Full Report
Claims on ransomware groups’ data leak sites reached an all-time high in November, with 632 reported victims, according to Corvus Insurance
Analysis Summary
# Incident Report: Surge in Global Ransomware Claims Driven by Akira and RansomHub
## Executive Summary
Ransomware activity reached an all-time high in November 2024, with 632 victim claims reported on Data Leak Sites (DLS), more than double the monthly average. This surge was primarily driven by heightened activity from the RansomHub and Akira ransomware groups. The overall impact assessment is broad, affecting numerous organizations across various sectors globally, though specific organizational responses are not detailed in this summary data.
## Incident Details
- **Discovery Date:** Data collected throughout November 2024 (reporting published December 11, 2024).
- **Incident Date:** November 2024 (period of peak activity).
- **Affected Organization:** Not specified (data aggregated across 632+ victims).
- **Sector:** Various (Implied by broad nature of DLS tracking).
- **Geography:** Global (Ransomware activity tracking is global).
## Timeline of Events
Due to the nature of the source material (an aggregated report on threat trends), a specific, single incident timeline is not available. The timeline references group emergence and trend spikes:
### Initial Access
- **Date/Time:** RansomHub emerged circa February 2024; Akira emerged circa March 2023.
- **Vector:** Not specified; these groups utilize standard, undisclosed ransomware vectors (likely vulnerable internet-facing services, phishing, or exploited vulnerabilities).
- **Details:** RansomHub showed consistent monthly growth, claiming 98 victims in November. Akira significantly ramped up operations to claim 73 victims in November (up from 6–30 per month previously).
### Lateral Movement
- *Not detailed in the provided summary data.*
### Data Exfiltration/Impact
- **What was stolen or damaged:** Data exfiltration is implied, as claims were posted on Data Leak Sites (DLS), indicating double-extortion tactics.
### Detection & Response
- **How it was discovered:** Detection occurred via monitoring ransomware groups' Data Leak Sites (DLS) by Corvus Insurance analysts.
- **Response actions taken:** Response actions for individual victims are not detailed in this summary.
## Attack Methodology
The report highlights the actors responsible for the volume, but specific TTPs (Tactics, Techniques, and Procedures) for individual incidents are aggregated:
- **Initial Access:** Not specified for the aggregate incidents.
- **Persistence:** *Not detailed in the provided summary data.*
- **Privilege Escalation:** *Not detailed in the provided summary data.*
- **Defense Evasion:** *Not detailed in the provided summary data.*
- **Credential Access:** *Not detailed in the provided summary data.*
- **Discovery:** *Not detailed in the provided summary data.*
- **Lateral Movement:** *Not detailed in the provided summary data.*
- **Collection:** Implied data collection supporting double extortion.
- **Exfiltration:** Implied data exfiltration tracked via DLS postings.
- **Impact:** Encryption/Disruption (implied by ransomware activity) and data exposure (implied by DLS listings).
## Impact Assessment
- **Financial:** Not quantified, but implied significant financial loss across 632 victims.
- **Data Breach:** High volume; 632 victim claims tracked in November 2024 alone, potentially involving sensitive corporate data (due to DLS presence).
- **Operational:** Disruption likely occurred for the 632 victim organizations, although specific downtime is not listed.
- **Reputational:** Significant reputational damage for all confirmed victims posting on DLS.
## Indicators of Compromise
*Specific IOCs (IPs, FQDNs, or file hashes) for Akira or RansomHub campaigns are not provided in this aggregated data overview.*
- **Network indicators:** None provided.
- **File indicators:** None provided.
- **Behavioral indicators:** Increased frequency of new victim postings on DLS by Akira and RansomHub compared to previous months.
## Response Actions
Individual organization response actions are not detailed in this trend report. The primary "response" noted is external monitoring by Corvus Insurance.
- **Containment measures:** *Not detailed.*
- **Eradication steps:** *Not detailed.*
- **Recovery actions:** *Not detailed.*
## Lessons Learned
- The ransomware ecosystem remains highly active, with established groups (Akira) or rapidly ascending groups (RansomHub) capable of driving record-breaking attack volumes.
- The top five ransomware groups accounted for nearly 50% of all observed claims in November 2024, indicating high centralization of threat activity.
- Claims posted on Data Leak Sites confirm the continued prevalence of double-extortion models.
## Recommendations
- Organizations must maintain elevated vigilance against known prolific ransomware operators like Akira and RansomHub.
- Implement or review multi-factor authentication and robust patch management to mitigate common initial access vectors used by these groups.
- Enhance network segmentation to limit the scope of lateral movement once an initial compromise is achieved.