A recent report by insurance specialist Hiscox reveals that ransomware attacks continue to pose a significant threat to businesses, with 27% of 5,750 surveyed small and medium-sized enterprises (SMEs) targeted by ransomware in the past year. Of those affected, 80% paid the ransom, yet only 60% managed to recover all or part of their data, highlighting the unreliable nature of ransom payments as a recovery strategy. The report also notes that nearly a third of companies that paid were subsequently met with additional demands for more money, compounding the financial and operational risks. The impact of these attacks is severe, with some high-profile companies such as Marks and Spencer, the Co-op, and Jaguar Land Rover (JLR) experiencing significant disruptions. JLR, for example, received a £1.5bn government loan guarantee to protect its supply chain after a month-long factory shutdown. Many SMEs, lacking such support, face existential threats from ransomware incidents, with some already forced to lay off staff. The study also points to vulnerabilities introduced by artificial intelligence as a contributing factor to the rise in successful cyber attacks. In parallel, ransomware gangs are evolving their tactics, as illustrated by the Medusa ransomware group's attempt to recruit a BBC journalist as an insider. The gang offered the journalist a substantial share of any ransom paid if he provided access to the BBC's internal systems, with the promise of anonymity and references to previous successful insider-assisted attacks. Medusa, active since 2021, is known for double-extortion tactics and has been linked to over 300 attacks on critical infrastructure in the United States, according to CISA. The group typically recruits initial access brokers via cybercrime forums and darknet marketplaces, focusing on leveraging insider threats and post-compromise extortion. The incident involving the BBC journalist underscores the increasing sophistication of ransomware groups in targeting not just technical vulnerabilities but also human factors within organizations. These developments highlight the urgent need for organizations to strengthen both their technical defenses and insider threat detection capabilities. The financial and reputational risks associated with ransomware are escalating, with attackers employing a mix of extortion, social engineering, and exploitation of emerging technologies. The Hiscox report and the Medusa case collectively demonstrate that paying ransoms does not guarantee data recovery and may even invite further extortion. Organizations are advised to invest in comprehensive cybersecurity measures, employee awareness training, and robust incident response plans to mitigate the growing threat landscape. The trend of targeting SMEs, which often lack the resources of larger enterprises, suggests that all organizations, regardless of size, are at risk. The evolving tactics of ransomware groups, including the recruitment of insiders, represent a significant challenge for security teams and require a multi-layered approach to defense.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Initial story creation
Semperis’s 2024 Ransomware Risk Report, based on a survey of 900 IT and security executives in France, Germany, the U.K., and the U.S., found that 32% of attacked organizations paid ransomware demands four or more times in the prior 12 months. The report also said most victims faced repeated attacks, widespread operational disruption, and frequent compromise of identity systems such as Active Directory and Entra ID.
4 references tracked. Mallory keeps watching after this page renders.
thetimes.com
Open sourcenews.sky.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritydive.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.