 strides in developing American cyber talent, these investments have lacked the scale and coordination necessary to meet increasing demand. Top Trends of 2023 Evolving Risks to Critical Infrastructure U.S. critical infrastructure faces evolving and unacceptable cyber risks. Nation-state adversaries are developing cyber capabilities and gaining accesses with the intent of disrupting or destroying U.S. and allied critical infrastructure. Such disruptions could support or enable an adversary’s strategic objectives outside of the cyber domain and pose challenges for risk management within and across critical infrastructure sectors. While adversaries pre-positioning for cyberattacks is a long-standing threat, the PRC’s prepositioning activity is a threat unlike any America has previously faced. In 2023, a PRC actor tracked as Volt Typhoon gained access to critical infrastructure in the United States and the Indo-Pacific region. Critically, this campaign targeted U.S. entities that presented little value from an espionage or intelligence perspective, but which could enable disruption of operational technology systems in critical infrastructure and interference with U.S. and allied warfighting capabilities. Also in 2023, PRC actors tracked as BlackTech used sophisticated tools to compromise routers and gain access to a wide variety of U.S. and Japanese critical infrastructure. These intrusions demonstrated the PRC’s intention to hold at risk U.S. and allied critical infrastructure, shape U.S. decision-making in a time of crisis, and use cyber capabilities to augment PRC geopolitical objectives. Ransomware Ransomware remains a persistent threat to national security, public safety, and economic prosperity. Comprehensive data on the full scope of the ransomware threat is difficult to obtain, particularly with cyber incident reporting requirements still evolving and victims reluctant to share information about attacks. Following a brief decrease in 2022, the Federal Bureau of Investigation (FBI) Internet Crime Complaint Center (IC3) received a 22% increase in reported ransomware incidents from American victims. Reports to the IC3 also reflected a 74% increase in the cost of ransomware incidents in 2023, relative to 2022. Established ransomware groups are continuing to develop sophisticated strategies to monetize their accesses and evade or circumvent defensive measures designed to frustrate their activities. Attackers have increased the use of “double” and “triple extortion” attacks, not only encrypting victims’ data but also threatening to sell or publicly release that data if a ransom is not paid, and sometimes also threatening to dox victims if they do not pay an additional fee. Victims who make these additional ransomware payments rely on their attackers’ promise to delete exfiltrated data and refrain from doxing attacks, a promise that is not always kept. Ransomware actors form conspiracies with each other, dividing up the work of developing and deploying malware, carrying out attacks on individual targets, and collecting cryptocurrency ransoms. This form of criminal economic specialization has made the ransomware threat especially potent. 2024 REPORT ON THE CYBERSECURITY OF THE UNITED STATES POSTURE 5

Select target paragraph3