Global Ransomware Attacks Hit 4,744 in H1, Q2 Surges 48% — BigGo Finance | #ransomware | #cybercrime


Global ransomware incidents surged nearly 50% year-over-year in the first half of this year. Notably, attackers have shifted their strategy away from malware itself toward exploiting corporate security vulnerabilities and stolen credentials, driving the spread of “common infrastructure attacks” that target shared infrastructure across multiple organizations, according to new analysis.

SK Shields’ KARA (Korea Anti Ransomware Alliance) ransomware trend report, published on the 21st, tallied 4,744 global ransomware incidents in the first half of this year. Second-quarter damage volume rose approximately 48% compared to the same period last year.

SK Shields analyzed that the core infiltration vector for recent ransomware attacks has moved from malware itself to exploitation of corporate security vulnerabilities and compromised accounts. Attackers are leveraging essential business infrastructure—including virtual private networks (VPNs), business productivity platforms, and management systems—to secure initial access and then expand the scope of damage.

Attacks on Common Infrastructure Multiply

The first half of this year saw a wave of attacks targeting shared platforms and infrastructure. The Qilin ransomware group exploited VPN vulnerabilities to inflict damage on a global automaker and a UK medical testing services company. ShinyHunters and Clop reportedly attempted large-scale breaches by targeting business platforms and management systems used by multiple organizations.

As VPNs, Software-as-a-Service (SaaS) offerings, business platforms, and management systems shared across multiple enterprises emerge as primary attack targets, “Common Infrastructure Attacks”—where a single vulnerability or account compromise cascades into damage across multiple organizations—are proliferating. When systems shared by multiple companies are breached, the damage can spread in a chain reaction.

The report placed particular emphasis on the importance of managing internet-exposed systems and accounts in ransomware defense. Attackers are increasingly targeting vulnerabilities in internet-connected systems or using stolen credentials to penetrate corporate networks. In South Korea, attacks targeting multiple companies simultaneously through Managed Service Providers (MSPs) have been confirmed, underscoring the growing risk that a single vulnerability or account breach can lead to widespread damage across numerous organizations.

Building Response Frameworks

SK Shields stressed the importance of auditing externally exposed assets through Attack Surface Management (ASM) and establishing real-time detection and response capabilities based on Managed Detection & Response (MDR). Continuous monitoring of internet-connected assets—including VPNs, firewalls, servers, and remote access systems—along with rapid security patching and multi-factor authentication (MFA) enforcement are essential, the company said.

SK Shields continuously monitors externally exposed assets and vulnerabilities through its ASM service, while its MDR service provides 24/7 threat monitoring by security experts covering detection, analysis, and response. The company also supports early identification of anomalous indicators during ransomware attack sequences—such as privilege escalation, credential theft, and data exfiltration attempts—as well as forensic analysis and recurrence prevention planning in the event of an incident.

Kim Byung-moo, Vice President and Head of SK Shields’ Cyber Business Division, said: “Recent ransomware attacks are increasingly targeting common infrastructure shared by multiple organizations rather than individual companies. Since a single vulnerability or account compromise can trigger cascading damage, enterprises must proactively audit their externally exposed assets and account management systems while strengthening real-time detection and response capabilities to build cyber resilience.”



Click Here For The Original Source.

——————————————————–

..........

.

.