Ransomware-as-a-Service Contacting victim’s customers Ransomware-as-a-service represents a rapidly developing threat. The NÚKIB has been recording ransomware attacks for a long time. Its victims span a wide range of public and private entities. Since the end of 2019, the trend of the ransomware-as-a-service model, unique for its use of manyfold extortion, began to prevail. In addition to the traditional encryption of data, additional layers of extortion may also include exfiltrating data and threats of publishing them, DDoS attacks to increase pressure on the victim, and contacting the victim’s customers and partners to further increase pressure on the victim to pay the ransom (see Figure 1). DDoS Data Exfiltration and publishing Data Encryption Figure 1: Four Levels of Ransomware Extortion (Source: the NÚKIB) In the Czech Republic, the NÚKIB recorded 27 cyber incidents caused by ransomware during 2022, with 15% of respondents reporting an attempted or successful ransomware attack. Ransomware, even in the form of a service, thus represented a continuing trend and threat to the security of domestic organizations in 2022. 17

Select target paragraph3