The threat of ransomware
Ransomware has become an increasingly prevalent
global threat, where cybercriminals use readily available
software to encrypt electronic devices, folders and files
that render systems inaccessible to users. Once files are
encrypted, criminals demand a ransom from the system
owner in return for the decryption keys, often in the form
of hard-to-trace cryptocurrencies. Not only do criminals
use ransomware to encrypt files, ransomware also allows
criminals to gain access to a network, enabling them to
steal sensitive information.
Australia’s relative wealth, high levels of online
connectivity and increasing delivery of services through
online channels make it very attractive and profitable for
transnational, organised cybercrime syndicates to target
Australians using cyber-enabled tools and techniques.
Consistent with global trends, the Australian Cyber
Security Centre has continued to observe cybercriminals
successfully use ransomware to disrupt operations and
cause reputational damage to Australian organisations,
and reported a 15% increase in ransomware attacks over
the past 12 months.
Globally, it is estimated that there is a ransomware attack
on a business every 11 seconds, with ransomware damage
losses projected to reach US$20 billion in 2021.1 Paying a
ransom does not guarantee recovery of ransomed data,
and only helps promote ransomware as a profitable
criminal enterprise.2 Ransomware and cyber extortion
remains the most serious cybercrime threat facing
Australia due to its high financial and disruptive impacts
to victims and the wider community.
This trend of data theft, encryption, and public shaming
reflects an evolution in ransomware tactics to more
effectively extort considerable ransoms from victims.
Cybercriminals are now regularly exfiltrating data,
including customer personally identifiable information (PII),
prior to encryption and subsequently threatening to release
the stolen information publicly unless the ransom is paid.
Victims who would have previously been well prepared for,
or able to, recover from a ransomware incident are unlikely
to be immune to this tactic known as ‘double extortion’.
Organisations are now required to evaluate the cost of
ransom payment against the potentially severe legal
and reputational consequences of a data breach.
Other extortion tactics observed in 2020 included
committing Distributed Denial of Service to force victims
to re-engage in ransom negotiations, directly contacting
senior employees (such as Chief Executive Officers or Chief
Financial Officers), alerting customers and/or the media to
inform them of imminent data leaks, and posting ransom
demands directly on victims’ publicly facing websites.
In the last 24 months, there has been an increase in
number of larger organisations experiencing ransomware.
This aligns with global trends and intelligence indicating
top tier and highly-skilled cybercriminal groups are moving
away from indiscriminately targeting large volumes of
small-scale victims and instead tailoring their ransomware
campaigns to specific million or billion dollar corporations
(referred to as ‘big game hunting’). Cybercriminals are
exploiting the need for such organisations to maintain
effective operation to increase ransom payment.
Globally, it is estimated that there is a ransomware attack on a business every
11 seconds, with ransomware damage losses projected to reach US$20 billion
in 2021.
1.
2.
2
Cybersecurity Ventures, 2021
Locked Out: Tackling Australia’s ransomware threat, Cyber Security Industry Advisory Committee, March 2021.
RANSOMWARE ACTION PLAN