Ransomware is still on the rise, according to Verizon’s latest Data Breach Investigation Report (DBIR). The annual report found that ransomware appeared in 10% of breaches, more than double the frequency from last year, and ransomware now ranks third among actions that cause data breaches.

Verizon’s DBIR echoes several other recent reports — not to mention recent events, such as the ransomware attack against Colonial Pipeline. One of these, Zscaler’s new ransomware report, also released today, found these types of double-extortion attacks are on the rise. This is when cybercriminals not only demand the victims pay a ransom, but they also threaten to leak sensitive data if the companies don’t pay up.

For the 2021 report — Verizon’s 14th DBIR — the operator analyzed 29,207 security incidents, of which 5,258 were confirmed breaches. This is a significant increase on the 3,950 breaches analyzed in last year’s DBIR. It includes data collected from 83 contributors, with victims spanning 88 countries and 12 industries.

Criminals Change Their Ransomware Tactics

Also between the 2020 and 2021 reports, Verizon analysts noticed ransomware tactics changed.

“Right after we finished our data collection for last year’s report, the Maze group changed their tactics,” said Verizon’s Suzanne Widup, a senior principal for threat intelligence and DBIR co-author. “Maze started taking a copy of the data, and then using that as leverage to get their victims to pay up. And so if they don’t pay up, then they were also having a data breach.”

Other ransomware gangs quickly learned from Maze’s success. “They saw that was a really good tactic and jumped on the bandwagon, and now they’ve all stood up this infrastructure to be able to share their victims’ data with the world,” Widup said. “It’s so prevalent now that 10% of data breaches are ransomware attacks.”

Ransomware attacks used to be primarily availability violations because companies couldn’t access their data. But now, with the double-extortion attacks, organizations risk confidentially compromises as well, she added. “That’s been a huge change that, in the past year, has just taken off,” Widup said.

DBIR Finds Phishing Spiked 25%

Verizon this year updated the DBIR patterns in breaches, which resulted in two new patterns for the 2021 report: social engineering and system intrusion. In fact, social attacks have been increasing since 2017, according to Verizon, with business email compromise breaches doubling since last year. The authors found phishing in 36% of breaches, up from 25% last year.

Interestingly, phishing emails saw a wide range of click rates, from no clicks to higher than 50% click rates. In a sample of 1,148 people who received real and simulated phishing emails, none of them clicked the simulated phish, but 2.5% clicked the real one.

“It really shows that the attackers out there are really good,” Widup said. “They’re really on their game as far as being able to craft a phishing email that really makes it likely they’re going to have some success.”

COVID-19 related phishes contributed to this success, she added. Attackers “started out talking about the virus, and using that as the lure,” Widup explained. “Then, after vaccines came out, they started using information about vaccines to try and get people to click on their phishing emails. They are very good at evolving and making the lure to be as attractive as possible.”

Did COVID-19 Help Cybercriminals?

And while Widup cautions that it’s difficult to do causal research and to definitively say the pandemic caused an increase in successful phishing emails or other breaches, certain trends resulting from COVID-19 — including the newly distributed workforce, use of personal devices and home networks, and doom scrolling COVID-related content — didn’t do organizations any favors in shrinking their threat landscape.

In August 2020, the co-authors forecast that COVID-19 would lead to an increase in phishing, ransomware, human-error related breaches, and the use of stolen credentials on web applications. They were partially right. In the 2021 DBIR, they found phishing increased 11% and ransomware grew 6% compared to last year. However, the use of stolen credentials remained the same and errors slightly decreased, from 22% to 17%.

Additionally, as businesses move their services to the cloud — another activity that saw a boost during the pandemic and subsequent lockdowns — attackers took note. Attacks on web applications represented 39% of all breaches in the 2021 report.

Putting Price Tags on Data Breaches

Also new this year: the DBIR analyzed the financial impact on breaches on organizations. To help put a price tag on breaches, Verizon used information on losses that were reported to the FBI as well as insurance cost data and stock prices before and after a reported breach.

“We looked at a study that looked at changes in the stock prices, both short term and long term, after a breach is announced, and how breached companies did as opposed to their un-breached peers in the Nasdaq,” Widup explained. “There are some indications that breaches wind up causing some kind of a longer-term impact.”

Verizon also modeled the cost of breaches using things like lost data, incident response, and legal costs, she added. Interestingly, it found 14% of simulated breaches had no financial impact. However, the median cost of a breach hit nearly $21,659 and 95% of security incidents cost between $826 and $654,587.