In 2021, greater numbers of ransomware cyber crews will shift their primary attack strategy to data exfiltration from data encryption to maximize financial hauls from large companies, cybersecurity provider Acronis said in its newly released Cyberthreats Report 2020.
Cybercriminals are no longer satisfied with extracting ransoms from victims in exchange for releasing hijacked data, the Swiss company said in the report. More threat actors are stealing proprietary and “sometimes embarrassing” data and threatening to release the information online unless the victim pays up. So convinced is Acronis of the wholesale shift in tactics that it is predicting 2021 will be the “year of extortion.”
The company’s analysts found evidence that more than 1,000 companies globally had their data leaked following a ransomware attack in 2020, a clear indication that data exfiltration will become cyber attackers' go-to tactic. As a result, cloud environments and managed service providers (MSPs) will continue to be highly valued targets of cyber extortionists because their systems can provide access to the data of multiple clients, Acronis said. "Attacks in 2020 showed that MSPs can be compromised via a variety of techniques, with poorly configured remote access software being among the top attack vectors. Cybercriminals used vulnerabilities, the lack of two-factor authentication (2FA), and phishing to get access to MSPs management tools and eventually to their clients’ machines."
Key findings include:
“More than any year in recent memory, 2020 posed a tremendous number of challenges to IT professionals, organizations, and the service providers who support them,” said Stas Protassov, Acronis co-founder and technology president. “What we’ve seen is how quickly bad actors are adjusting their attacks to the new IT landscape. By analyzing the activity, attacks, and trends we’ve detected and clearly presenting our findings, we hope to empower our partners and help the IT community at large prepare for the threats on the horizon.”
Malware data for the report was collected from June to October, 2020 and is based on some 100,000 unique endpoints distributed globally. Only threats for Microsoft's Windows operating systems are reflected in the report due to their prevalence in comparison to Apple's macOS.