Increased Ransomware on SMOs
In today’s SensCy Cyber Brief, the SensCy cybersecurity team is investigating the increase in ransomware attacks on Small and Medium Organizations (SMO) in the U.S.
Although these cases don’t typically make national headlines—unlike when a ransomware attack delays patient care at hospitals across the U.S. or when the City of Dallas was struck by ransomware with systems still down a week later—SMOs are a primary target for ransomware groups. According to a report by ransomware recovery specialists Coveware, 82% of ransomware attacks target small businesses, and organizations with fewer than 1,000 employees are most at risk.
The SensCy team is observing a change in tactics, techniques, and procedures regarding ransomware gangs that will likely increase the number of attacks on SMOs. The primary concern for ransomware gangs is media exposure that attracts the attention of Law Enforcement. By targeting SMOs, these ransomware gangs can reduce their media exposure and risk.
Groups like H0lyGh0st, based in North Korea and allegedly state-sponsored, have been linked to attacks on large banks and crypto platforms. However, Microsoft released a deep analysis of their behavior, showing an increase in ransomware attacks on SMOs in the U.S. where they stole data before deploying the ransomware encryption to the infected systems. The SensCy team believes the current geopolitical landscape makes it highly likely for this trend to continue.
Key Takeaways
- Target Shift: Ransomware gangs are shifting focus from large enterprises to Small and Medium Organizations (SMOs), with 82% of attacks now targeting small businesses.
- Stealth Tactics: Attackers target smaller entities to avoid the media attention and law enforcement scrutiny that comes with high-profile breaches.
- Vulnerable Entry: The primary attack vector is Remote Desktop Protocol (RDP), exploited through weak passwords, misconfigured security, or phishing.
- Essential Defense: To survive an attack, businesses must maintain offline, encrypted data backups and provide consistent cybersecurity awareness training for employees.
What vectors do the gangs use and how to protect your company?
The research by Coveware found that the primary ransomware attack vector used by ransomware gangs is Remote Desktop Protocol (RDP) – a tool used by IT to access an employee’s computer. Since ransomware attacks are hitting small businesses, following experts’ top defense tips regarding RDP security is vital. The cause of entry is often weak passwords on administrator accounts, misconfigured endpoint security, or phishing.
Protecting your data is crucial to recover from ransomware attacks; having your data backups separate from your network (offline, cloud) is a good starting point. You should also make sure that your backups are encrypted and that you have a recovery system in place that is tested regularly.
Strong password policies and consistent awareness training for your employees are also critical. Humans will always be the most valuable but vulnerable asset to your organization. Make sure to contact your SensCy Client Advocate for any questions about our cyber policy and awareness training platform. It is also important to understand the limits of your coverage, specifically regarding legal precedents like the Ohio Court ruling that non-physical software damage in a ransomware attack is not covered under insurance.
Frequently Asked Questions (FAQ)
1. Why are hackers targeting small businesses (SMOs) instead of big corporations?
Hackers target SMOs because they often have weaker cybersecurity defenses than large corporations, making them easier to breach. Additionally, attacking smaller companies attracts less attention from the FBI and major news outlets, allowing the gangs to operate longer without being shut down.
2. What is Remote Desktop Protocol (RDP)?
RDP is a technical protocol that allows a user (usually IT staff or remote employees) to connect to another computer over a network connection. Hackers scan the internet for computers with “open” RDP ports protected only by weak passwords to gain control of the system.
3. Why must backups be “separate” from the network?
Modern ransomware is designed to find and encrypt backups if they are connected to the main network. If your backups are “offline” (unplugged or on an isolated cloud system), the ransomware cannot reach them, allowing you to restore your data without paying the ransom.
4. Does cyber insurance cover all ransomware damages?
Not always. Policies vary significantly. Some policies cover the ransom payment, while others only cover recovery costs. As noted in the article, some courts have ruled that software damage isn’t “physical damage,” potentially voiding certain claims. It is crucial to review your specific policy details.
To read the Coveware report, click here.
To read the Microsoft report, click here.

