- The average ransom payment was $233,817 in the third quarter, up 31 percent from 2Q20.
- The median ransom payment was $110,532, up 2 percent from the prior quarter.
- 61 percent of ransomware victims reported annual revenues of less than $50 million.
- Sodinokibi (16.2 percent) was the most-prevalent ransomware during the quarter, followed by Maze (13.2 percent) and Netwalker (9.9 percent).
- Nearly half of all ransomware cases included the threat to release exfiltrated and encrypted data.
- Remote Desktop Protocol (RDP) compromise ranked first among ransomware attack vectors, followed by email phishing and software vulnerabilities.
- Professional services (25 percent) was the most-common industry targeted during ransomware attacks, followed by the public (12 percent) and healthcare (11 percent) sectors.
- Ransomware: Organizations must prepare for new ransomware strains that target remote workers.
- Coronavirus (COVID-19) Pandemic: Organizations must implement security controls to ensure employees can work safely during the pandemic and after it ends.
- Business Continuity: Organizations must use threat intelligence to stay ahead of cyberattacks and avoid data breaches that cause service interruptions and downtime.
- Threat Detection: Organizations must understand commonly cybercriminal tools and techniques and map out their security plans accordingly.
- Device Management: Organizations must regularly patch and test end-user devices and leverage technologies and tools to consistently manage them.