Ransomware attacks reached record levels in July 2023, driven by the Cl0p ransomware group's exploitation of MOVEit software. In a new report released by NCC Group's Global Threat Intelligence team, analysts observed a record number of ransomware-related cyberattacks last month, with 502 major incidents tracked. According to the researchers, this represents a 154% increase year-on-year, compared to 198 attacks traced in July 2022. Also: What is ransomware? Everything you need to know July's numbers represent a 16% rise from the previous month, with 434 ransomware incidents recorded in June 2023. NCC Group says that this record number is due, in no small part, to the activities of Cl0P, a notorious group connected to the exploit of MOVEit software. Cl0p, also known or associated with Lace Tempest, was responsible for 171 of 502 attacks in July, many of which are believed to be down to the exploitation of file transfer software MOVEit. Also: Ransomware has now become a problem for everyone, and not just tech Cl0p has been around since 2019 and is known as a Ransomware-as-a-Service (RaaS) offering to cybercriminals. Also known as -- or associated with -- TA505, Cl0p has aggressively pursued high-value targets with the aim of extorting high ransomware payments, and operators will often steal information prior to encryption in what is known as a double-extortion tactic. If victims refuse to pay up, they risk having their stolen data published online and being named on a public lea...
Ransomware attacks broke records in July, mainly driven by this one group
Charlie Osborne
·Published Aug 23, 2023
·Updated
Affected Software
2 affected components
Progress Software MOVEit Transfer
Progress Software MOVEit Cloud
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the record levels of ransomware attacks in July 2023, primarily driven by the Cl0p ransomware group.
2
What security implications are discussed in the article?
The article highlights the significant threats posed by ransomware attacks and their impact on organizations' data security.
3
What group is identified as the main driver of recent ransomware attacks?
The Cl0p ransomware group is identified as the main driver of the surge in ransomware attacks.
4
Which software products are specifically mentioned as being exploited?
The article mentions Progress Software's MOVEit Transfer and MOVEit Cloud as the exploited software products.
5
How did the Cl0p ransomware group achieve their record-breaking attacks?
The group exploited vulnerabilities in the MOVEit software to execute their record-breaking ransomware attacks.