As ransomware attacks continue to rise and reach record levels, the U.S. government this week updated its #StopRansomware guide to provide additional tools and recommendations, including those addressing cloud backups and zero-trust architecture, It also reiterated that businesses should not pay ransoms.

NCC Group recorded an unprecedented surge in ransomware attacks in March with 459 victims, a  91% increase over February. The all-time high volume was likely associated with the highly publicized GoAnywhere MFT vulnerability being exploited across the world.

The firm noted that ransomware threats remained at a high level in April with 352 attacks recorded. And most-active threat groups Lockbit 3.0, BlackCat and BianLian were responsible for 58% of overall ransomware activities for the month.

“We faced another record-breaking volume of ransomware attacks in April, demonstrating how the threat landscape is continuing to evolve at an alarming pace,” Matt Hull, global head of threat intelligence at NCC Group, said in a statement, adding leaking data to encourage ransom payments — also known as a double-extortion ransomware attack — is on the rise.

Veeam’s 2023 Ransomware Trends Report echoed this growth. The security vendor surveyed 1,200 IT leaders in 14 countries and found that ransomware attacks increased by more than 12% over the past year and 76% of surveyed organizations reported at least one attack.

Paying ransom does not ensure data recovery

The Veeam report also revealed a concerning trend: The majority (80%) of organizations paid the ransom in hopes of recovering their data, up 4% compared to last year, despite 41% of them having a “do-not-pay” policy on ransomware.

However, 21% of those paid were unable to retrieve their data from the cybercriminals. This figure showed paying the ransom does not ensure data recovery, Veeam noted. And only 16% of organizations managed to recover their data from backups without paying a ransom, according to the report.

U.S. authorities also do not recommend paying the ransom. The updated #StopRansomware Guide, which is co-authored by the Cybersecurity and Infrastructure Security Agency (CISA), FBI, National Security Agency (NSA), and Multi-State Information Sharing and Analysis Center (MS-ISAC), noted: “paying ransom will not ensure your data is decrypted, that your systems or data will no longer be compromised, or that your data will not be leaked.”

The guide also warns organizations may face sanction risks if paying ransoms based on the U.S. Department of the Treasury Office of Foreign Assets Control (OFAC) memorandum from September 2021, which updated advisory on potential sanctions for facilitating ransom payments.

Ransomware attackers target backups

Another finding in the report that Veeam highlighted is the importance of secure and reliable backups.

The report revealed that 93% of attackers target backups during cyberattacks, and they are successful in debilitating their victims' ability to recover in 75% of these events. This finding reinforces “the criticality of immutability and air gapping [physically isolating a network] to ensure backup repositories are protected,” the vendor noted.

The #StopRansomware Guide also amplifies the backup recommendations. It noted automated cloud backups may not be sufficient as local files encrypted by attackers could synchronize with the cloud, possibly overwriting unaffected data.

The agencies suggest organizations establish and maintain offline and encrypted backups for critical data and regularly test the availability and integrity of those backups in a disaster recovery scenario.

Meanwhile, consider a multi-cloud strategy to avoid vendor lock-in for cloud-to-cloud backups, especially in cases where all accounts under a single vendor are compromised, the guide wrote.

What’s new in the updated #StopRansomware Guide

CISA pointed out that since the release of the first version of the Ransomware Guide in 2020, ransomware attackers have accelerated their tactics and techniques, so the agency updated the guide to remain relevant.

The agency added FBI and NSA as co-authors for the latest version; incorporated lessons learned from the past two years; changed the guide title to #StopRansomware; updated recommendations for preventing common initial infection vectors including compromised credentials and social engineering, cloud backups and zero trust; and expanded the ransomware response checklist.

In the guide, agencies urge organizations to implement a zero-trust architecture to prevent unauthorized access to data and services.

"We strongly encourage all organizations to review this guide and implement recommendations to prevent potential ransomware incidents," Eric Goldstein, executive assistant director for cybersecurity at CISA, said in a statement.