A recent report from Arctic Wolf highlights a significant shift in the tactics of cyber attackers, who have begun to abandon encryption in favor of data exfiltration and extortion. This shift has emerged as a response to the pursuit of better economic returns, contributing to a new wave of attacks where ransomware is no longer the sole focus. In fact, ransomware accounted for 44% of the response incidents during the analyzed period.
New strategies of criminals
The manufacturing sector has become the most affected, followed by law firms, schools, financial institutions, and health organizations. These sectors account for the majority of attacks, reflecting the growing impact of cyber threats on key industries of the economy. Furthermore, ransomware gangs have adopted affiliate models, allowing for greater interconnection between different groups, making them more competitive and harder to stop.
The report indicates that police interactions have weakened groups like LockBit, ALPHV/BlackCat, and BlackSuit, suggesting that law enforcement efforts have had some effect on their operability. However, other types of attacks, such as business email compromise, have proliferated, representing 26% of the cases investigated by Arctic Wolf. Most of these attacks have targeted financial and legal organizations, with a notable use of email phishing as the initial access method in 85% of the compared cases.

In addition, attackers have shown a particular preference for compromising remote access tools, such as Remote Desktop Protocol and remote management software, which account for two-thirds of cases unrelated to BEC, a significant increase compared to previous years. This shift in tactics underscores the adaptability and operational maturity of cybercriminals in a constantly evolving technological landscape.