Significant percentage of Indian firms hit by ransomware in 2023: Report

Typically, ransomware attacks come with a timeline, threatening users that if ransomware demands are not fulfilled, the users will lose files

cybersecurity laptop working
The findings are derived from an independent survey of 5,000 IT decision makers across 14 countries, including 500 respondents in India. (Representative image)
Press Trust of India New Delhi
2 min read Last Updated : May 14 2024 | 3:06 PM IST

Nearly 64 per cent of Indian organisations surveyed were hit by ransomware attacks in 2023, a latest report by Sophos said on Tuesday, noting that while the attack rates fell year-on-year, the impact on victims actually intensified.

The average ransom demand was $4.8 million, with 62 per cent of demands exceeding $1 million.

The median ransom paid was $2 million, the report by the global cybersecurity solutions provider said.

Put simply, ransomware refers to malicious software or malware that seizes files on a computer, network share, backups, and server, and encrypts them, following which the attacker exhorts the user to cough up money to unlock the files.

Typically, ransomware attacks come with a timeline, threatening users that if ransomware demands are not fulfilled, the users will lose files.

According to the 'State of Ransomware in India 2024' report by Sophos, there has been a decrease in the rate of ransomware attacks against Indian organisations from the 73 per cent reported in last study (2022) to 64 per cent in 2023.

Notably though, "the impact on victims has intensified, with higher ransom demands and recovery costs compared to the previous year".

The findings are derived from an independent survey of 5,000 IT decision makers across 14 countries, including 500 respondents in India.

Conducted in January and February 2024, respondents were asked to answer based on their experiences in the previous 12 months.

For the first time, Indian organisations were found to be more likely to recover data by paying the ransom (65 per cent) than using backups (52 per cent).

The report revealed that 44 per cent of impacted computers on an average were encrypted in attacks against Indian victims.

"Thirty four per cent of attacks included data theft in addition to encryption, slightly down from 38 per cent the previous year. Excluding ransom payments, the average cost to recover from an attack was $1.35 million," Sophos said in a release.

As per the report, 61 per cent of victims were able to recover data within a week, up from 59 per cent in 2022. As many as 96 per cent reported the attack to authorities, with 70 per cent receiving investigation assistance.

"Prevention remains the most cost-effective ransomware strategy," Sunil Sharma, Vice President, Sales, India and SAARC, Sophos said.

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :ransomware attackRansomware cyber attacksIndian firms QIPIndian corporatesCyber spacecyber security

First Published: May 14 2024 | 3:06 PM IST

Next Story