IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Ransomware activity falls 25% in Q1 2022

The drop in ransomware has been attributed to larger ransomware gangs being less active compared to the end of 2021

The number of ransomware attacks dropped significantly during the first quarter of 2022, according to new research published this week.

Ransomware is still one of the biggest cyber security threats businesses are facing, but the number of organisations named in ransomware attacks has fallen 25.3% compared to Q4 2021.

A total of 582 organisations were named by ransomware groups on their sites this quarter, according to Digital Shadows, which conducted the research.

The security company said the decrease in activity can be attributed, in part, to a less prominent threat of larger ransomware groups so far this year.

Conti, one of the most prolific ransomware groups of recent years, was found to have claimed 31.8% fewer victims compared to the previous quarter. The PYSA group has so far listed no new corporate victims in 2022.

The same can’t be said for the operators of LockBit 2.0, though. The group has been highly active this year, claiming the majority of ransomware victims, Digital Shadows said.

Graph showing success of different ransomware gangs during Q1 2022

Digital Shadows

Conti is still the second-most active group of the year, according to the security company’s data, with both it and LockBit 2.0 accounting for more than half of all ransomware success so far this year.

Ransomware groups have also changed their strategy in recent months, as the national security agencies of the US, UK, and Australia have noted.

Cyber criminals are shifting away from the ‘big game hunting’ approach to ransomware after the double extortion model became popularised with attacks on larger businesses in 2020.

Ransomware groups are now shifting their focus to medium-sized companies after a string of high-profile attacks throughout 2021 led to heightened international pressure to disrupt and unearth ransomware groups like REvil, which was behind the supply chain attack on Kaseya.

Despite the first quarter of 2021 showing signs of a slower ransomware market, cyber criminals have been hard at work in other areas.

Conti’s lack of action could have been affected by a Ukrainian security researcher leaking the group’s tools and internal communications in retaliation for the group’s public support of Russia’s invasion of Ukraine.

The invasion has also spurred cyber attackers from across the world to help support the fight against Russia in cyber space. Distributed denial of service (DDoS) attacks are among the most common types of cyber attacks being launched against Russia, at the command of Ukraine’s IT Army.

Anonymous has also claimed to have successfully executed a number of attacks against Russia since the war started, including injecting footage from inside Ukraine to Russian television streams.

The LAPSUS$ hackers were among the most prominent cyber criminals of the year so far and were at first confused with a ransomware gang, but later analysis of its attacks showed the group operated on a pure extortion model.

Featured Resources

Activation playbook: Deliver data that powers impactful, game-changing campaigns

Bringing together data and technology to drive better business outcomes

Free Download

In unpredictable times, a data strategy is key

Data processes are crucial to guide decisions and drive business growth

Free Download

Achieving resiliency with Everything-as-a-Service (XAAS)

Transforming the enterprise IT landscape

Free Download

What is contextual analytics?

Creating more customer value in HR software applications

Free Download

Recommended

Darktrace AI’s Antigena helps stop ransomware attack at Dordogne GHT
ransomware

Darktrace AI’s Antigena helps stop ransomware attack at Dordogne GHT

13 Apr 2022
Sabbath hackers are targeting US schools and hospitals
ransomware

Sabbath hackers are targeting US schools and hospitals

29 Nov 2021
Out-of-hours ransomware attacks have a greater impact on revenue
ransomware

Out-of-hours ransomware attacks have a greater impact on revenue

18 Nov 2021
US and Israel join forces to fight ransomware
ransomware

US and Israel join forces to fight ransomware

15 Nov 2021

Most Popular

16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

13 May 2022
Preparing for the 3G sunset
Network & Internet

Preparing for the 3G sunset

18 May 2022
(ISC)2 launches free scheme to get 100,000 UK citizens into cyber security
Careers & training

(ISC)2 launches free scheme to get 100,000 UK citizens into cyber security

17 May 2022