Large US businesses are hackers' ideal ransomware targets
Research into dark web ads finds organizations in English-speaking countries are top targets
If you run a large, US-based non-health-care or -education company with revenue exceeding $100 million, then you will likely find yourself a victim of a ransomware attack.
These organizations are the most likely ransomware victims, according to a new report by cyber security firm Kela.
Kela searched dark web forums for hackers wanting to buy access to organizations. It found 48 active threads where hackers claimed they wanted to buy different kinds of accesses. Of those hackers, 40% were involved in ransomware in some way or another.
Victoria Kivilevich, a threat intelligence analyst at Kela, said ransomware attackers appear to form “industry standards” defining an ideal victim based on its revenue and geography and excluding specific sectors and countries from the targets list.
One of the hackers’ most basic requirements was network access such as RDP and VPN. The most common products mentioned were Citrix, Palo Alto Networks, VMware, Fortinet, and Cisco, according to Kivilevich.
She said that, on average, the actors active in July 2021 wanted to buy access to US companies with revenues exceeding $100 million. Almost half of them refused to buy access to companies in health care and education.
She added that the US was the most popular choice of hackers regarding victim location, as 47% of the actors mentioned it. Other top locations included Canada (37%), Australia (37%), and European countries (31%).
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
“Most of the advertisements included a call for multiple countries. The reason behind this geographical focus is that actors choose the wealthiest companies which are expected to be located in the biggest and the most developed countries,” she said.
The research found that the average minimum revenue ransomware attackers wanted was $100 million, but some stated the desired revenue depended on the location.
“For example, one of the actors described the following formula: revenue should be more than $5 million for US victims, more than $20 million for European victims, and more than $40 million for “the third world” countries,” said Kivilevich.
RELATED RESOURCE
Nine traits you need to succeed as a cyber security leader
What characteristics and certifications make a successful cyber security leader?
Almost half of ransomware-related threads included a blacklist of sectors, meaning the actors are not ready to buy access to companies from specific industries. 7% of ransomware attackers refused to buy access to companies from the health care and education industries. 37% prohibited compromising the government sector, and 26% claimed they would not purchase non-profit organizations access.
“When actors prohibit healthcare or non-profit industries offers, it is more likely due to the moral code of the actors. When the education sector is off the table, the reason is the same or the fact that education victims simply cannot afford to pay much,” she said.
“Finally, when actors refuse to target government companies, it is a precaution measure and an attempt to avoid unwanted attention from law enforcement.”
Unsurprisingly, Russian-speaking countries are off-limits for ransomware hackers, the research found.
“The actors based in CIS suppose that if they will not target these countries, local authorities will not hunt them,” she said.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Shifting from traditional MDR to an AI-powered agentic SOCAs autonomous threats proliferate, relying on standalone AI tools is a major business risk. Here is how Arctic Wolf is setting the market standard to solve the AI trust problem
-
Tokenmaxxing means FinOps is more important than everNews With firms facing surging AI bills, FinOps techniques are more important than ever
-
Companies are still paying ransoms to cyber criminals despite official adviceNews A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims
-
Health tech firm Craneware admits “significant volume” of customer and employee data exposed in cyber attackNews The incident has been contained and Craneware has launched a probe into the breach
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments