Learn more about Zscaler Advanced Cloud Sandbox and Zscaler Ransomware Protection.
Though cybercriminals have been using ransomware attacks for more than 30 years, there has been a significant uptick in recent years. According to the FBI, ransomware attacks started picking up in 2012, and show no sign of slowing.
In the past, ransomware attacks that locked down a user’s computer or files could be easily reversed by a trained professional. But in recent years, ransomware attacks have become more sophisticated and, in many cases, have left the victims with little choice but to pay the ransom or lose their data forever.
A 2020 ThreatLabz report showed an increase of more than 500% in ransomware delivered in encrypted channels between March and September. It is estimated that during the year 2020 alone, ransomware will have inflicted damages of more than $20 billion worldwide.
A recent and notable change in many ransomware family variants is the addition of a data exfiltration feature. This new feature allows cybercriminals to exfiltrate sensitive data from victim organizations before encrypting the data. This exfiltrated data is like an insurance policy for attackers: even if the victims have good backups, they’ll likely pay the ransom to avoid having their data exposed.
The most common targets for ransomware attacks in recent years have been municipal governments and academic institutions, but since the start of the COVID-19 pandemic, hospitals and remote workers have become a new focus for ransomware gangs. Furthermore, in the last year, reports of ransomware delivered through encrypted traffic have increased significantly.
Due to the capacity limitations of legacy security technologies, such as next-generation firewalls, most organizations do not have the ability to inspect all encrypted traffic. Attackers know this, so they are increasingly using encryption to hide their malicious links and attachments.
US Federal Bureau of Investigation (FBI)
Ransomware is most commonly spread by phishing emails and ads with infected links or a planted website embedded with malware. Phishing emails often appear as though they have been sent from a legitimate organization or someone known to the victim (in targeted attacks), tricking the user into clicking on a malicious link or opening a malicious attachment.
In ransomware attacks on an individual, documents, photos, and financial information are most commonly locked and held hostage. While individuals might be an easier target, corporations—especially larger organizations—are far more attractive. If attackers can get just one employee to download the malware, it can then spread from that user’s device onto the network, where the stakes are much higher. Not only can an attack disrupt business, but the threat of data loss or exposure could be devastating and costly in dollars and in company reputation.
While some organizations are investing in cybersecurity insurance to help cover costs in the event of a cyberattack or data breach, the best course of action when it comes to ransomware is prevention.
To protect your organization from ransomware, CISA, the Cybersecurity & Infrastructure Security Agency and the FBI recommend the following:
US Cybersecurity & Infrastructure Security Agency
Institute for Critical Infrastructure Technology
Modern ransomware defense technology is not only highly effective but also easy to deploy. Sufficient ransomware protection begins with adopting a security posture that’s natively built in the cloud to protect users, applications, and sensitive data from these attacks, regardless of where users connect or what devices they’re using.
To keep up with today’s most common ransomware threats, a prevention strategy must incorporate the following principles and tools to prevent these attacks from exposing your data, disrupting your business, or costing your organization time and money:
No company, large or small, is safe from ransomware without a dedicated security defense. Avoid becoming the next victim of ransomware, or the next organization in the news as a result of an attack.
Learn more about Zscaler Advanced Cloud Sandbox and Zscaler Ransomware Protection.
As research and headlines show, ransomware isn’t going anywhere. Zscaler has already helped thousands of customers prevent ransomware and countless other cyberattacks from reaching their networks with unparalleled scalability and superb user experiences.
Here are some further resources to consider as you refine your overall security strategy:
Ready to protect your organization from advanced ransomware? Learn more about Zscaler Ransomware Protection.
Zscaler ThreatLabz: Security Research
Read the blogsThreatLabz Research: 2021 State of Encrypted Attacks
Read the reportZero Trust Powers the World’s Most Effective Ransomware Protection
Learn moreHow to Protect Your Data from Ransomware and Double Extortion
Read the blog