View all newsletters
Receive our newsletter - data, insights and analysis delivered to you
  1. Technology
  2. Cybersecurity
December 12, 2019updated 13 Dec 2019 10:06am

Ransomware’s Toll Laid Bare: Over 100 US Gov’t Agencies Now Hit

"The fact that there were no confirmed ransomware-related deaths in 2019 is simply due to good luck, and that luck may not continue into 2020"

By CBR Staff Writer

Nearly 1,000 US government agencies, educational establishments and healthcare providers have been hit by ransomware attacks in 2019, with attacks reaching epidemic proportions, security firm Emsisoft warned today, saying it had tracked attacks on 103 federal, state and municipal governments and agencies, a stunning 759 healthcare providers and 86 universities, colleges and school districts.

The report comes amid a high-profile series of recent attacks, with data centre provider CyrusOne among the companies recently affected; others reported on by Computer Business Review include businesses that themselves put cybersecurity operations at the heart of their service; nobody is seemingly immune and attacks are increasingly highly targeted, security experts say, with extensive initial scoping of the target.

Read this: New Ransomware Mutation Raises Alarm over Defensive Techniques

In the US alone such attacks have caused some $7.5 billion-worth of damage, Emsisoft said in a report it had planned to publish January 1, but which it said it is bringing forward in the wake of yet another attack on local US government, this time Pensacola.

The attacks disproportionately hit the healthcare sector, resulting in cancelled operations, delays to surgical procedures and interruptions to 911 services: “The fact that there were no confirmed ransomware-related deaths in 2019 is simply due to good luck, and that luck may not continue into 2020. Governments and the health and education sectors must do better”, said Emisoft CTO Fabian Wosar.

Ransomware Attacks in 2019: State Gov’t Has a “Disregard” for Cybersecurity

The New Zealand-based cybersecurity firm pointed to a report issued by the State Auditor of Mississippi in October 2019 that stated there was a “disregard for cybersecurity in state government,” with many state entities “operating like state and federal cybersecurity laws do not apply to them”.

That report found that many state government bodies do not have a security policy plan or disaster recovery plan in place; are not performing legally mandated risk assessments and are not encrypting sensitive information.

ransomware attacks in 2019As Commvault’s Nigel Tozer told Computer Business Review: “A significant malware attack is a game-changer. System dependencies kick-in and create recovery-roadblocks, communications go down, plans evaporate, and business recovery priorities shift like desert sands. You may even need to build a new datacentre to recover to (as with COSCO and others). It’s imperative to have a robust backup system with its own defences;  failure to do this means cracking the encryption keys or paying the ransom becomes your only option, assuming that destruction alone is not the attack’s purpose”.

Content from our partners
Scan and deliver
GenAI cybersecurity: "A super-human analyst, with a brain the size of a planet."
Cloud, AI, and cyber security – highlights from DTX Manchester

Among a series of initiatives proposed by Emsisoft to stem the flood of attacks is mandating disclosure. As the firm notes: “Currently, there is no legal requirement for public entities to report or disclose ransomware incidents and, as a result, relatively little data about the incidents is available. However, information such as the ransomware strain used, the attack vector, the vulnerability exploited and the financial impact of incidents is critical as it can help other organizations better understand the threat landscape and better assess their security priorities.

“For example, if organizations know what weaknesses enabled other organizations to be compromised, they can make sure that they do not have the same weaknesses. To close the intelligence gap, reporting requirements should be introduced and the data collected aggregated, anonymized and shared. As Algirde Pipikaite (World Economic Forum) and Marc Barrachin (S&P) recently stated, “Information is power and, in cybersecurity, it’s the power to prevent other similar events.”

Read this: The NCSC’s Guidance on Protecting Your Organisation from Ransomware

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how Progressive Media Investments may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.