Despite the increasing efforts of law enforcement and investigators, ransomware remains one of the most dangerous threats on the Internet. The number of victims continues to increase, and new gangs appear to have strong incentives to achieve their malicious goals. A recent report released by NCC Group revealed that September saw a record number of ransomware operations.

The company's latest "Monthly Cyber ​​Threat Intelligence Report" focuses on new trends in the threat landscape, particularly ransomware attacks and cybercriminal groups engaged in sophisticated digital extortion campaigns.

In September 2023, ransomware groups carried out 514 attacks, a 32% increase compared to the previous month. While August 2023 was a relatively quiet month for ransomware, the number of attacks still exceeded typical summer rates. Ransomware incidents increased by 153% compared to 2022.

In the NCC Group's previous "Threat Pulse" report, it was estimated that we could see a total of 4,000 attacks by the end of the year. New reports show that the number of ransomware incidents has reached 3,500 and is likely to exceed 4,000 before 2024.

(Global ransomware attacks by month in 2022-2023)

The top five most active groups involved in ransomware threats in September 2023 are all new actors. According to NCC Group, this shows that these new cybercriminals are eager to start their malicious activities "with a bang". Record-breaking ransomware members include LockBit3.0 (79 attacks), LostTrust (53), BlackCat (47) and RansomedVC (44).

RansomedVC is a newly established cybercriminal organization that began to appear in underground forums in August 2023. The man behind RansomedVC calls himself a "penetration tester" and has launched a novel extortion tactic, spinning reports around GDPR fines related to network vulnerabilities.

According to NCC Group’s assessment, RansomedVC’s operations are still relatively new, which means that information about the organization is very limited. The underground forum was launched in early August and is supervised by two administrators named "Admin" and "Yuna". They implemented a credit system to incentivize members to leak undisclosed data. It is worth noting that RansomedVC is the group that claimed responsibility for the September breach of all Sony networks.

The NCCGroup report also highlights the industries most targeted in ransomware incidents, with "industrial" (construction, engineering, services) accounting for 40% of all attacks, followed by consumer cycles (retail, media, hospitality) at 18% and technology at 10%.