Report by ReliaQuest

Ransomware and Cyber Extortion in Q4 2024

16 FINDINGSPublished Jan 1, 2025
View Original Report →

Key Findings

"Akira" more than doubled its Q3 count and listed 71 organisations on data-leak sites in December alone.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

Roughly 20% of the domains registered by Scattered Spider imitated Gateway and Network Infrastructure.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

LockBit's victim count decreased from 176 in May 2024 to only five in December.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

Approximately 15% of domains registered by Scattered Spider imitated VPN and Secure Access.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

Newcomers in Q4 like “SafePay” and “FunkSec” quickly ramped up their activity, claiming 45 and 82 victims, respectively.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

Ransomware attacks reached an all-time high in December 2024.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

In Q4 2024, there was the highest jump of the year with 13 new ransomware groups emerging.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

The median ransom payment rose from $199,000 in 2023 to $1,500,000 in 2024.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

Nearly half of the 1,110 initial access listings collected in Q4 2024 were related to US-based companies.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

"BlackLock" activity rose 1,425% from Q3 to Q4 2024.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

Approximately 30% of domains registered by Scattered Spider imitated Single Sign-On (SSO) and Identity Providers.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

30% of the domains registered by Scattered Spider imitated hosts for common services such as Binance and Coinbase.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

25–30% of Scattered Spider domains targeted manufacturing companies.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

Around 20% of domains registered by Scattered Spider imitated Help Desk and IT Support.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

70% of the domains egistered by Scattered Spider imitated a specific organisation.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025

20–25% of Scattered Spider domains targeted finance and insurance companies.

ReliaQuestRansomware and Cyber Extortion in Q4 2024 ·Jan 1, 2025