{"id":44991,"date":"2021-08-19T11:14:10","date_gmt":"2021-08-19T03:14:10","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=44991"},"modified":"2021-08-19T11:14:13","modified_gmt":"2021-08-19T03:14:13","slug":"retail-sector-top-target-for-ransomware-data-theft-extortion-attacks-during-pandemic-sophos","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2021\/08\/19\/retail-sector-top-target-for-ransomware-data-theft-extortion-attacks-during-pandemic-sophos\/","title":{"rendered":"Retail sector top target for ransomware, data-theft extortion attacks during pandemic- Sophos"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong><a href=\"http:\/\/www.sophos.com\/\">Sophos<\/a> published the \u201c<a href=\"https:\/\/www.sophos.com\/en-us\/medialibrary\/pdfs\/whitepaper\/sophos-state-of-ransomware-retail-2021-wp.pdf\">State of Ransomware in Retail<\/a>,\u201d which looks at the extent and impact of ransomware attacks on mid-sized retail organizations worldwide during 2020.\u00a0<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The results show how retail organizations became a prime target for ransomware during the COVID-19 pandemic, when many retailers started trading online for the first time simply in order to survive, while others saw a huge increase in their web traffic and online transactions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The survey findings reveal that retail organizations were particularly vulnerable to a small but growing new trend: extortion-only attacks, where the ransomware operators don\u2019t encrypt files but threaten to leak stolen information online if a ransom demand isn\u2019t paid. More than one in ten (12%) retail ransomware victims experienced this, nearly double the cross-sector average of 7%. Only the central government, at 13%, was more affected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Other top research findings include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Retail, together with education, faced the highest level of ransomware attacks during 2020, with 44% of organizations hit (compared to 37% across all industry sectors)&nbsp;<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>The total bill for rectifying a ransomware attack in the retail sector, considering downtime, people time, device cost, network cost, lost opportunity, ransom paid, and more, was US$1.97 million on average \u2013 compared to a cross-sector average of US$1.85 million<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>Over half (54%) of the retail organizations hit by ransomware said the attackers had succeeded in encrypting their data&nbsp;<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>A third (32%) of those whose data was encrypted paid the ransom. The average ransom payment was US$147,811 (lower than the global average of US$170,404.) However, those who paid recovered on average only two-thirds (67%) of their data, leaving a third inaccessible; and just 9% got all their encrypted data back<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe retail sector has always been an attractive target for cyberattacks, with its complex, distributed IT environments, including a multitude of connected point-of-sale devices, a relatively transient and non-technical workforce, and access to a wide range of personal and financial customer data,\u201d said Chester Wisniewski, principal research scientist at Sophos. \u201cThe impact of the pandemic introduced additional security challenges that cybercriminals were quick to exploit.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe comparatively high percentage of targets hit with data-theft based extortion attacks is not entirely surprising. Service industries such as retail hold information that is often subject to strict data protection laws, and attackers are only too willing to exploit a victim\u2019s fear of fallout from a data breach in terms of fines and damage to brand reputation, sales and customer trust.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIt\u2019s not all bad news for retail IT managers, however. While enabling, managing, and securing IT during the pandemic increased the overall IT workload for three quarters of retailers \u2013 the sector was also the most likely (at 77%) to see a positive return in terms of enhanced cybersecurity skills and knowledge.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cTo secure retail IT networks against ransomware and other cyberattacks, we advise IT teams to focus resources on three critical areas: building stronger defenses against cyberthreats, introducing security skills training for users including part time and temporary staff, and, where possible, investing in more resilient infrastructure.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Sophos State of Ransomware in Retail, 2021, survey polled 5,400 IT decision makers, including 435 retail IT managers, in 30 countries across Europe, the Americas, Asia-Pacific and Central Asia, the Middle East, and Africa.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The results show how retail organizations became a prime target for ransomware during the COVID-19 pandemic, when many retailers started trading online for the first time simply in order to survive, while others saw a huge increase in their web traffic and online transactions.<\/p>\n","protected":false},"author":6,"featured_media":44992,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,22],"tags":[6498,6151,54,2103,3914,53,4100,206],"class_list":["post-44991","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-spotlight","tag-good-tech","tag-high-tech","tag-security","tag-security-breach","tag-security-platform","tag-security-risk-management","tag-security-solutions","tag-sophos"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/44991","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=44991"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/44991\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/44992"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=44991"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=44991"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=44991"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}