IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Report finds ransomware hitting manufacturers hardest

Several ransomware families prioritized the manufacturing sector in the last year

Wannacry ransomware screen on a desktop monitor

Manufacturing companies are the most likely targets of double-extortion ransomware attacks, according to a report from research team ThreatLabZ this week.

In a double-extortion attack, criminals not only encrypt data but steal it too, enabling them to blackmail victims into preventing its publication. ThreatLabZ, ZScaler's research team, noted that 12.7% of the companies affected by these attacks were in the manufacturing sector, followed by services companies. This stood out from a cluster of other sectors who each accounted for between 8 and 9% of attacks: services, transportation, retail, and technology. This report follows a previous study that found a 300% increase in cyber attacks on manufacturing organizations

ThreatLabZ identified seven ransomware families that stood out as sources of double-extortion attacks. The most common was Maze, which accounted for 273 attacks in the last year. Even though Maze ceased operations in November 2020, it still outpaced the Conti ransomware, which took second place with 190 attacks.

The Ragnar Locker ransomware, which sets up a virtual machine on its target machine, focused the most on the manufacturing sector, with 22% of its attacks hitting those companies. 

Doppelpaymer was also focused on manufacturing, targeting manufacturers in 15.1% of its incidents. 

Manufacturing was also Conti's top target, attracting 12.4% of its attacks, while Sodinokibi/REvil featured manufacturing and transportation equally as its top target sectors.

ThreatLabz also examined DarkSide, which is of particular interest this week after its use in the Colonial Pipeline attack. The group, which clarified its motives for hitting the pipeline this week, focused only 2.8% of its attacks on the oil and gas sector. Services was its go-to sector, accounting for 16.7% of attacks.

Anti-ransomware company Coveware highlighted a rise in double-extortion attacks in its most recent Q1 ransomware research, which reported that 77% of attacks now featured this tactic, up 10% from Q4 2020.

Featured Resources

Join the 90% of enterprises accelerating to the cloud

Business transformation through digital modernisation

Free Download

Delivering on demand: Momentum builds toward flexible IT

A modern digital workplace strategy

Free download

Modernise the workforce experience

Actionable insights and an optimised experience for both IT and end users

Free Download

The digital workplace roadmap

A leader's guide to strategy and success

Free Download

Recommended

Solve cyber resilience challenges with storage solutions
Whitepaper

Solve cyber resilience challenges with storage solutions

4 Jul 2022
Storage's role in addressing the challenges of ensuring cyber resilience
Whitepaper

Storage's role in addressing the challenges of ensuring cyber resilience

4 Jul 2022
Introducing IBM Security QRadar XDR
Whitepaper

Introducing IBM Security QRadar XDR

4 Jul 2022
The Total Economic Impact™ of IBM Security MaaS360 with Watson
Whitepaper

The Total Economic Impact™ of IBM Security MaaS360 with Watson

4 Jul 2022

Most Popular

Universities are fighting a cyber security war on multiple fronts
cyber security

Universities are fighting a cyber security war on multiple fronts

4 Jul 2022
Hackers claim to steal personal data of over a billion people in China
data breaches

Hackers claim to steal personal data of over a billion people in China

4 Jul 2022
Raspberry Pi launches next-gen Pico W microcontroller with networking support
Hardware

Raspberry Pi launches next-gen Pico W microcontroller with networking support

1 Jul 2022