A recent report from Palo Alto Networks' Unit 42 indicated that nearly 4,000 companies were listed on ransomware leak sites in 2023, marking a 50% increase from the previous year in its “Ransomware Retrospective 2024” report. The figures likely fall short of the actual number of ransomware victims due to unreported or listed incidents.

Unit 42 noted the ransomware landscape experienced significant transformations and challenges last year. The team observed 3,998 posts from ransomware leak sites, a 49% increase from 2,679 posts in 2022.

The surge in activity can be attributed to the exploitation of high-profile vulnerabilities, including SQL injection flaws in MOVEit and GoAnywhere MFT services. Zero-day exploits targeting these vulnerabilities led to spikes in ransomware infections by malicious groups such as CL0P, LockBit and ALPHV (BlackCat), often before organizations could patch the vulnerable software, according to the report.

The findings also showed among the 2023 leak site posts that the team reviewed, LockBit ransomware remains the most active, posting data from 928 organizations and accounting for 23% of the total posts.

Geographically, organizations from at least 120 different countries have been impacted by ransomware extortion. The United States was the primary target for ransomware attacks, with nearly half (47.6%) of the leak site posts in 2023 pointing to U.S.-based organizations, followed by the U.K. (6.5%), Canada (4.6%) and Germany (4%).

Unit 42’s report also noted ransomware groups targeted a wide range of victims with no preference for specific industries, but based on the collected leak site data, manufacturing was the most affected industry in 2023.

The manufacturing sector accounted for 14% of the total posts, which signals significant vulnerabilities in this industry, the team noted. “Manufacturers usually have limited visibility into their operational technology (OT) systems, often lack adequate network monitoring and occasionally fail to implement best security practices.”

Other top-impacted sectors include professional and legal, high technology, wholesale and retail and construction.

New ransomware groups and goners in 2023

The leak site data also revealed the emergence of at least 25 new ransomware groups in 2023, which contributed to about one-quarter of the total ransomware posts. The Akira group, first observed in March, led with the most posts. However, many new groups, such as Darkrace, CryptNet and U-Bomb, disappeared during the second half.

In addition, last year also witnessed significant law enforcement actions against notorious ransomware groups, which led to the decline of groups like Hive and Ragnar Locker, and the near-collapse of ALPHV (BlackCat), according to Unit 42.

The Hive ransomware group, one of the most prolific groups in 2022, was shut down as part of a law enforcement-led operation reported in January 2023. The operation captured the group’s decryption keys and saved potential victims over $130 million in ransom payments.

Similarly, the Federal Bureau Of Investigation (Ffbi) disrupted ALPHV, also known as BlackCat operations in December 2023. The bureau released a decryption tool that allowed more than 500 victims to recover their data.

Unlike Hive’s disappearing for the remainder of 2023 due to the shutdown, the ALPHV group fought back against law enforcement action. “But if this group cannot fix its reputation, it could shut down and rebrand as a new ransomware gang,” Unit 42 noted.

Other noteworthy ransomware departures or shutdowns in 2023 include Ragnar Locker, Ransomed.Vc and Trigona.