Ransomware Q3 Roll Up
ID: f3d79fe2-d539-5833-b8bb-ec8bdac88d1f
STIX ID: report--f3d79fe2-d539-5833-b8bb-ec8bdac88d1f
Feed Name: ReliaQuest Blog
Q3 2021 saw continued and evolving ransomware activity: a major REvil supply-chain compromise of Kaseya (claimed ~1M affected and a BTC 70M demand), BlackMatter’s disruptive attack on New Cooperative, the emergence of LockBit 2.0 as the most active group, and the launch of a new Russian-language ransomware forum (RAMP). The report analyzes 571 victims named on data-leak sites in Q3, sector and geographic targeting (Industrial Goods & Services and North America most affected), trends in group disappearance/rebranding, operational challenges with data-leak hosting and downloads, and expectations that ransomware and data-exfiltration tactics will remain significant into Q4 2021.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
