Security

Cyber-crime

Ransomware cost US banks $1.2 billion last year

Up 188% on 2020 but could be because financial institutions were encouraged to report incidents


Banks in the US paid out nearly $1.2 billion in 2021 as a result of ransomware attacks, a marked rise over the year before though it may simply be due to more financial institutions being asked to report incidents.

The figures come from the most recent Financial Trend Analysis report [PDF] on ransomware from the US Treasury's Financial Crimes Enforcement Network (FinCEN) covering Bank Secrecy Act (BSA) filings for 2021.

Its findings indicate that ransomware continued to pose a significant threat to US critical infrastructure, businesses, and the public, and that a substantial number of ransomware attacks appear to be connected to sources in Russia.

In fact, the total of ransomware-related incidents and their monetary value reported in BSA filings during 2021 far exceeds that of other years, according to the report. FinCEN said it received 1,489 ransomware-related filings worth nearly $1.2 billion, a 188 percent increase over the $416 million filed in 2020.

However, the report also notes that the Treasury's Office of Foreign Assets Control (OFAC) released ransomware-related advisories and encouraged the reporting of ransomware incidents in the second half of 2021, which may have contributed to an overall rise in the figures.

Meanwhile, of the 84 individual ransomware variants reported to FinCEN in connection with incidents during this period, the agency reports that 49 of these, roughly 58 percent, may be connected with suspected Russian threat actors.

FinCEN claims that it was able to make this identification because these variants were found to be using Russian language code, were coded specifically not to attack targets in Russia or ex-Soviet states, or were advertized mainly on Russian-language websites. Four of the top five ransomware variants reported during the period could be connected with Russia via at least one of these attributes.

"Today's report reminds us that ransomware – including attacks perpetrated by Russian-linked actors – remains a serious threat to our national and economic security," FinCEN Acting Director Himamauli Das said in a statement.

The report was released to coincide with the second International Counter Ransomware Initiative Summit in Washington, where participants from 36 countries were hosted by the US Deputy Secretary of the Treasury, Wally Adeyemo, to discuss a unified approach to the ransomware threat.

"It is a clear testament to both the grave threat that ransomware poses and the critical importance of international cooperation that we have such strong participation from countries across the globe during this Summit," Adeyemo said in a statement.

"In the midst of this landscape, it is more important than ever that we come together to share what we are seeing through our unique lenses and learn from each other's best practices." ®

Send us news
2 Comments

Kremlin's Sandworm blamed for cyberattacks on US, European water utilities

Water tank overflowed during one system malfunction, says Mandiant

Change Healthcare faces second ransomware dilemma weeks after ALPHV attack

Theories abound over who's truly responsible

185K people's sensitive data in the pits after ransomware raid on Cherry Health

Extent of information seized will be a concern for those affected

French issue <em>alerte rouge</em> after local governments knocked offline by cyber attack

Embarrassing, as its officials are in the US to discuss Olympics cyber threats

UK businesses shockingly unaware of how to handle security threats

Many decide to make no changes after detecting a breach

US government excoriates Microsoft for 'avoidable errors' but keeps paying for its products

In what other sphere does a bad supplier not feel pain for its foulups?

Security pioneer Ross Anderson dies at 67

A man with a list of accolades long enough for several lifetimes, friends remember his brilliance

Ransomware gang <em>did</em> steal residents' confidential data, UK city council admits

INC Ransom emerges as a growing threat as some ex-LockBit/ALPHV affiliates get new gigs

Fire in the Cisco! Networking giant's Duo MFA message logs stolen in phish attack

Also warns of brute force attacks targeting its own VPNs, Check Point, Fortinet, SonicWall and more

MGM says FTC can't possibly probe its ransomware downfall – watchdog chief Lina Khan was a guest at the time

What a twist!

Microsoft squashes SmartScreen security bypass bug exploited in the wild

Plus: Adobe, SAP, Fortinet, VMware, Cisco issue pressing updates

Ivanti commits to secure-by-design overhaul after vulnerability nightmare

CEO addresses whirlwind start to 2024 and how it plans to prevent a repeat