logo

Microsoft says more ransomware stopped before reaching encryption

ID: 9a6c489d-c138-5477-8097-52f8dcd71afe

STIX ID: report--9a6c489d-c138-5477-8097-52f8dcd71afe

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-10-15

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Microsoft's Digital Defense Report shows ransomware attacks have risen significantly while defenses are preventing many campaigns from reaching the encryption phase; attackers increasingly rely on social engineering (phishing, adversary-in-the-middle, SIM swapping) and cloud identity abuse to bypass MFA and gain persistent access. Notable actors include Octo Tempest (Scattered Spider), Storm-0501, and Midnight Blizzard/Nobelium, with top ransomware families being Akira, LockBit, Play, ALPHV/BlackCat, and Black Basta; recommended mitigations include deploying MFA, blocking legacy authentication, enforcing privilege management, and moving toward phishing-resistant passwordless passkeys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.