In March 2023, cybersecurity analysts recorded 459 attacks, marking the most prolific month in recent years and a 91% increase from the previous month and a 62% rise compared to March 2022. NCC Group compiled a report attributing the surge in attacks to a vulnerability in Fortra’s GoAnywhere MFT secure file transfer tool, CVE-2023-0669, which the Clop ransomware gang exploited as a zero-day to steal data from 130 companies within ten days. March 2023’s activity continued the upward trend observed by NCC Group since January and February, with the highest number of hack and data leak incidents recorded in the past three years.
Clop performed 129 recorded attacks, topping NCC Group’s graph of the most active ransomware gangs for the first time in its operational history. The most targeted sector in March 2023 was “Industrials,” receiving 147 ransomware attacks, accounting for 32% of the recorded attacks. Sectors that received significant attention from ransomware gangs were “Consumer Cyclicals,” “Technology,” “Healthcare,” “Basic Materials,” “Financials,” and “Educational Services.” The top three most active ransomware groups, Clop, LockBit, and Royal, primarily targeted companies within the “Industrials” sector.
Almost half of all attacks (221) breached entities in North America, followed by Europe with 126 episodes and Asia with 59 ransomware attacks. The recorded activity spike in March 2023 highlights the importance of applying security updates as soon as possible, mitigating potentially unknown security gaps like zero days by implementing additional measures, and monitoring network traffic and logs for suspicious activity.
You can read the full article here https://www.bleepingcomputer.com/news/security/march-2023-broke-ransomware-attack-records-with-459-incidents/
If you want to talk to us about your cybersecurity, please get in touch.