Cyber insurer says ransomware attacks drove a spike in claim sizes

Avatar

A report published Thursday by cyber insurance provider Coalition found that although its customers made fewer claims in the first half of 2024 than the same period a year earlier, the size of those claims increased 14% — to an average loss of $122,000.

The jump in losses was “driven by a spike in ransomware severity,” the company said, adding that threat actors “targeted larger businesses and reaped the benefits with increased paydays.”

The average loss for ransomware claims was $353,000 — a 68% spike compared to the same period during the previous year, Coalition said.

The report isn’t all bad news, however. Ransomware claims among businesses with between $25 million and $100 million in revenue steadily declined over the past 12 months, for example, though Coalition expects that number to tick back up during the winter months that often see a surge in hacker activity. Additionally, ransomware gangs are showing a willingness to negotiate ransoms down significantly — often to less than half of their original ask.

The average ransom demand in the first half of 2024 was $1.3 million, but certain groups like Play and BlackSuit are known for higher average ransom demands — often above $2.5 million. 

About 40% of all Coalition policyholders paid ransoms after a ransomware attack. 

Although ransomware had especially pricey claims, the report noted that business email compromise was still the leading brand of cyber event that companies filed claims on, accounting for almost a third of all reported claims in the first half of 2024.

BEC, ransomware and funds transfer fraud together accounted for nearly 75% of all reported claims in the first half of 2024.

Other reports show that ransomware gangs earned at least $400 million in the first half of 2024 from ransom payments.

CybercrimeIndustryNewsNews Briefs
Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

 

Total
0
Shares
Previous Post

How Hybrid Password Attacks Work and How to Defend Against Them

Next Post

Cyberattack targets healthcare nonprofit overseeing 13 Colorado facilities

Related Posts

Webinar: Learn to Boost Cybersecurity with AI-Powered Vulnerability Management

The world of cybersecurity is in a constant state of flux. New vulnerabilities emerge daily, and attackers are becoming more sophisticated. In this high-stakes game, security leaders need every advantage they can get. That's where Artificial Intelligence (AI) comes in. AI isn't just a buzzword; it's a game-changer for vulnerability management. AI is poised to revolutionize vulnerability
Avatar
Read More

New CRON#TRAP Malware Infects Windows by Hiding in Linux VM to Evade Antivirus

Cybersecurity researchers have flagged a new malware campaign that infects Windows systems with a Linux virtual instance containing a backdoor capable of establishing remote access to the compromised hosts. The "intriguing" campaign, codenamed CRON#TRAP, starts with a malicious Windows shortcut (LNK) file likely distributed in the form of a ZIP archive via a phishing email. "What makes the CRON#
Avatar
Read More