Zscaler’s ThreatLabz reported a nearly 40% increase in global ransomware attacks this year driven by the growth of ransomware-as-a-service (RaaS) and encryptionless extortion. The vendor recommends adopting a comprehensive zero-trust security strategy with ransomware protection measures to combat these threats.

The research team analyzed data from the Zscaler security cloud from April 2022 to April 2023, its own ransomware samples, and attack data with external intelligence sources to identify key ransomware trends for the 2023 ThreatLabz Ransomware Report.

It found that ransomware attacks increased by more than 37% compared to the previous year, with average enterprise ransom payments surpassing $100,000 and demands averaging $5.3 million.

The U.S. led the pack as the primary target for ransomware campaigns, accounting for 40% of all victims of double-extortion ransomware attacks, followed by Canada (6.75%), the U.K. (6.44%) and Germany (4.92%) — these three counties combined had less than half of the attacks that targeted U.S. entities, according to the report.

Zscaler listed LockBit, ALPHV/BlackCat, and BlackBasta as the most prevalent ransomware families over the last year based on the number of victims listed on their leak sites. Additionally, manufacturing was the most-targeted market sector globally in 2023, accounting for 14.8% of ransomware attacks.

Zscaler predicts 2023-2024 ransomware attack trends

In this year’s report, Zscaler researchers noted encryptionless extortion attacks and RaaS are among the ransomware trends that showed growth in 2023.

Instead of traditional tactics that involve encrypting a victim’s files and demanding a ransom for their release, the encryptionless ransom attacks skip over the process of encryption but focus on exfiltrating sensitive data as leverage for extortion.

“This tactic results in faster and larger profits for ransomware gangs by eliminating software development cycles and decryption support,” researchers noted. “These attacks are also harder to detect and receive less attention from the authorities because they do not lock key files and systems or cause the downtime associated with recovery.”

The encryptionless extortion tactic originally started with ransomware groups like Babuk and SnapMC, and now a number of new families have adopted this tactic, including Karakurt, Donut, RansomHouse, and BianLian.

“Ransomware authors are increasingly staying under the radar by launching encryptionless attacks, which involve large volumes of data exfiltration,” Deepen Desai, global CISO and head of security research at Zscaler, said in a statement, adding another trend — RaaS — has also contributed to a steady rise in sophisticated ransomware attacks.

RaaS is a business model where threat actors sell their services on the dark web for 70-80% of ransomware profits, which lowers the barrier of entry and drives up the sophistication of ransomware attacks, researchers noted. “The vast majority of ransomware groups employ RaaS, and it has proven effective over the years, leading to increases in the number of attacks each year.”

Zscaler also predicts other trends for 2023-2024, including artificial intelligence (AI)-powered ransomware attacks, increased targeting of the cyber-insured and public entities, growing numbers of initial access brokers, and attacks on cloud services and against additional operating systems and platforms.

Use zero trust to protect against ransomware attacks

To address the increasing ransomware threats, Zscaler recommends that businesses adopt a comprehensive zero-trust security approach. This includes measures such as zero-trust network access (ZTNA) architecture, granular segmentation, browser isolation, advanced sandboxing, data loss prevention, deception technology, and cloud access security broker (CASB) solutions.

The vendor noted the zero-trust strategy can help prevent initial compromise, stop compromised users and insider threats, minimize the external attack surface and lateral movement and prevent data loss.

“Organizations must move away from using legacy point products and instead migrate to a fully integrated zero-trust platform that minimizes their attack surface, prevents compromise, reduces the blast radius in the event of a successful attack, and prevents data exfiltration,” Desai said.