KELA-BERICHT
Beware. Ransomware. Top Trends of 2021
In this report, KELA provides insights into ransomware victims, recaps activity of ransomware groups in 2021 — both in terms of their attacks and presence on cybercrime forums — and shares exclusive findings about collaboration of ransomware actors with other cybercriminals.
Teilen:

Executive Summary
In 2021, ransomware attacks continued to be one of the most prominent threats targeting businesses and organizations worldwide. High-profile attacks disrupted operations of companies in various sectors, including critical infrastructure (Colonial Pipeline), food processing (JBS Foods), insurance (CNA) and many more. Following the attacks, pressure of law enforcement on ransomware gangs intensified, though simultaneously these threat actors continue to evolve. They not only become more technologically sophisticated but also extensively leverage the growing cybercrime ecosystem aiming to find new partners, services and tools for their operations.
In this report, KELA provides insights into ransomware victims, recaps activity of ransomware groups in 2021 — both in terms of their attacks and presence on cybercrime forums — and shares exclusive findings about collaboration of ransomware actors with other cybercriminals.
Herunterladen
Executive Summary
- Ransomware victims nearly doubled from 1,460 in 2020 to 2,860 in 2021, with 65% of leak sites emerging that year
- Almost 40 “double victims” and the links between data leak sites Marketo, Snatch and Quantum and ransomware gangs
- Top attackers Conti, LockBit, Pysa, Avaddon and REvil, new players Alphv, Hive and AvosLocker, and a deep dive into LockBit 2.0
- The forum ransomware ban, the rise of RAMP, and internal leaks as an insider threat to RaaS operations
- Over 1,300 access listings by almost 300 Initial Access Brokers, the ideal victim (US, USD 60 million+ revenue), and five attacks traced from access sale to ransomware




