IC3) had received 2,084 ransomware complaints with over $16.8 million in losses, a 62% increase in reporting and a 20% increase in reported losses compared to the same time frame in 2020. It added that the two most prevalent initial access vectors to infect victims with ransomware was done through phishing and brute-forcing unsecured remote desktop protocol endpoints.
The two agencies also suggested that organisations engage in preemptive threat hunting on their networks to deal with these threats and also highlighted they “strongly discourage” paying a ransom to criminal actors”.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Hackers breached a 158 year old company by guessing an employee password – experts say it’s a ‘pertinent reminder’ of the devastating impact of cyber crime
News A Panorama documentary exposed hackers' techniques and talked to the teams trying to tackle them
-
The ransomware boom shows no signs of letting up – and these groups are causing the most chaos
News Thousands of ransomware cases have already been posted on the dark web this year
-
Everything we know about the Ingram Micro cyber attack so far
News A cyber attack on Ingram Micro severely disrupted operations and has been claimed by the SafePay ransomware group.
-
A prolific ransomware group says it’s shutting down and giving out free decryption keys to victims – but cyber experts warn it's not exactly a 'gesture of goodwill'
News The Hunters International ransomware group is rebranding and switching tactics
-
Swiss government data published following supply chain attack – here’s what we know about the culprits
News Radix, a non-profit organization in the health promotion sector, supplies a number of federal offices, whose data has apparently been accessed.
-
Ransomware victims are getting better at haggling with hackers
News While nearly half of companies paid a ransom to get their data back last year, victims are taking an increasingly hard line with hackers to strike fair deals.
-
LockBit data dump reveals a treasure trove of intel on the notorious hacker group
News An analysis of May's SQL database dump shows how much LockBit was really making
-
‘I take pleasure in thinking I can rid society of at least some of them’: A cyber vigilante is dumping information on notorious ransomware criminals – and security experts say police will be keeping close tabs
News An anonymous whistleblower has released large amounts of data allegedly linked to the ransomware gangs