CISA and FBI release holiday ransomware alert
The agencies have observed an increase in 'highly impactful' ransomware attacks during the holidays, ahead of the Labour Day holiday taking place this weekend
The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have published an alert stating they have observed an increase in “highly impactful” ransomware attacks during holidays and weekends ahead of the upcoming Labour Day holiday.
The two agencies said that they do not “currently have any specific threat report indicating a cyber attack will occur over the upcoming Labour Day holiday”. Instead, they said are sharing information on how to combat ransomware attacks “to provide awareness to be especially diligent in your network defence practices in the run-up to the holidays and weekends”.
The warning states that cyber actors have conducted increasingly impactful attacks against US entities on or around holiday weekends over the last several months. The agencies state that cyber actors may view this time period as attractive as it gives them a “head start” to conduct network exploitation and the propagation of ransomware as network defenders and IT support of organisations are “at limited capacity for an extended time”.
The agencies provided examples of these attacks, such as the DarkSide ransomware attack which occurred in May 2021, leading into Mother’s Day weekend, the JBS Sodinokobi/REvil attack which occured in May 2021 over Memorial Day weekend, and another Sodinokobi/REvil attack that occurred in July 2021 over the Fourth of July holiday weekend.
Cyber security expert Kevin Beaumont posted on Twitter that he expects to see “a spate of ransomware incidents in coming weeks” although doubts that any will take place during the Labour Day holiday weekend. Beaumont highlighted that he’s seen “big game ransomware groups” on Exchange honeypots recently, using web shells planted weeks ago based upon the tools and tactics they’ve been using.
The FBI also revealed that from January to July 31, 2021, its Internet Crime Complaint Center (IC3) had received 2,084 ransomware complaints with over $16.8 million in losses, a 62% increase in reporting and a 20% increase in reported losses compared to the same time frame in 2020. It added that the two most prevalent initial access vectors to infect victims with ransomware was done through phishing and brute-forcing unsecured remote desktop protocol endpoints.
The two agencies also suggested that organisations engage in preemptive threat hunting on their networks to deal with these threats and also highlighted they “strongly discourage” paying a ransom to criminal actors”.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Trump's AI executive order could leave US in a 'regulatory vacuum'News Citing a "patchwork of 50 different regulatory regimes" and "ideological bias", President Trump wants rules to be set at a federal level
-
TPUs: Google's home advantageITPro Podcast How does TPU v7 stack up against Nvidia's latest chips – and can Google scale AI using only its own supply?
-
15-year-old revealed as key player in Scattered LAPSUS$ HuntersNews 'Rey' says he's trying to leave Scattered LAPSUS$ Hunters and is prepared to cooperate with law enforcement
-
The Scattered Lapsus$ Hunters group is targeting Zendesk customers – here’s what you need to knowNews The group appears to be infecting support and help-desk personnel with remote access trojans and other forms of malware
-
Impact of Asahi cyber attack laid bare as company confirms 1.5 million customers exposedNews No ransom has been paid, said president and group CEO Atsushi Katsuki, and the company is restoring its systems
-
The US, UK, and Australia just imposed sanctions on a Russian cyber crime group – 'we are exposing their dark networks and going after those responsible'News Media Land offers 'bulletproof' hosting services used for ransomware and DDoS attacks around the world
-
A notorious ransomware group is spreading fake Microsoft Teams ads to snare victimsNews The Rhysida ransomware group is leveraging Trusted Signing from Microsoft to lend plausibility to its activities
-
Volkswagen confirms security ‘incident’ amid ransomware breach claimsNews Volkswagen has confirmed a security "incident" has occurred, but insists no IT systems have been compromised.
-
The number of ransomware groups rockets as new, smaller players emergeNews The good news is that the number of victims remains steady
-
Teens arrested over nursery chain Kido hacknews The ransom attack caused widespread shock when the hackers published children's personal data
