The threat of ransomware Ransomware has become an increasingly prevalent global threat, where cybercriminals use readily available software to encrypt electronic devices, folders and files that render systems inaccessible to users. Once files are encrypted, criminals demand a ransom from the system owner in return for the decryption keys, often in the form of hard-to-trace cryptocurrencies. Not only do criminals use ransomware to encrypt files, ransomware also allows criminals to gain access to a network, enabling them to steal sensitive information. Australia’s relative wealth, high levels of online connectivity and increasing delivery of services through online channels make it very attractive and profitable for transnational, organised cybercrime syndicates to target Australians using cyber-enabled tools and techniques. Consistent with global trends, the Australian Cyber Security Centre has continued to observe cybercriminals successfully use ransomware to disrupt operations and cause reputational damage to Australian organisations, and reported a 15% increase in ransomware attacks over the past 12 months. Globally, it is estimated that there is a ransomware attack on a business every 11 seconds, with ransomware damage losses projected to reach US$20 billion in 2021.1 Paying a ransom does not guarantee recovery of ransomed data, and only helps promote ransomware as a profitable criminal enterprise.2 Ransomware and cyber extortion remains the most serious cybercrime threat facing Australia due to its high financial and disruptive impacts to victims and the wider community. This trend of data theft, encryption, and public shaming reflects an evolution in ransomware tactics to more effectively extort considerable ransoms from victims. Cybercriminals are now regularly exfiltrating data, including customer personally identifiable information (PII), prior to encryption and subsequently threatening to release the stolen information publicly unless the ransom is paid. Victims who would have previously been well prepared for, or able to, recover from a ransomware incident are unlikely to be immune to this tactic known as ‘double extortion’. Organisations are now required to evaluate the cost of ransom payment against the potentially severe legal and reputational consequences of a data breach. Other extortion tactics observed in 2020 included committing Distributed Denial of Service to force victims to re-engage in ransom negotiations, directly contacting senior employees (such as Chief Executive Officers or Chief Financial Officers), alerting customers and/or the media to inform them of imminent data leaks, and posting ransom demands directly on victims’ publicly facing websites. In the last 24 months, there has been an increase in number of larger organisations experiencing ransomware. This aligns with global trends and intelligence indicating top tier and highly-skilled cybercriminal groups are moving away from indiscriminately targeting large volumes of small-scale victims and instead tailoring their ransomware campaigns to specific million or billion dollar corporations (referred to as ‘big game hunting’). Cybercriminals are exploiting the need for such organisations to maintain effective operation to increase ransom payment. Globally, it is estimated that there is a ransomware attack on a business every 11 seconds, with ransomware damage losses projected to reach US$20 billion in 2021. 1. 2. 2 Cybersecurity Ventures, 2021 Locked Out: Tackling Australia’s ransomware threat, Cyber Security Industry Advisory Committee, March 2021. RANSOMWARE ACTION PLAN

Select target paragraph3