Part 3. Attack Focus Areas

25 June 2025

Adversaries escalate the intensity of ransomware attacks

Ransomware continues to pose a serious threat to most organizations. Given the increasing competition among malicious actors in this domain, we anticipated that in 2023 cybercriminals would become more aggressive and expand their target lists and attack scenarios. We also expected adversaries to seek larger payouts by focusing on high-value targets.

As predicted, last year saw a significant rise in aggressive attacks. Threat actors disrupted critical sectors and operations, deploying destructive tools to inflict irreversible harm on victims.

  • Attacks on the healthcare sector

Cybercriminals continue to target healthcare providers, with several large-scale attacks disrupting hospital operations and jeopardizing patient safety. These incidents underscore the sector’s vulnerability to ransomware, where downtime can have life-threatening consequences. In March 2024, a U.S. medical billing company fell victim to a ransomware attack by the notorious BlackCat/AlphV group and reportedly paid a $22 million ransom to restore services and prevent further disruptions. The attack, which affected one-third of Americans, caused payment delays to doctors and facilities and hindered billing and prescription fulfillment processes.

  • Disruptions in utilities and the energy sector

Utility providers, especially in the energy sector, are increasingly targeted by ransomware groups aiming to cause large-scale outages and secure high payouts. Ransomware attacks also targeted water management facilities, disrupting purification and distribution services. In one case, local authorities had to issue a boil-water advisory to affected communities, highlighting vulnerabilities in the utilities sector. In this incident, the attackers did not merely encrypt data but threatened to alter water quality parameters, raising public safety concerns and illustrating a shift toward more aggressive, potentially harmful tactics.

  • Manufacturing sector targeted for maximum disruption

Ransomware attacks have also surged in the manufacturing sector, with threat actors targeting OT systems to halt production lines, resulting in significant financial losses. A BlackSuit ransomware attack on an automotive software provider caused production shutdowns across several North American car manufacturers. This led to vehicle manufacturing delays, disrupted supply chains, and widespread operational ripples across the industry.

  • Financial institutions face new ransomware compliance pressures

According to the Financial Services Information Sharing and Analysis Center (FS-ISAC), about 65% of financial institutions reported ransomware-related issues in 2024. As attackers increasingly adopt tactics beyond encryption, financial entities are becoming prime targets. Recent attacks indicate a shift toward extortion-focused methods, such as threatening to expose financial records of high-profile banking clients. The sensitivity of data and reputational risks make institutions more likely to comply with ransom demands.

  • Ransomware-as-a-Service (RaaS) gains momentum

Although not new, the RaaS model has enabled a broader range of cybercriminals to launch sophisticated attacks without deep technical skills, creating a new revenue stream for affiliates. The Black Basta ransomware group emerged as a prominent player in 2024, using the RaaS model to launch numerous high-impact attacks across sectors. One such attack targeted a government defense contractor, exposing confidential contract information. Black Basta affiliates escalated attacks on critical infrastructure, demonstrating how RaaS has expanded access to ransomware capabilities and empowered less-experienced actors.

Wiper malware expands its footprint

As anticipated, ransomware variants employing destructive techniques—particularly data-wiping—have increased in number, moving beyond traditional encryption. This trend, aimed at maximizing disruption and irreversible data loss, is evident in recent ransomware attacks. One notable trend involves integrating wiper malware as a feature within ransomware packages. While not entirely new, this approach became more prominent in 2024, serving as a tactic to heighten pressure on victims through threats of irreversible data destruction unless demands are met. FortiGuard Labs reported that such destructive methods can devastate organizations, particularly in critical infrastructure sectors where downtime and data loss have significant societal consequences. Another example involves attackers targeting OT systems and critical assets in industries reliant on data continuity, such as healthcare and manufacturing. These adversaries seek either ransom payments or permanent damage through disk-wiping functionality. This raises the urgency for robust incident response and backup strategies. These developments reflect the increasing complexity and aggressiveness of ransomware playbooks, where attackers go beyond encryption to incorporate wipers, intensifying leverage and rendering recovery without backups nearly impossible. Such incidents show how ransomware in 2024 continued to increase in impact and strategic focus, with attackers targeting sectors where operational disruptions can result in maximum social and financial consequences—aligning with earlier predictions of more destructive scenarios and broader high-stakes targeting.

Global events create opportunities for cybercrime

In 2024, attackers were expected to exploit more personalized, event-driven opportunities, such as the Paris Games and U.S. elections. While prominent and geopolitical events have always attracted cybercriminals, adversaries now have new tools to support their efforts. Threat actors actively capitalized on global attention toward the Paris Games. FortiGuard Labs observed a sharp increase in dark web activity tied to the Games, particularly targeting French-speaking users, French government institutions, businesses, and infrastructure providers. Since the second half of 2023, dark web activity aimed at France surged by 80–90%, remaining high through H2 2023 and H1 2024. Similarly, threats related to the U.S. elections were noted. Dark web analysis showed attackers selling ready-made phishing kits targeting voters and donors by impersonating presidential candidates and their campaigns. There was also a spike in malicious domain registrations, with attackers creating websites hosting election-related content. These types of attacks highlight the need for organizations and individuals to remain vigilant, especially during periods of heightened activity that attract increased threat actor engagement.

📷
📷
📷
Читати більше новин
EN