SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Story image
Over half of ransomware victims pay up - but does it work?
Fri, 9th Apr 2021
FYI, this story is more than a year old

More than half (56%) of ransomware victims paid the ransom to restore access to their data last year, according to new research.

A global study of 15,000 consumers conducted by global security company Kaspersky found 17% of those who did pay, paying the ransom did not guarantee the return of stolen data.

Kaspersky says as public awareness of potential cyberthreats grows, there is reason for optimism in the fight against ransomware.

Ransomware is a type of malware which criminals use to extort money. It holds data to ransom using encryption or by locking users out of their device.

The percentage of victims that paid the ransom to restore access to their data last year was highest among those aged 35-44; with two-thirds (65%) admitting to paying. This compares to just over half (52%) of those aged 16-24 and only 11% of those over the age of 55, showing that younger users are more likely to pay a ransom than those over 55.

Whether they paid or not, only 29% of victims were able to restore all their encrypted or blocked files following an attack. Half (50%) lost at least some files, 32% lost a significant amount, and 18% lost a small number of files. Meanwhile, 13% who did experience such an incident lost almost all their data.

“This data shows we have seen a significant proportion of consumers paying a ransom for their data over the past 12 months," says Marina Titova, head of consumer product marketing at Kaspersky.

"But handing over money doesn't guarantee the return of data, and only encourages cybercriminals to continue the practice.

"Therefore, we always recommend that those affected by ransomware do not pay as that money supports this scheme to thrive,” she says.

“Instead consumers should make sure to invest in initial protection and security for their devices and regularly back up all data. This will make the attack itself less appealing or lucrative to cybercriminals, reducing the use of the practice, and presenting a safer future for web users.

At present, around four-in-10 (39%) of those surveyed claimed they were aware of ransomware over the past 12 months. It's important that this number rises as remote working becomes more prolific. To better help consumers protect themselves as they learn more about this form of cyberattack, it is vital that they understand what to look out for, and what to do if they encounter ransomware.

Kaspersky recommends the following:

  • Do not pay the ransom if a device has been locked. Paying extortionate ransoms only encourages cybercriminals to continue their practice. Instead, contact your local law enforcement agency and report the attack
  • Try to find out the name of the ransomware Trojan. This information can help cybersecurity experts decrypt the threat and retain access to your files.
  • Visit noransom.kaspersky.com to find the latest decryptors, ransomware removal tools, and information on ransomware protection
  • Avoid clicking links in spam emails or on unfamiliar websites and do not open email attachments from senders you do not trust
  • Never insert USBs or other removal storage devices into your computer if you do not know where they came from
  • Protect your computer from ransomware with a comprehensive internet security solution like Kaspersky Internet Security
  • Backup your devices so your data will remain safe if you do experience a ransomware attack