Security Experts:

Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Ransomware Took Heavy Toll on US in 2020: Researchers

Ransomware attacks took a heavy toll on the United States last year with more than 2,000 victims in government, education and health care, security researchers say in a new report.

Ransomware attacks took a heavy toll on the United States last year with more than 2,000 victims in government, education and health care, security researchers say in a new report.

The study released Monday by the security firm Emsisoft said ransomware attacks — which encrypt and disable computer systems while demanding a ransom — affected 113 federal, state and municipal governments, 560 health facilities and 1,681 schools, colleges and universities last year.

“The attacks caused significant, and sometimes life-threatening, disruption: ambulances carrying emergency patients had to be redirected, cancer treatments were delayed, lab test results were inaccessible, hospital employees were furloughed and 911 (emergency) services were interrupted,” the report said.

The security firm said it was unable to estimate the losses from the attacks due to a lack of data but that it was “safe to assume that the total cost runs to multiple billions.”

The numbers of attacks were little changed from 2019 but there were “more successful attacks on the healthcare sector,” including incidents affecting groups with multiple hospitals, according to Emsisoft spokesman Brett Callow.

Similarly, Callow said, “the education sector saw a similar number of attacks, but more schools were affected due to bigger districts” hit.

The targets included large regional cities and municipalities, major hospital systems and large colleges and universities, according to Emsisoft.

The researchers said hackers are stepping up by not only encrypting but stealing data which may be sold to competing firms or various governments.

“We anticipate there will be more cases of data theft in 2021 than there were in 2020,” the report said. “Like legitimate businesses, criminal enterprises adopt strategies that are proven to work, and data theft has indeed been proven to work. “

Emsisoft’s chief technical officer Fabian Wosar said much of the risk from ransomware can be eliminated with preventive steps.

“Proper levels of investment in people, processes and IT would result in significantly fewer ransomware incidents and those incidents which did occur would be less severe, less disruptive and less costly,” he said in a statement.

RelatedU.S. Hospitals Warned of Imminent Ransomware Attacks From Russia

Related: University Project Tracks Ransomware Attacks on Critical Infrastructure

Written By

AFP 2023

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this webinar to learn best practices that organizations can use to improve both their resilience to new threats and their response times to incidents.

Register

Join this live webinar as we explore the potential security threats that can arise when third parties are granted access to a sensitive data or systems.

Register

Expert Insights

Related Content

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.

Cybercrime

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Application Security

PayPal is alerting roughly 35,000 individuals that their accounts have been targeted in a credential stuffing campaign.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

No one combatting cybercrime knows everything, but everyone in the battle has some intelligence to contribute to the larger knowledge base.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...