Retail was the second-most targeted industry by ransomware last year of all sectors, after media, leisure, and entertainment sectors, a report has shown.

Globally, 77 percent of retail organizations surveyed were hit — a 75 percent increase from 2020.

This is also 11 percent more than the cross-sector average attack rate of 66 percent, according to global cybersecurity firm Sophos.

In 2021, the average ransom payment was $226,044, a 53 percent increase when compared to 2020 ($147,811).

“Retailers continue to suffer one of the highest rates of ransomware attacks of any industry. With more than three in four suffering an attack in 2021, it certainly brings a ransomware incident into the category of when not if,” said Chester Wisniewski, principal research scientist, Sophos.

Buy Me A Coffee

The report showed that only 28 percent of retail organizations targeted were able to stop their data from being encrypted.

“It’s likely that different threat groups are hitting different industries. Some of the low-skill ransomware groups ask for $50,000 to $200,000 in ransom payments, whereas the larger, more sophisticated attackers with increased visibility demand $1 million or more,” said Wisniewski.

In 2021, the overall cost to retail organizations to remediate a ransomware attack was $1.27 million, down from $1.97 million in 2020.

When compared to 2020, the amount of data recovered after paying the ransom decreased (from 67 percent to 62 percent), as did the percentage of retail organizations that got all their data back (from 9 percent to 5 percent).

READ
Chinese Hackers Breach Over 20,000 FortiGate Systems Worldwide in Extensive Cyber Espionage Campaign