Ransomware Attacks Surge: Key Insights from a Secret Service Cyber Investigator
Ransomware attacks continue to escalate, targeting critical infrastructure, supply chains, and businesses of all sizes. In 2021, high-profile incidents underscored the growing threat: CNA Financial paid $40 million in March to restore access to its data, Colonial Pipeline handed over $4.4 million in May after an attack disrupted East Coast fuel supplies, and JBS Meats paid $11 million the same month to prevent global food supply disruptions. Even small businesses are now in the crosshairs, with lower-level cybercriminals demanding ransoms as low as $500 to $1,000.
Stephen Nix, assistant to the special agent in charge at the U.S. Secret Service and a member of the National Cyber Investigative Joint Task Force, emphasized that federal agencies uniformly advise against paying ransoms. However, he acknowledged that many companies still opt to pay, making the decision a complex business dilemma.
Nix outlined five critical considerations for organizations facing ransomware attacks:
-
Contact Authorities – Engaging federal agencies can provide valuable resources, including decryption tools for known ransomware variants (available through platforms like nomoreransom.org). Authorities can also offer insights into non-encryption extortion schemes, where hackers claim access to data without encrypting it, and help assess whether payment is necessary.
-
Report Payments – If a company pays a ransom, authorities urge them to disclose it. This enables agencies to track cryptocurrency payments, potentially recover funds, and gather intelligence on cybercriminals. For example, the Department of Justice recovered a portion of Colonial Pipeline’s ransom payment. Reporting also helps authorities analyze attacker behavior, such as negotiation tactics and likelihood of repeat extortion.
-
Post-Payment Risks – Paying a ransom does not guarantee full data recovery. A 2021 Cybereason survey found that 46% of companies that paid ransoms failed to regain complete access to their data. Additionally, 70% of ransomware negotiations now involve double extortion, where attackers demand further payments after the initial ransom is paid.
-
Consequences of Paying – Ransom payments fund cybercriminal operations, enabling them to invest in more sophisticated attacks. Some hackers even demand cyber tools or software instead of money, further empowering their capabilities. Nix warned that continued payments will only perpetuate the cycle of attacks.
-
Prevention as the Best Defense – Basic cybersecurity measures such as regular backups, patch management, and phishing awareness can significantly reduce the risk of ransomware infections. Federal resources like stopransomware.gov provide guidance for organizations seeking to bolster their defenses.
The rise in ransomware underscores the need for proactive cybersecurity strategies, as attackers increasingly target both large enterprises and small businesses. While federal agencies advocate against payment, they remain a critical resource for affected organizations navigating the aftermath of an attack.
Colonial Pipeline Company cybersecurity rating report: https://www.rankiteo.com/company/colonial-pipeline-company
JBS USA cybersecurity rating report: https://www.rankiteo.com/company/jbsusa
CNA Insurance cybersecurity rating report: https://www.rankiteo.com/company/cna-insurance
"id": "COLJBSCNA1788174167",
"linkid": "colonial-pipeline-company, jbsusa, cna-insurance",
"type": "Ransomware",
"date": "3/2021",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Insurance',
'name': 'CNA Financial',
'size': 'Large',
'type': 'Corporation'},
{'industry': 'Energy/Oil & Gas',
'location': 'United States',
'name': 'Colonial Pipeline',
'size': 'Large',
'type': 'Corporation'},
{'industry': 'Food Processing',
'location': 'Global',
'name': 'JBS Meats',
'size': 'Large',
'type': 'Corporation'},
{'name': 'Small businesses',
'size': 'Small',
'type': 'Businesses'}],
'data_breach': {'data_encryption': 'Yes (ransomware encryption)',
'data_exfiltration': 'Possible (double extortion tactics '
'mentioned)'},
'date_publicly_disclosed': '2021',
'description': 'Ransomware attacks continue to escalate, targeting critical '
'infrastructure, supply chains, and businesses of all sizes. '
'High-profile incidents in 2021 included CNA Financial, '
'Colonial Pipeline, and JBS Meats, with ransoms paid ranging '
'from $4.4 million to $40 million. Small businesses are also '
'targeted with demands as low as $500 to $1,000.',
'impact': {'financial_loss': ['$40 million (CNA Financial)',
'$4.4 million (Colonial Pipeline)',
'$11 million (JBS Meats)',
'$500-$1,000 (small businesses)'],
'operational_impact': ['Disrupted East Coast fuel supplies '
'(Colonial Pipeline)',
'Global food supply disruptions (JBS '
'Meats)']},
'lessons_learned': 'Ransomware attacks are escalating, targeting critical '
'infrastructure and businesses of all sizes. Paying '
'ransoms does not guarantee full data recovery and funds '
'further criminal activity. Prevention through basic '
'cybersecurity measures is critical.',
'motivation': 'Financial gain, operational disruption',
'ransomware': {'data_encryption': 'Yes',
'data_exfiltration': 'Possible (double extortion tactics '
'mentioned)',
'ransom_demanded': ['$40 million (CNA Financial)',
'$4.4 million (Colonial Pipeline)',
'$11 million (JBS Meats)',
'$500-$1,000 (small businesses)'],
'ransom_paid': ['$40 million (CNA Financial)',
'$4.4 million (Colonial Pipeline)',
'$11 million (JBS Meats)']},
'recommendations': ['Contact authorities (e.g., U.S. Secret Service, National '
'Cyber Investigative Joint Task Force) for decryption '
'tools and guidance.',
'Report ransom payments to track cryptocurrency and '
'recover funds.',
'Avoid paying ransoms due to risks of incomplete data '
'recovery and double extortion.',
'Implement basic cybersecurity measures (backups, patch '
'management, phishing awareness).',
'Utilize federal resources like nomoreransom.org and '
'stopransomware.gov for guidance.'],
'references': [{'source': 'U.S. Secret Service',
'url': 'https://www.nomoreransom.org'},
{'source': 'StopRansomware.gov',
'url': 'https://www.stopransomware.gov'},
{'source': 'Cybereason Survey (2021)'}],
'response': {'law_enforcement_notified': 'Recommended (U.S. Secret Service, '
'National Cyber Investigative Joint '
'Task Force)'},
'stakeholder_advisories': 'Federal agencies advise against paying ransoms but '
'provide resources for affected organizations.',
'title': 'Surge in Ransomware Attacks on Critical Infrastructure and '
'Businesses',
'type': 'Ransomware'}