< Back to all clusters
[CRIME] · United States, United Kingdom · 13 sources

Ransomware attacks surge as compromised identities and AI tools fuel new threats

Sophos reports that 79% of ransomware incidents now begin with compromised identities, marking a shift from vulnerability exploits to credential theft. The same study notes that 56% of affected organisations had their data encrypted, with half of those paying the ransom. Cyber‑security experts warn that ransomware groups are increasingly using artificial‑intelligence techniques; the BlackMamba gang, for example, leverages AI to modify its code hourly and exploit a zero‑day in hospital management systems, disrupting services at over 50 hospitals across the United States and Europe.

In response, governments are moving to restrict ransom payments. The United Kingdom plans to ban payouts by public‑sector and critical‑infrastructure entities, while other jurisdictions debate similar measures. Industry guidance highlights mitigation steps such as continuous employee training, zero‑trust architectures, regular offline backups, and strong multi‑factor authentication. These combined trends point to a more sophisticated, identity‑driven ransomware ecosystem with broader economic and public‑health implications.