The latest data from Sophos, a cybersecurity solutions provider, show a staggering 500% increase in average ransom payments over the past year.
According to the “State of Ransomware 2024” survey, organizations grappling with cyber extortion reported an average ransom payment of $2 million, a significant leap from $400,000 in 2023. The cost of recovery, excluding ransoms, has also skyrocketed, reaching $2.73 million on average, marking an alarming uptick from $1.82 million reported the previous year.
Despite a slight reduction in the frequency of ransomware attacks, with 59% of organizations affected compared to 66% in 2023, the threats remain prevalent. Even smaller entities, generating less than $10 million in revenue, aren’t spared, with 47% experiencing ransomware incidents in the past year.
“We must not let the slight dip in attack rates give us a sense of complacency,” said John Shier, field CTO, Sophos. “Ransomware attacks are still the most dominant threat today and are fueling the cybercrime economy.”
The report also reported on ransom demands, with a whopping 63% exceeding $1 million and 30% surpassing $5 million. Nearly half (46%) of organizations with revenue below $50 million faced seven-figure ransom demand.
Higher rates of backup compromise
“The skyrocketing costs of ransomware attacks belie the fact that this is an equal opportunity crime,” Shier said. “The ransomware landscape offers something for every cybercriminal, regardless of skill. While some groups are focused on multi-million-dollar ransoms, others settle for lower sums by making it up in volume.”
Organizations hit by attacks originating from exploited vulnerabilities reported more severe consequences, including higher rates of backup compromise, data encryption, and propensity to pay the ransom.
The report underscores the challenges in dealing with ransom demands, revealing that less than a quarter (24%) pay the full amount initially requested. Also, 94% of organizations faced attempts to compromise their backups during attacks, indicating the need for robust defensive measures.
Sophos recommends proactive steps, including understanding risk profiles, implementing robust endpoint protection, and maintaining comprehensive incident response plans. The findings, based on a survey of 5,000 cybersecurity/IT leaders across 14 countries, underscore the urgent need for organizations to fortify their defenses against evolving cyber threats.