25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Ransomware Groups Increasingly Targeting Poorly Secured and Outdated VPNs for Initial Access

Ransomware attacks continue to be conducted at elevated levels, with the number of new victims added to data leak sites increasing slightly (0.72%) in Q3, 2024 from the previous quarter, according to the 2024 Q3 Cyber Threat Report from Corvus. In Q3, 2024 Corvus tracked 1,257 new additions to data leak sites, down 1.64% from Q3, 2023.

There has been a marked change in the ransomware landscape, which is far more distributed than last year when a few highly prolific threat groups conducted the majority of attacks. Successful law enforcement operations against LockBit and ALPHV saw affiliates of both groups jump ship, and following the ransomware attack on Change Healthcare, the ALPHV operation was shut down pushing the remaining affiliates into joining other groups or starting up their own operations.

In Q3, 2024, there were 59 active ransomware groups, many of which were small-scale ransomware groups, although some highly active ransomware groups remain. The most active group in the quarter was RansomHub, which increased its activity by 160% with at least 195 successful attacks. RansomHub has been rapidly increasing its dominance, helped by the recruitment of experienced ransomware affiliates from other groups. In March 2024, RansomHub conducted fewer than 20 attacks, then increased to more than 45 attacks in July, and between 70 and 80 in August and September. Play ransomware was the second most active group with 93 victims, and there were 91 new LockBit 3.0 victims, less than half the number of LockBit victims in Q2, 2024. The Medusa and Akira ransomware groups round out the top 5 with each claiming between 40 and 50 victims.

Healthcare was the second most targeted industry sector behind construction and experienced a 12.8% increase in attacks from the previous quarter with 53 new victims, up from the 47 victims in Q2. While many ransomware groups have a policy of not attacking healthcare organizations, groups such as Play and Medusa are actively targeting healthcare organizations.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The most common initial access vector in Q3 was Virtual Private Networks (VPNs), which accounted for 28.7% of all claims. Victims have made it too easy for ransomware groups by failing to keep their VPN software up to date and having poorly security accounts. All too often ransomware groups can easily brute force VPNs due to the use of default usernames and weak passwords, combined with a lack of multi-factor authentication. The importance of MFA cannot be overstated. Corvus reports that around 75% of policyholders submitting a claim for a ransomware attack either did not have MFA, had not implemented MFA fully, or MFA coverage could not be determined.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist