Ransomware hit industrial sector the hardest in the third quarter

Cyber criminals are now also targeting the technology sector, which saw a 30% rise in attack volume

Ransomware gangs hit the industrial sector the hardest during the third quarter of this year, according to a report by security company Digital Shadows.

The report named the industrial goods and services sector as the biggest target during the third quarter of this year, maintaining a position that it has held throughout 2021. The technology sector came second, followed by construction and materials, legal services, and financial services. 

The number of attacks on the industrial sector fell by 42% quarter-on-quarter, however, which the report attributes to diversification. Ransomware groups are now targeting more sectors, it said, adding that many of these attacks seem to be targeting the technology sector, which saw a 29.8% bump in attack volume. 

The busiest ransomware group was LockBit 2.0, first seen in July this year. It knocked Conti from the top spot, which it had retained for the first half of this year. LockBit 2.0 hit 203 victims, which was almost triple Conti's count for the third quarter. 

The report also highlighted the chaotic nature of the ransomware business. It cited several groups that had disappeared, with some reappearing later or rebranding. This includes REvil, which vanished from the dark web in July and then reappeared. The group's web site went dark again this month following a multinational effort by law enforcement. 

Related Resource

How to reduce the risk of phishing and ransomware

Top security concerns and tips for mitigation

Large letter 'O' against a background of a city - whitepaper from MimecastFree download

Digital Shadows noted the difficulty in using dark web sites, which are limited in speed. This has made it difficult for ransomware groups to leak large data files, causing some to rely instead on the regular web. 

The third quarter also saw the Colonial Pipeline attack by the DarkSide group, which was responsible for a ban on ransomware-related discussions from most cyber crime forums. There was also the REvil attack on managed services company Kaseya, and last month's hit on an Iowa farming cooperative. 

Even though the Colonial Pipeline attack had caused forums to ban ransomware discussions, there's always another criminal entrepreneur willing to step up. In this case, a new forum called RAMP, dedicated to ransomware, picked up the slack. Digital Shadows' report said it uses the same URL as the Babuk ransomware group's data leak site, and hosts a data leak site of its own called Groove.

Featured Resources

Shining light on new 'cool' cloud technologies and their drawbacks

IONOS Cloud Up! Summit, Cloud Technology Session with Russell Barley

Watch now

Build mobile and web apps faster

Three proven tips to accelerate modern app development

Free download

Reduce the carbon footprint of IT operations up to 88%

A carbon reduction opportunity

Free Download

Comparing serverless and server-based technologies

Determining the total cost of ownership

Free download

Recommended

Sophos Intercept X Advanced review: AI-powered protection
endpoint security

Sophos Intercept X Advanced review: AI-powered protection

30 Nov 2021
Sabbath hackers are targeting US schools and hospitals
ransomware

Sabbath hackers are targeting US schools and hospitals

29 Nov 2021
SMBs urged to update software ahead of Black Friday
e commerce

SMBs urged to update software ahead of Black Friday

25 Nov 2021
US adds dozen Chinese tech companies to trade blacklist
Policy & legislation

US adds dozen Chinese tech companies to trade blacklist

25 Nov 2021

Most Popular

Sabbath hackers are targeting US schools and hospitals
ransomware

Sabbath hackers are targeting US schools and hospitals

29 Nov 2021
Apple's mixed reality headset could debut in 2022
augmented reality (AR)

Apple's mixed reality headset could debut in 2022

29 Nov 2021
Nike to take customers into the metaverse with 'NIKELAND'
virtualisation

Nike to take customers into the metaverse with 'NIKELAND'

19 Nov 2021