Microsoft says more ransomware stopped before reaching encryption
ID: 9a6c489d-c138-5477-8097-52f8dcd71afe
STIX ID: report--9a6c489d-c138-5477-8097-52f8dcd71afe
Feed Name: The Register (Security)
Microsoft's Digital Defense Report shows ransomware attacks have risen significantly while defenses are preventing many campaigns from reaching the encryption phase; attackers increasingly rely on social engineering (phishing, adversary-in-the-middle, SIM swapping) and cloud identity abuse to bypass MFA and gain persistent access. Notable actors include Octo Tempest (Scattered Spider), Storm-0501, and Midnight Blizzard/Nobelium, with top ransomware families being Akira, LockBit, Play, ALPHV/BlackCat, and Black Basta; recommended mitigations include deploying MFA, blocking legacy authentication, enforcing privilege management, and moving toward phishing-resistant passwordless passkeys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
