Ransomware Impact Analysis 2023
Ransomware Impact Analysis 2023
RANSOMWARE
A Detaile d A nalysis of the Fre quenc y and Impac t of Rans omware Event s
Introduction
THE CYENTIA INSTITUTE
Few cyber threats have inspired more fear, uncertainty, and doubt
Table of
Contents
(FUD) in recent years than ransomware. Organizations fear they’ll
be the subject of headlines detailing the latest crippling wave of
attacks. They’re uncertain about the likelihood and impact of such
an event and doubt whether current defenses adequately mitigate
the risk. While ransomware FUD-mongering abounds, the risk is
real, and concerns justified. It is no “small thing.”
Introduction 2
Like its predecessors, this latest edition of the Information Risk
Insights Study (IRIS) is about FUD-managing rather than FUD- Key Findings 2
mongering. Our goal is to shine the clarifying light of rigorous
analysis to dispel the fog of FUD enshrouding ransomware that Ransomware Ranks
inhibits organizations’ ability to make informed, rational decisions Somewhere… But Where? 5
to manage risk.
Ransomware Event Frequency 7
To enable that, we leverage a massive dataset containing over
Historical Ransomware Events 7
14,000 ransomware events that compromised over a billion data
records and led to projected financial losses topping $270 billion Modeling Ransomware
over the last five years. We highlight key findings from our analysis Event Frequency 11
of that data on the next page and dive right into the detailed insights
straightaway after that. Ransomware Losses 16
The Cyentia Institute wishes to thank and acknowledge the Top Ransomware Strains 24
Cybersecurity Division and the Office of the Chief Economist at
the Cybersecurity and Infrastructure Security Agency (CISA) for Top Ransomware Techniques 26
sponsoring this study. It is our sincere hope that this research will lead
Conclusion 29
to better cyber risk assessments
and cyber risk reduction decisions Appendix A: Incident
for years to come. Pattern Descriptions 31
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
2
R ANSOMWARE Key Findings
INFO R M AT I O N R IS K INS I G H TS S T UDY
In just the last five years, the typical financial loss from ransomware
incidents has grown from $686K to $3.7M.
Our analysis focuses primarily on ransomware incidents that occurred from 2019 through 2023,
unless otherwise indicated. This five-year timeframe encompasses over 14,000 ransomware events
that compromised more than 1.1B data records and led to projected financial losses topping
$270B.
It’s important to note that we’re not claiming the data used in this report reflects all ransomware
incidents that occurred during this timeframe. We can only analyze those that make their way into
the public record, through outward signs or impacts, mandatory reporting, voluntary disclosure,
etc. Advisen and Cyentia closely monitor such events and have high confidence that this dataset is
representative of significant ransomware events.
In addition to Advisen’s standard fields, we further enriched the dataset through a combination
of natural language processing, classification models, and manual analysis. We also incorporate
datasets from Fortinet, Ransomwatch, and Tidal Cyber into our analysis where appropriate.
4
THE CYENTIA INSTITUTE
Ransomware Ranks
Somewhere...But Where?
LET’S START WITH THE BIG PICTURE RIGHT UP FRONT: WHERE
DOES RANSOMWARE RANK IN RELATION TO OTHER TYPES OF CYBER Events
EVENTS?
Events
It should be noted Losses
that there is some degree of overlap among these Records
patterns. For example, many ransomware events involve attacks 2.7%
intruding into the target organization's network and systems. In such
cases, we classified those events as ransomware rather than system
intrusion. When events 31.7%
exhibit characteristics that span 37.6%
multiple
patterns, we go with the one that fits best.
2nd 1st 3rd
62.4%
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
1
Refer to the Terms Used in this Study for more information on how we define incidents and losses throughout this report.
5
THE CYENTIA INSTITUTE
The message from the data is clear: ransomware is a top cyber risk for organizations today. The rest of this
report is dedicated to digging into the details surrounding key ransomware frequency and impact trends so
that organizations are better prepared to manage this risk.
6
THE CYENTIA INSTITUTE
Ransomware
Event Frequency
“May the odds be ever in your favor!”
Effie Trinket, Hunger Games
In our journey to better assess the risk posed by ransomware events, we first
explore how often they occur. Our initial step is to examine high-level trends,
and then we’ll establish an annualized probability of a given organization
experiencing a ransomware event. Our ultimate goal is to develop an event
frequency model along with the associated parameters to support risk analysis
focused on ransomware.
Historical
Ransomware Events
History doesn’t always repeat itself, but studying past events is usually a better
predictor of future trends than blind predictions. With that in mind, Figure 2
tallies the monthly count of all public security incidents (gray dashed line) and
splits that into ransomware (light blue line) and non-ransomware (dark blue
line) events. We’ve opted for a 10-year window here to grant a wider view of
historical trends.
Keep in mind that public incident reporting often lags months (even years)
behind as events progress from discovery to disclosure, which explains the
apparent falloff of the overall and non-ransomware trendlines toward the end
of the period.
7
THE CYENTIA INSTITUTE
The overall frequency of security incidents fluctuates with a slight rising trend over the last few years. Breaking
that out between ransomware and non-ransomware events reveals ransomware to be the primary cause of
that rise. Non-ransomware events actually show a slightly downward trajectory.
O v e r a ll
750
No
n-r
a ns om
war
e
500
250 ar e
ns omw
Ra
Figure 2: Monthly count of all cyber loss events (top) and ransomware events (bottom)
So, ransomware’s clearly running up. But the event counts depicted in Figure 2 actually downplay the rise of
ransomware relative to other types of security incidents. Figure 3 makes that more apparent by showing
ransomware as a proportion of all recorded events.
50%
40%
Professionalization of ransomware
30%
20%
10%
0%
2015 2016 2017 2018 2019 2020 2021 2022 2023 2024
8
THE CYENTIA INSTITUTE
Ransomware was merely an “also ran” among contenders for the top cyber event
category back in 2015, accounting for ~1% of all incidents. As described in this
Atlantic Council brief2, ransomware gangs during this time primarily engaged in
“take-it-or-leave it” extortion schemes that involved low-end ransoms.
That same Atlantic Council brief identifies a new phase of ransomware evolution
starting around 2016, when it was increasingly used in targeted and destructive
attacks. Prominent ransomware strains during this period include Ryuk and
REvil. The one-two punch of WannaCry and NotPetya captured global attention
and signaled more disruptive use cases.
While everyone else hunkered down during the COVID-19 pandemic, ransomware
gangs seized the opportunity to ramp up their operations. They enjoyed higher
leverage over victims, more sophisticated capabilities, and huge profits. This
era of professionalization fueled the surge seen in Figure 3, culminating in
ransomware averaging 52% of monthly reported cyber events throughout 2023!
Per Figure 4, more ransomware incidents hit the Education sector than any
other. The many cybersecurity challenges faced by educational institutions are
well documented, and it appears ransomware has amplified those challenges.
An environment filled with a diverse array of devices that often aren’t centrally
controlled creates a large attack surface vulnerable to ransomware infections.
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
The Professional sector brings up a close second. Most entities in that industry
exist to provide services to others, hinting at the disruptive ripple effects of
ransomware that spread beyond organizational and sector boundaries.
2
Behind the Rise of Ransomware, Atlantic Council, 2022. [Link]
issue-brief/behind-the-rise-of-ransomware
9
THE CYENTIA INSTITUTE
Headlines routinely feature the ravages of ransomware on Manufacturing production lines and Healthcare
providers, so it’s not surprising to see those industries high on the list in Figure 4. Retail/Trade (a combo of
Retail and Wholesale Trade sectors in NAICS) rounds out the top five sectors most frequently affected by
ransomware incidents.
Education 1,548
Professional 1,480
Manufacturing 1,248
Healthcare 1,194
Retail/Trade 1,102
Financial 631
Administrative 551
Public 523
Information 339
Transportation 299
Real Estate 228
Management 209
Hospitality 138
Entertainment 126
Agriculture/Mining 105
Utilities 72
If we examine the share of all cyber events classified as ransomware in each sector, a different picture emerges
from Figure 5. The previously second-ranked Professional sector drops to the middle of the pack, Utilities
jumps from last place into the top six, and healthcare plummets to the bottom three. Ransomware claims the
highest proportion of security incidents for the Manufacturing, Agriculture/Mining, and Management sectors,
echoing the supply chain theme that we’re well familiar with from ransomware headlines.
Manufacturing 51%
Agriculture/Mining 51%
Management 50%
Education 50%
Transportation 43%
Utilities 42%
Real Estate 42%
Retail/Trade 39%
Professional 35%
Hospitality 31%
Administrative 30%
Entertainment 30%
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
Information 23%
Healthcare 22%
Public 21%
Financial 16%
10
THE CYENTIA INSTITUTE
We can also apply this same analysis to organizations of different sizes based on annual revenue.
Doing so reveals that ransomware accounts
for less than 10% of all incidents experienced Ransomware disproportionately
by the largest $100B+ enterprises. But among affects small businesses, with
<$100M companies, that ratio jumps into the incidents comprising 30% to
30% to 40% range! In case you didn’t know it 40% of all security breaches in
already, ransomware presents big problems companies earning less than
for small businesses. $100M annually.
From this, it’s obvious that ransomware gangs have no interest in playing fair. To help level the playing field,
the Institute for Security + Technology created a Blueprint3 for building ransomware defenses in small and
medium-sized businesses. CISA also has a hub of resources focused specifically on helping small businesses
meet cybersecurity challenges.
Over the last 5 years 93% of Our dataset contains the names of victim
organizations, enabling us to determine how
affected firms experienced a
many ransomware incidents they have on the
single ransomware event.
public record. We give that breakdown in Figure
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
thankfully, very few suffered more than that. Good to know, but it’s still a ways away from the probability-
based questions we ultimately want to answer.
3
Blueprint for Ransomware Defense, Institute for Security + Technology, 2022. [Link]
[Link]
4
Only firms with at least one publicly known ransomware event are in our dataset. There is no explicit, confirmed record of firms with zero
events.
11
THE CYENTIA INSTITUTE
$100M to $1B 0.16653069 0.9294919 upper and lower bound approaches. For
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
5
We tested different distributions for each revenue group and selected the best fit. For most, the Poisson log-normal or negative binomial
provided the best results.
6
Specifically, Kolmogorov-Smirnov and Cramér-von Mises tests.
12
THE CYENTIA INSTITUTE
The reference to upper and lower bound in Table 2 demands an explanation. In a nutshell, the
difference between these stems from the count of “all organizations” used as the denominator for
the calculation. The dataset records how many firms had a ransomware event, but we don’t know
how many didn’t have one. So we developed two ways of approximating this, one that yields high
estimates (upper bound) and one that gives a lower bound. These are described in more detail in
Appendix B. For now, just know that the upper bound gives a more risk-averse view that we believe is
generally better suited to managing risk.
According to the upper bound estimate in Figure 8, there’s about a 10% chance that any given organization will
experience at least one ransomware incident in the next 12 months. That works out to getting hit once every 10
years. Now we’re much closer to being able to answer that “how likely” question.
0.00111%
3 While we don’t modify event
frequency estimates by security
0.0199% posture, we can rightsize the
2 output to be more in line with
organizations similar to yours.
0.465% Prior research in the IRIS series
1
shows that incident frequency
Model 99.5% differs substantially by firm
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
7
We decided not to develop a model for organizations under $10M in revenue because of insufficient data coverage and model reliability.
Anytime we show stats for loss event frequency, they refer to organizations over $10M in revenue.
13
THE CYENTIA INSTITUTE
When reviewing Table 3, the first thing that jumped out to us is the relatively low variation among the different
revenue tiers for having a single event (at least for the upper bound). Companies from $100M to $100B are
pretty much all equally likely to be hit by ransomware. Interestingly, the smallest (<$100M) and largest
($100B+) organizations exhibit somewhat elevated probabilities that are surprisingly similar. To put that in
perspective, the IRIS 2022 showed a roughly 250% difference in likelihood between those groups across all
types of security incidents.
We attribute this to the nature of ransomware and the criminals behind it. Ransomware gangs are known
to tailor their demands to fit the pocketbooks of the victim organization. Combine that with highly scalable
distribution mechanisms, and ransomware is a threat that cybercriminals can adapt to any target irrespective
of size. Table 3 suggests they’re doing that well.
This pattern
The likelihood of experiencing multiple ransomware shifts when
incidents escalates significantly with an organizations comparing
size, underscoring a drastic vulnerability among probabilities
$100B+ corporations, which are 35 times more at risk for more
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
14
THE CYENTIA INSTITUTE
After reading this section, some may be thinking something like “These numbers are way too low—we see
a lot more ransomware than that!” First, it’s entirely possible that these numbers are low relative to your
organization’s frequency of ransomware incidents. But it’s also possible you’re comparing apples and
oranges.
12.8%
12.6%
If by “see,” you’re referring to ransomware attacks 12.5%
Figure 9 will cause some to wonder what’s behind the mid-year rise and subsequent drop in that rate, but
digging into such things is not our purpose here. Suffice it to say that attack frequency will fluctuate based
on adversary campaigns, capabilities, and myriad other shifts across the threat landscape8.
8
Fortinet’s Outbreak Alerts offer information on trending ransomware (or other) campaigns.
15
THE CYENTIA INSTITUTE
Ransomware
Losses
“Boy that escalated quickly.”
~Ron Burgundy, Anchorman
Now that we know how often ransomware events occur, it’s time to evaluate
how much they cost. There’s been quite a bit of information shared on ransom
demands, but that’s only part of the total impact to organizations hit by these
incidents. We’ll start with observed losses from our historical dataset and then
fit a distribution to those values to support ransomware risk models.
While reading this section, keep in mind that not all losses for
all incidents become public. Certain types of losses are easier
to identify from public records, such as class action suits and
SEC Filings. Other forms of loss get absorbed internally with no
outward expenditures and/or are simply difficult to quantify.
We suspect the losses from major ransomware events are more
complete than other types of incidents due to their disruptive
and often public nature. Thus, we hold that our recorded losses
suitably reflect known financial losses from publicly visible
ransomware incidents.
may change that. For now, we’ll have to work with what’s come to light about
the impact of prior events. Thankfully, we have enough of those to establish a
range of historical financial losses triggered by ransomware incidents.
16
THE CYENTIA INSTITUTE
Inflation-adjusted ransomware losses are shown in red in Figure 10 amid those recorded across all other
types of incidents for comparison (in gray). Even on a log scale that diminishes the apparent length of the tail,
it’s easy to see that ransomware losses cluster toward the upper end of the range. The annotated statistics
reinforce that point.
Ransomware
Non-ransomware
17
THE CYENTIA INSTITUTE
LOSSES BY
SECTOR AND SIZE
We’d be remiss if we didn’t provide some analysis of how ransomware impacts different types of organizations.
As was done with frequency, we’ll start with a comparison across industries. Figure 13 tees that up with
ransomware’s share of reported losses across all cyber events in each sector.9
Transportation 84%
Education 79%
Manufacturing 79%
Hospitality 73%
Healthcare 63%
Management 40%
Retail/Trade 40%
Administrative 32%
Information 19%
Public 14%
Professional 10%
Financial 4%
Figure 13: Percentage of all reported cyber losses from ransomware events by sector
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
18
THE CYENTIA INSTITUTE
It shows that ~80% of all known losses from all security incidents in the Transportation, Education, and
Manufacturing sectors come from ransomware. Furthermore, ransomware claims roughly two-thirds of all
costs recorded for the Hospitality and Healthcare industries. On the flip side, only a small proportion of all
reported cyber losses for the Professional and Finance sectors is attributed to ransomware.
Losses
Transportation
80% Education
Manufacturing
Hospitality
Healthcare
60%
Management
40%
Retail/Trade
Administrative
20% Information
Public
Professional
Financial
0% 20% 40% 60% 80%
Events
Figure 14: Percentage of cyber events and losses tied to ransomware by sector
If you’re like us, you’re now tempted to scroll up to see how these industries stack up in terms of event
frequency. We’ll save you (and us) the effort. Figure 14 plots each sector according to the share of events and
losses over the last five years attributed to ransomware.
If frequency and losses were perfectly correlated, sectors would lie on or near the dashed line. In general,
that’s not the pattern we see here. Instead, we see industries that are very disproportionately impacted by
ransomware relative to event frequency (e.g., Healthcare, Hospitality), while the opposite is true for others
(e.g., Financial, Professional). A myriad of factors contribute to the placement of sectors in Figure 14, but
the targeting strategy of ransomware gangs is likely a major driver among them.
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
19
THE CYENTIA INSTITUTE
Figure 15: Percentage of all reported cyber losses from ransomware events by organization revenue
Ransomware Loss
Exceedance
Given what we’ve learned thus far about ransomware frequency and losses, is it possible to answer questions
like “What’s the probability that we’ll lose $10M or more over the next year from ransomware incidents?” Yes,
it is!
One way of answering such questions is to create an exceedance probability curve (EP Curve), more
commonly known as a loss exceedance curve (LEC) among cyber risk professionals. The purpose of LECs is to
demonstrate the probability of experiencing a minimum amount of loss in a given time period. This can be
very useful for supporting risk decisions and mitigations.
11%
9.2% chance of
10% $100K or greater loss
9%
8%
6.1% chance of
7% $1M or greater loss
6%
5%
4%
2.3% chance of
3% $10M or greater loss
2%
1%
0%
$1K $10K $100K $1M $10M $100M $1B $10B
Total yearly loss
Figure 17: Ransomware Loss Exceedance Curve
Figure 17 presents the results from a simulation of frequency and loss data to produce a ransomware LEC
for a typical organization. Trace any point on the curve to the x and y intercepts to determine exposure. For
example, there’s a 2.3% chance that a firm’s ransomware-related losses will exceed $10M in a year.
We emphasize “typical” in the preceding paragraph to remind readers that this LEC represents a composite
view across numerous firms of various types, sizes, and security postures. A LEC for your organization or its
peers would certainly look different.
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
21
THE CYENTIA INSTITUTE
As mentioned previously, verifiable financial losses are recorded for only a subset of the more than 14,000
ransomware incidents in our dataset. Adding up only those known losses would be trivial but would vastly
underestimate ransomware’s total impact over the last five years. So, we won’t even put that number out into
the eternal memory of the internet. But still—it sure would be nice to have such a number, huh?
We think so too, which is why we’re going to break our tradition of sticking rigidly to hard data on prior events.
But don’t worry—we’re not going to abandon our core principles and ride the trolley into the Neighborhood
of Make-Believe. We won’t force the data anywhere it doesn’t lead.
There’s no strong reason to believe that the ransomware incidents for which we have recorded losses are
significantly different than those for which we do not10. That means it is reasonable to apply the distribution
of known losses to the events for which we have no known losses. Note that this doesn’t mean simply adding
the average loss or always assuming the worst case. It means properly sampling estimated values based on
the distribution parameters—standard stats stuff.
Figure 18: Projected total cost of ransomware events based on known losses
Though some of the most common ransomware strains in our incident dataset do tend to be those with higher ransom demands (e.g.,
10
Clop). It’s possible the costlier strains are overrepresented in our dataset, which would create an upward bias for our total loss estimates.
Analysis of ransomware strains follows later in this report.
22
THE CYENTIA INSTITUTE
Using this method, we calculate the total financial losses from publicly known ransomware incidents over
the last five years to be about $276B dollars. We suspect that that estimate will be perceived by some as
outrageously high and scandalously low by others. The lack of consensus is understandable; it’s difficult to
find a comparable statistic to determine how this estimate aligns (or not) with that of other sources.
Figure 19 breaks down that five-year total on an annual basis and stretches back another five years before that.
This supplies the astounding observation that the total estimated losses from ransomware events increased
around 140X over the last 10 years! 2018, 2020, and 2021 stand out in terms of major leaps in aggregate loss.
While not quite the high-water mark set in 2021, ransomware’s projected impact for 2023 stands at almost
$95B (a figure we expect to climb still higher as new data emerges).
$100B
$124.4B $79.5B $94.6B
$68.5B $44.6B
$3.4B $5.3B
$1.4B $1.5B
$669.0M $681.4M $750.4M $659.3M $442.6M
$225.9M $366.2M
$100M
$49.7M
$14.8M $21.5M
$6.6M
$100K
$100
2014 2015 2016 2017 2018 2019 2020 2021 2022 2023
Figure 19: Annual projected total cost of ransomware events based on known losses
As large as these projections are, they likely represent a conservative estimate from a geographic standpoint.
The dataset on which we’re basing that projection is global, but coverage is most comprehensive for incidents
involving organizations with a presence in the United States. Plus, the losses reported for those events tend
to be the direct financial costs that often don’t capture the full extent of impact on the affected organization.
Caveats aside, however, the overall takeaway still stands. Ransomware is a major financial drain on industry
and the overall economy.
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
23
THE CYENTIA INSTITUTE
Ransomware Campaigns
& TTPs
“If you find yourself in a fair fight, your tactics suck.”
John Steinbeck (we imagine this posted prominently in cybercriminal of f ice breakrooms)
Aside from focusing exclusively on ransomware, everything we’ve served up to this point has been standard
“bread and butter” IRIS fare. A great deal of far more technical analysis exists out there regarding the actors
behind ransomware, the most prevalent variants, and the common tactics, techniques, and procedures
(TTPs) they employ. Much of that is deeper than we care to go for our risk-oriented purposes, but we would
like to at least create a bridge to that domain for those who want to cross over to it.
• Most prevalent ransomware strains from our core dataset and Ransomwatch
First, check the timeframe before you start analyst-splaining about how some of the ransomware gangs in
scope here are now defunct. This list is based on incidents that occurred from 2019–2023 and contains a mix
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
of gangs and strains. Some are no longer active and some have become more/less active over time.
Second, remember the nature of the dataset. It’s based on events impacting individual organizations. Not
campaigns, malware detections, number of variants, ransom payments, or even simple infections that were
handled internally. These led to real incidents that, for one reason or another, became publicly known.
24
THE CYENTIA INSTITUTE
Third, keep in mind that many factors contribute to the prevalence of ransomware shown here. For example,
the dominance of the Cl0P (aka CLOP, TA505) ransomware gang is largely due to its exploitation of the
infamous “MOVEit” vulnerability in 2023. Such attacks are far more scalable to a large population than more
targeted/bespoke campaigns.
cl0p 1,840
lockbit 3.0 978
conti 711
alphv/blackcat 573
lockbit 529
revil/sodinokibi 353
blackbasta 303
lockbit 2.0 301
maze 269
play 231
doppelpaymer 214
egregor 199
pysa 196
avaddon 188
royal 178
vice society 174
netwalker 169
bianlian 159
hive 152
wannacry 150
To offer a more temporal perspective on ransomware strains, we’ll turn to Ransomwatch. This project trails
the extortion sites used by ransomware groups and surfaces an aggregated feed of claims (as in claiming
responsibility; not insurance claims). This makes it an inherently more timely accounting of ransomware
activity than our core incident dataset.
200
150
100
lockbit 3.0
50
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
conti
cl0p alphv/blackcat
play
blackbasta
Oct Jan Apr Jul Oct Jan Apr Jul Oct
2021 2022 2022 2022 2022 2023 2023 2023 2023
25
THE CYENTIA INSTITUTE
Figure 21 trends the activity associated with the top ransomware from Figure 20 through the lens of
Ransomwatch. Here, we see the death of LockBit 2.0, the reincarnation of LockBit 3.0, the 2023 exploits of
Cl0P, etc. Again, we won’t go into details on these campaigns in this report, but you’re more than welcome
(even encouraged!) to do some homework.
Unfortunately, public disclosures or media coverage of security incidents rarely come with a detailed list of the
ATT&CK techniques involved. Evidence collected via a digital forensics investigation is generally needed for
that. However, through a combination of analytical techniques, we’ve managed to do some level of ATT&CK-
ification on over 40% of the ransomware events in our dataset.
We’ve organized identified techniques into three key stages of an incident: initial access, post-compromise
(execution through lateral movement), and exfiltration and impact. In this section, we’ll present the most
frequent and impactful techniques for each of these stages.
INITIAL ACCESS
The Initial Access tactic describes techniques used by adversaries to gain an initial foothold within a target
victim environment. Of all techniques in ATT&CK, these are probably the most familiar (who hasn’t heard of
phishing?). Nevertheless, it’s important to understand these trends because repulsing attacks at this stage
avoids the many problems and costs that ensue once they gain access.
22. But the former typically External Remote Services (T1133) 18% $22.1M
parties occur less often but Supply Chain Compromise (T1195) 0.14% $494.2K
punch well above their weight Figure 22: Relative frequency and losses for observed initial access techniques
in terms of average impact. This is
one of the few lists we’ve seen where the exploitation of valid accounts isn’t near the top of the list, though it
does round out third place in the losses column.
26
THE CYENTIA INSTITUTE
POST-COMPROMISE
Let’s go beyond the initial
Post-Compromise
Frequency Typical Loss intrusion and take a look at the
Command and Scripting Interpreter (T1059) 88% $49.4M TTPs utilized by adversaries to
Impair Defenses (T1562) 71% $47.2M
maintain presence, escalate
privileges, spread across
File and Directory Discovery (T1083) 67% $47.0M
the internal network, evade
Obfuscated Files or Information (T1027) 64% $46.9M
security defenses, establish
Deobfuscate/Decode Files or Information (T1140) 64% $46.4M
command and control
Native API (T1106) 63% $46.2M channels, and other nefarious
Process Discovery (T1057) 59% $46.2M activities. Figure 23 provides
Network Share Discovery (T1135) 53% $45.7M a breakdown of the top post-
System Binary Proxy Execution (T1218) 47% $45.5M compromise techniques we
System Location Discovery (T1614) 46% $44.6M were able to identify.
Figure 23: Relative frequency and losses for observed post-compromise techniques
Compared with the initial access group, there’s decidedly less variation in frequency and losses among the top
10 post-compromise techniques. This is largely because many of the major ransomware groups incorporate
many of the same basic functions, being derived from or patterned after successful strains that came before.
All these techniques won’t necessarily be used in every incident, but the capabilities are there when needed.
behind ransomware schemes are Inhibit System Recovery (T1490) 88% $46.4M
no different. While some stick to Service Stop (T1489) 76% $46.3M
the classic playbook of infect > Exfiltration Over Web Service (T1567) 17% $3.9M
encrypt > extort, others prefer to Defacement (T1491) 14% $2.6M
siphon off data for double/triple
System Shutdown/Reboot (T1529) 10% $2.3M
extortion or disrupt the entire
Transfer Data to Cloud Account (T1537) 9% $1.2M
network. Whatever their ends,
Automated Exfiltration (T1020) 9% $1.1M
the means are captured under
ATT&CK’s exfiltration and impact Exfiltration Over C2 Channel (T1041) 8% $1.1M
In an unforeseen twist, the most common impact associated with ransomware is . . . encryption. We’re obviously
kidding; it goes without saying. The two biggies beyond that both seek to undermine the defensive services and
recovery capabilities of the infected system so ransomware can sink its hooks deep. The presence of several
data exfiltration and transfer techniques reflects the popularity of double/triple extortion schemes.
27
THE CYENTIA INSTITUTE
Figure 25 ranks the top ATT&CK techniques attributed to ransomware campaigns over the last
four years. We’ve removed T1486 (Data Encrypted for Impact) since it’s pretty much a given for
ransomware and always on top.
Beyond encryption capabilities, T1059 (Valid Accounts) is the undisputed champion among
ransomware techniques, according to OSINT. That’s noticeably different from what we see in
Figure 22 and a good reminder of the value of using multiple sources for this kind of analysis.
Speaking of, see our report Multi-Source Analysis of Top MITRE ATT&CK Techniques for an in-
depth review of observed TTPs from 20+ sources.
We find it interesting how techniques appear to consolidate over time in Figure 25. That
timeframe roughly overlaps the “professionalism of ransomware phase from way back in
Figure 3. It seems to tell a story of ransomware gangs honing what works and incorporating or
purchasing successful capabilities for their own campaigns.
Figure 25: Ranking of ATT&CK techniques over time based on adversary campaigns tracked by Tidal Cyber
28
THE CYENTIA INSTITUTE
Conclusion
A principal aim of this IRIS report is to bring data and sound analysis to
bear on organizations' cyber risk questions. To that end, insights from this
special edition on ransomware support the following observations:
Without accounting for the (potentially large) effect of one's sector, cyber
risk managers should start their cost-benefit analysis around preventing
and mitigating ransomware at a 1-in-10 chance of experiencing at least
$100K in losses from ransomware over the next year and a 1-in-20 chance of
experiencing at least 10x that.
29
THE CYENTIA INSTITUTE
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
30
THE CYENTIA INSTITUTE
Appendix A: Incident
Pattern Descriptions
All security incidents in our historical dataset are assigned one of these mutually exclusive patterns using a
combination of natural language processing techniques and human expert assessment.
DOS ATTACK: Any attack intended to render online systems, applications, or networks
unavailable, typically by consuming processing or bandwidth resources.
SCAM OR FRAUD: Any incident that primarily employs various forms of deception to
defraud the victim of money, property, identity, information, and so on.
PHYSICAL THREATS: Threats that occur via a physical vector, such as device tampering,
snooping, theft, loss, sabotage, and assault.
RANSOMWARE: A broad family of malware that seeks to encrypt data with the promise to
unlock upon payment or seeks to completely eradicate data/systems without the pretense
R ANSOMWARE
of collecting payment.
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
SYSTEM FAILURE: All unintentional service disruptions resulting from system, application,
or network malfunctions or environmental hazards.
31
THE CYENTIA INSTITUTE
LOWER BOUND: This includes all registered organizations in the United States
according to Dun & Bradstreet (because we don’t have numbers for the whole
world). This assumes that incident frequency among the U.S. firms is similar to
that ever y where else, which is cer tainly not the case. But it’s a good star ting
point, even if you don’t work for a U.S. firm. We call this the lower bound
because it assumes that all registered firms engage in activities that subject
them equally to the kinds of incidents found in this dataset. We don’t believe
that to be the case.
UPPER BOUND: This includes all organizations recorded in our dataset, which
means these organizations have experienced a known incident at some point
in the past. While that’s clearly not the case for all organizations, this upper
bound approach is based on the premise that not all firms are equally subject
to the kinds of incidents contained in this dataset (i.e., perhaps they don’t use
IT or aren’t subject to incident disclosure regulations). This assumes that all
firms prone to incidents have already had one incident, thus likely resulting in
overestimation.
The “just right” (Goldilocks) zone is, of course, somewhere in the middle. It’s impossible for us to know exactly
where your organization falls between the lower and upper bounds, so we’ve opted to share both to support
your assessment. In general, the upper-bound offers a more risk-averse view with higher values. Choose one or
fuse both to suit your organization’s risk posture and tolerance.
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
32
THE CYENTIA INSTITUTE
Number of events
0.647% 0.524%
2
10.5% 9.29%
1
0.581% 0.739%
2
8.91% 9.02%
1
0.464%
3
1.82%
2
10.4%
1
Figure B1: Upper bound model for annual ransomware event frequency by revenue category
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
33
THE CYENTIA INSTITUTE
Number of events
0.0115% 0.0477%
2
0.318% 1.16%
1
0.147% 0.382%
2
2.51% 4.18%
1
0.585%
3
1.79%
2
6.77%
1
R ANSOMWARE
I N F O R M AT I O N R I S K I N S I G H T S S T U DY
34