Ransomware
Need Immediate Assistance?
If your organization is experiencing a ransomware attack, security breach, or critical system disruption, our team is ready to respond and help minimize operational impact.
Prevention

Reduce risk by strengthening security posture and minimizing vulnerabilities.

Response

Contain threats quickly and coordinate recovery efforts during an active attack.

Recovery

Restore systems, rebuild infrastructure, and return operations to normal as quickly as possible.

Solutions
Need Immediate Assistance?
If your organization is experiencing a ransomware attack, security breach, or critical system disruption, our team is ready to respond and help minimize operational impact.
Prevention

Reduce risk by strengthening security posture and minimizing vulnerabilities.

Response

Contain threats quickly and coordinate recovery efforts during an active attack.

Recovery

Restore systems, rebuild infrastructure, and return operations to normal as quickly as possible.

Industries
Need Immediate Assistance?
If your organization is experiencing a ransomware attack, security breach, or critical system disruption, our team is ready to respond and help minimize operational impact.
Prevention

Reduce risk by strengthening security posture and minimizing vulnerabilities.

Response

Contain threats quickly and coordinate recovery efforts during an active attack.

Recovery

Restore systems, rebuild infrastructure, and return operations to normal as quickly as possible.

Home / Ransomware Attacks Saw Huge Increase in March 2023
Alvaka Resources

Ransomware Attacks Saw Huge Increase in March 2023

24×7×365 Rapid Response & Recovery

Share this post

Facebook
LinkedIn
Twitter X

According to NCC Group’s Global Threat Intelligence Team, ransomware attacks have seen a significant increase this year. In March 2023, ransomware attacks increased by over 90% compared to February and over 60% compared to March 2022. NCC Group stated that this is the highest number of ransomware attacks recorded in a single month. North America was the most targeted region, followed by Europe and Asia. The Industrial industry was hit the hardest, followed by Consumer Cyclicals and the Tech industry.

Cl0p Ransomware was responsible for almost 30% of all attacks in March, making it the most active Ransomware-as-a-Service group. Cl0p’s predecessor, known as CryptoMix, was notorious for targeting private companies, universities, and government institutions. Cl0p targeted larger organizations with advanced techniques and began using the double extortion method in 2020. LockBit 3.0 Ransomware and the Royal ransomware group followed Cl0p in the list of most active ransomware groups in March 2023.

NCC Group states that the sudden increase in attacks by Cl0p was due to vulnerability exploitations in Fortra GoAnywhere MFT. It is advised that organizations using GoAnywhere MFT should follow certain steps to prevent attacks, including installing the latest patch update, following steps in the GoAnywhere MFT security advisory (and contacting support if you need additional help), and monitoring for suspicious activity on admin accounts.

Matt Hull, NCC Group’s head of threat intelligence, warns that ransomware attacks are likely to continue to increase, and Cl0p is expected to be a critical and widespread threat for the remainder of 2023 if they continue to operate.

To protect against ransomware threats, organizations should be patching as often as possible, blocking common points of entry, creating offsite and offline backups, constantly monitoring for suspicious activity, being well-versed in your organization’s systems, exploring endpoint security packages, and isolating and removing malware, tools, and holes in the case of an attack.


Click HERE to more about our Ransomware Recovery Services! We are available 24×7, 365 days a year, to assist you with any of your ransomware needs.

Related Posts
AI Is Changing Who Is Worth Attacking: Why Smaller Businesses Need to Rethink Cybersecurity

Written by Sarah Accongio, Market Development Specialist at Alvaka For years,...

Cyber Criminal Unemployment? Something to Celebrate in the Unnerving Google GTIG Report

Written by Kevin B. McDonald, COO & CISO at Alvaka The...

Cisco CVE-2026-20079 Is Being Actively Exploited: What Organizations Need to Know

Cisco has confirmed active exploitation of CVE-2026-20079, a maximum-severity authentication bypass...