IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Ransomware hit industrial sector the hardest in the third quarter

Cyber criminals are now also targeting the technology sector, which saw a 30% rise in attack volume

Ransomware gangs hit the industrial sector the hardest during the third quarter of this year, according to a report by security company Digital Shadows.

The report named the industrial goods and services sector as the biggest target during the third quarter of this year, maintaining a position that it has held throughout 2021. The technology sector came second, followed by construction and materials, legal services, and financial services. 

The number of attacks on the industrial sector fell by 42% quarter-on-quarter, however, which the report attributes to diversification. Ransomware groups are now targeting more sectors, it said, adding that many of these attacks seem to be targeting the technology sector, which saw a 29.8% bump in attack volume. 

The busiest ransomware group was LockBit 2.0, first seen in July this year. It knocked Conti from the top spot, which it had retained for the first half of this year. LockBit 2.0 hit 203 victims, which was almost triple Conti's count for the third quarter. 

The report also highlighted the chaotic nature of the ransomware business. It cited several groups that had disappeared, with some reappearing later or rebranding. This includes REvil, which vanished from the dark web in July and then reappeared. The group's web site went dark again this month following a multinational effort by law enforcement. 

Related Resource

How to reduce the risk of phishing and ransomware

Top security concerns and tips for mitigation

Large letter 'O' against a background of a city - whitepaper from MimecastFree download

Digital Shadows noted the difficulty in using dark web sites, which are limited in speed. This has made it difficult for ransomware groups to leak large data files, causing some to rely instead on the regular web. 

The third quarter also saw the Colonial Pipeline attack by the DarkSide group, which was responsible for a ban on ransomware-related discussions from most cyber crime forums. There was also the REvil attack on managed services company Kaseya, and last month's hit on an Iowa farming cooperative. 

Even though the Colonial Pipeline attack had caused forums to ban ransomware discussions, there's always another criminal entrepreneur willing to step up. In this case, a new forum called RAMP, dedicated to ransomware, picked up the slack. Digital Shadows' report said it uses the same URL as the Babuk ransomware group's data leak site, and hosts a data leak site of its own called Groove.

Featured Resources

Four strategies for building a hybrid workplace that works

All indications are that the future of work is hybrid, if it's not here already

Free webinar

The digital marketer’s guide to contextual insights and trends

How to use contextual intelligence to uncover new insights and inform strategies

Free Download

Ransomware and Microsoft 365 for business

What you need to know about reducing ransomware risk

Free Download

Building a modern strategy for analytics and machine learning success

Turning into business value

Free Download

Recommended

Dell Technologies World 2022: Dell unveils fastest storage architecture in company history
Server & storage

Dell Technologies World 2022: Dell unveils fastest storage architecture in company history

4 May 2022
Dell Technologies World 2022: Dell unveils security offerings for major cloud providers
public cloud

Dell Technologies World 2022: Dell unveils security offerings for major cloud providers

3 May 2022
How do you become an ethical hacker?
ethical hacking

How do you become an ethical hacker?

29 Apr 2022
What is phishing?
phishing

What is phishing?

29 Apr 2022

Most Popular

Windows Server admins say latest Patch Tuesday broke authentication policies
Server & storage

Windows Server admins say latest Patch Tuesday broke authentication policies

12 May 2022
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

13 May 2022
How full-stack observability can accelerate IT innovation
Sponsored

How full-stack observability can accelerate IT innovation

3 May 2022