Ransomware is becoming faster, quieter and identity-driven

Google's latest threat intelligence report highlights a clear shift in ransomware activity: attackers are moving away from noisy, encryption-led attacks toward quieter, faster campaigns focused on data theft and extortion. Rather than relying on malware, adversaries increasingly exploit compromised identities, legitimate tools and trusted relationships to gain access and move laterally. The report also notes that the ecosystem is becoming more scalable through ransomware-as-a-service, that initial access frequently comes via third-party software, exposed services or weak identity controls, and that time from intrusion to impact keeps shrinking.

What this means for your organisation

When attacks are carried out with valid accounts and tools already present in the environment, the activity resembles normal use. Defence shifts from detecting malware to understanding identities and access, particularly in cloud and SaaS environments. For leadership the question is no longer whether the company has antivirus, but whether it knows who has access to what, and how quickly it can respond.

Berigo recommends

  • Review privileged access and remove rights no longer justified by a role.
  • Introduce phishing-resistant multi-factor authentication on all administrative accounts.
  • Establish monitoring of identity events in cloud and SaaS, not only on clients and servers.
  • Rehearse an extortion scenario without encryption, where data is stolen and decisions must be made quickly.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch