As if 2020 could not get any worse, this year has also ushered in a dramatic uptick in ransomware attacks. On Dec. 13, BleepingComputer reported that the Habana Labs, which develops AI processors, allegedly suffered a cyber attack involving the Pay2Key ransomware. US ransomware attacks doubled (~98% increase) in the last 3 months, making it the #1 most targeted country for ransomware, followed by India, Sri Lanka, Russia and Turkey. According to UCSF's June 26 security update: While we stopped the attack as it was occurring, the actors launched malware that encrypted a limited number of servers within the School of Medicine, making them temporarily inaccessible. Ransomware attacks are targeting every industry globally, including highly regulated industries such as government and healthcare. The aggregate number of ransomware attacks decreased in Q2 2020, according to data from Coveware. NetWalker, also known as Mailto, is a ransomware strain that's thought to have made its criminal debut in August 2019. A Trump administration official told CNN that several hospitals have been targeted in the attacks over the past two days, and while it's still early, the official said the incidents may be connected. BleepingComputer reports that the attackers demanded more than 1,804 BTC — or what equates to well over $34 million (USD) — in exchange for access to their decryption tool. In a statement from the St. Lawrence Health Systems, the virus has been identified as a new variant of Ryuk ransomware, previously unknown to antivirus software providers and security agencies. Consequently, emergency response exercises also failed to provide employees with decision-making experience in dealing with cyberattacks. Ransomware is a type of malware, or malicious software, that encrypts a victim's files. The good news for Blackbaud is that they were able to discover and disrupt the attack, ultimately blocking them from their systems. But after Shirbit missed the first payment deadline, that rate increased to 100 BTC and, later, 200 BTC. It is not known who carried out the attacks, but overall, the incidents represent a solid expansion of hospital targets in a short period of time who have sought to take advantage of the crush facing hospitals in the wake of the global pandemic. Of course, this list is far from being complete list. Ryuk and Sodinokibi, perennially the most observed variants in Kroll’s cases, have been joined by Maze as the top three ransomware variants so far in 2020. According to the BleepingComputer article: “As part of this attack, the threat actors claim to have encrypted about 1,200 servers, stole 100 GB of unencrypted files, and deleted 20-30 TB Of backups.”. Further to the above, on October 1, 2020, OFAC issued an advisory to companies that pay or facilitate a ransom payment, warning them that ransomware attack victims, and third parties who facilitate payments may face sanctions. In 2020, we conducted a survey of IT managers in 5000 companies in 26 different countries and asked about ransomware attacks. Griffin Hospital in Derby, CT, is one of the most recent victims of a ransomware incident. Ransomware attacks against healthcare organizations are on the rise as their systems become a target for malicious actors. Federal agencies say cybercriminals could unleash a major ransomware assault against the U.S. health care system. Egregor is a ransomware gang that's been gaining notoriety over the past several months. The ransomware attack on Sky Lakes Medical Center was early in the year. Threat actor groups are taking advantage of the pandemic to target healthcare organizations. The Sodinokibi ransomware attacks so far can be fatal in terms of both severity and costs, costing organizations millions annually. While the Pittsburg Unified school district located Contra Costa County does exist, cybersecurity in education has a way to go in terms of suffering data breaches. The actor used commodity ransomware to carry out their attack. The official said ransomware attacks increased in terms of both severity and costs this year. Third-party computer forensic specialists were retained to assist in the investigation.