Cyber Crime

Ransomware attacks hit 105 US local governments in 2022

In 2022, ransomware attacks targeted 105 state or municipal governments or agencies in the US, reads a report published by Emsisoft.

According to the “The State of Ransomware in the US: Report and Statistics 2022” report published by Emsisoft, the number of ransomware attacks against government, education and healthcare sector organizations is quite similar to the number of attacks in previous years.

The report aggregates data from disclosure statements, press reports, Tor leak sites, and third-party information feeds. Experts pointed out that some incidents will have escaped their attention and so the figures reported in the study could be just the tip of the iceberg.

It is important to note that figures reported in the study were dramatically affected by a single incident in Miller County, AK, where an infection of a mainframe caused the compromise of endpoints in 55 different counties.

Below are the attacks reported by Emsisoft:

  • 105 local governments
  • 44 universities and colleges
  • 45 school districts operating 1,981 schools
  • 25 healthcare providers operating 290 hospitals

“When it comes to cybersecurity incidents, it has always been hard to get accurate statistical information.” reads the report published by Emsisoft. “What data is available is based largely on publicly available reports, but not all incidents are made public, even in the public sector and, consequently, the true number of incidents in all sectors of the economy is and has always been higher than reported.”

The ransomware attack against local governments resulted in data theft in at least 27 of the 105 incidents (26 percent). The only local government known to have paid a ransom in 2022 was Quincy, MA., which paid a $500,000 ransom.

In 2022, 89 education sector organizations were impacted by ransomware, while in 2021 the number of impacted organizations in the same industry was 88. 

In at least 58 incidents (65 percent) the experts reported data breaches.

The most severe incident in 2022 was suffered by the Los Angeles Unified School District, which is the second-largest district in the U.S.

The report also states that 25 ransomware attacks involved hospitals and multi-hospital health systems, potentially impacting patient care at up to 290 hospitals.

The most significant incident of 2022 was the attack suffered by CommonSpirit Health, which resulted in the exposure of the personal data of 623,774 patients.

In at least 17 incidents (68 percent), threat actors exfiltrated data including Protected Health Information (PHI).

“Early ransomware attacks were simple and mostly automated. However, today’s attacks are often complex, human-directed events in which data is exfiltrated and encryption, if it happens at all, is the very last step in the attack chain.” concludes the report. “A better way of thinking about incidents is simply “data extortion events.” “Encryption-based data extortion” and “exfiltration-based data extortion,” which are not mutually exclusive, are subcategories to that.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, malware)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Experts warn of an ongoing malware campaign targeting WP-Automatic plugin

A critical vulnerability in the WordPress Automatic plugin is being exploited to inject backdoors and…

14 hours ago

Cryptocurrencies and cybercrime: A critical intermingling

As cryptocurrencies have grown in popularity, there has also been growing concern about cybercrime involvement…

16 hours ago

Kaiser Permanente data breach may have impacted 13.4 million patients

Healthcare service provider Kaiser Permanente disclosed a security breach that may impact 13.4 million individuals…

16 hours ago

Over 1,400 CrushFTP internet-facing servers vulnerable to CVE-2024-4040 bug

Over 1,400 CrushFTP internet-facing servers are vulnerable to attacks exploiting recently disclosed CVE-2024-4040 vulnerability. Over…

19 hours ago

Sweden’s liquor supply severely impacted by ransomware attack on logistics company

A ransomware attack on a Swedish logistics company Skanlog severely impacted the country's liquor supply. …

21 hours ago

CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalog

CISA adds Cisco ASA and FTD and CrushFTP VFS vulnerabilities to its Known Exploited Vulnerabilities…

1 day ago

This website uses cookies.