A payment security standards group
The Payment Card Industry Security Standards Council, formed by Visa, Mastercard and other major credit card companies in 2006, said Feb. 10 its ransomware bulletin was one of only two it would release this year. The National Cybersecurity Alliance joined the standards council in releasing the notice.
Lance Johnson, executive director of the PCI Security Standards Council, said that as working from home became commonplace during the pandemic, there has also been “a significant increase in ransomware attacks.” According to the bulletin, “cybercriminals see new opportunities due to the disruption created by the global COVID-19 pandemic.”
As to the kinds of entities at risk, Lisa Plaggemier, the executive director of the National Cybersecurity Alliance, said that all organizations, “large and small, public and private” face the threat of ransomware.
According to
The Fincen data comes from suspicious activity reports, known as SARs, filed by financial institutions and associated businesses pursuant to the Bank Secrecy Act of 1970.
“If current trends continue, SARs filed in 2021 are projected to have a higher ransomware-related transaction value than SARs filed in the previous 10 years combined, which would represent a continuing trend of substantial increases in reported year-over-year ransomware activity,” Fincen’s October report stated.
In November, FinCEN released an
“Other extortion schemes have also emerged whereby the cybercriminals use the system breach to target additional parties related to the initial victim, such as the victim’s business partners and customers, in an attempt to identify follow-on targets,” the agency’s November advisory said.
Ransomware attacks can be highly sophisticated, even when they target smaller businesses, according to a 2021 report from the cybersecurity firm Sophos.
The firm surveyed 5,400 IT professionals from 30 countries at the beginning of 2021. Of the 500 U.S. respondents, 51% reported they had been impacted by a ransomware attack, slightly lower than the 59% who said the same in 2020.
“While the overall number of attacks is lower, our experience shows that the potential for damage from these targeted attacks is much higher,”
Among respondents in the 2021 survey who said that they expected their organization to be hit by ransomware (65%), the most common reason cited (47%) was that attacks are increasing in sophistication.
To avoid ransomware, Plaggemier said, the best and least expensive defense strategy for companies and nonprofits "is by educating themselves and their teams about cybersecurity threats.” The National Cybersecurity Alliance provides
For businesses that use online payment systems, Johnson said adherence to the Payment Card Industry