Security

Cyber-crime

Ransomware cost US banks $1.2 billion last year

Up 188% on 2020 but could be because financial institutions were encouraged to report incidents


Banks in the US paid out nearly $1.2 billion in 2021 as a result of ransomware attacks, a marked rise over the year before though it may simply be due to more financial institutions being asked to report incidents.

The figures come from the most recent Financial Trend Analysis report [PDF] on ransomware from the US Treasury's Financial Crimes Enforcement Network (FinCEN) covering Bank Secrecy Act (BSA) filings for 2021.

Its findings indicate that ransomware continued to pose a significant threat to US critical infrastructure, businesses, and the public, and that a substantial number of ransomware attacks appear to be connected to sources in Russia.

In fact, the total of ransomware-related incidents and their monetary value reported in BSA filings during 2021 far exceeds that of other years, according to the report. FinCEN said it received 1,489 ransomware-related filings worth nearly $1.2 billion, a 188 percent increase over the $416 million filed in 2020.

However, the report also notes that the Treasury's Office of Foreign Assets Control (OFAC) released ransomware-related advisories and encouraged the reporting of ransomware incidents in the second half of 2021, which may have contributed to an overall rise in the figures.

Meanwhile, of the 84 individual ransomware variants reported to FinCEN in connection with incidents during this period, the agency reports that 49 of these, roughly 58 percent, may be connected with suspected Russian threat actors.

FinCEN claims that it was able to make this identification because these variants were found to be using Russian language code, were coded specifically not to attack targets in Russia or ex-Soviet states, or were advertized mainly on Russian-language websites. Four of the top five ransomware variants reported during the period could be connected with Russia via at least one of these attributes.

"Today's report reminds us that ransomware – including attacks perpetrated by Russian-linked actors – remains a serious threat to our national and economic security," FinCEN Acting Director Himamauli Das said in a statement.

The report was released to coincide with the second International Counter Ransomware Initiative Summit in Washington, where participants from 36 countries were hosted by the US Deputy Secretary of the Treasury, Wally Adeyemo, to discuss a unified approach to the ransomware threat.

"It is a clear testament to both the grave threat that ransomware poses and the critical importance of international cooperation that we have such strong participation from countries across the globe during this Summit," Adeyemo said in a statement.

"In the midst of this landscape, it is more important than ever that we come together to share what we are seeing through our unique lenses and learn from each other's best practices." ®

Send us news
2 Comments

Extortion crew threatened to inform Edward Snowden (?!) if victim didn't pay up

Don't laugh. This kind of warning shows crims are getting desperate

Medusa ransomware affiliate tried triple extortion scam – up from the usual double demand

Feds warn gang still rampant and now cracked 300+ victims around the world

AI agents swarm Microsoft Security Copilot

Looking to sort through large volumes of security info? Redmond has your backend

VanHelsing ransomware emerges to put a stake through your Windows heart

There's only one rule – don't attack Russia, duh

Names, bank info, and more spills from top sperm bank

Cyber-crime is officially getting out of hand

So … Russia no longer a cyber threat to America?

Mixed messages from Pentagon, CISA as Trump gets pally with Putin and Kremlin strikes US critical networks

Like whitebox servers, rent-a-crew crime 'affiliates' have commoditized ransomware

Which is why taking down chiefs and infra behind big name brand operations isn't working

Oracle Cloud says it's not true someone broke into its login servers and stole data

Despite evidence to the contrary as alleged pilfered info goes on sale

How NOT to f-up your security incident response

Experts say that the way you handle things after the criminals break in can make things better or much, much worse

Uncle Sam charges alleged Garantex admins after crypto-exchange web seizures

$96B in transactions, some even labeled 'dirty funds,' since 2019, say prosecutors

Ex-NSA boss: Election security focus helped dissuade increase in Russian meddling with US

Plus AI in the infosec world, why CISA should know its place, and more

As nation-state hacking becomes 'more in your face,' are supply chains secure?

Ex-US Air Force officer says companies shouldn't wait for govt mandates