Global Ransomware Victims Reach 4,744 in First Half, Up 14% From a Year Earlier
IT DAILY · · 3 views
✦ AI Summary
Global ransomware victims in the first half of this year totaled 4,744, up from 4,131 in the same period last year.
Attacks focused more on exploiting vulnerabilities and stealing accounts against core infrastructure such as VPNs, work platforms, and management systems than on malware distribution.
The medical industry was also a major target, and the University of Mississippi Medical Center, Chonnam National University Hospital, and Kangwon National University Hospital were hit by ransomware.
Global ransomware victims topped 4,000 in the first half of this year, data showed. In terms of attack types, intrusions based on exploiting vulnerabilities and stealing accounts stood out more than malware distribution.
SK Shieldus announced the "2026 First-Half KARA Ransomware Trends Report" on the 21st. KARA stands for Korea Anti Ransomware Alliance.
The report includes an analysis of global ransomware attack trends and major cases in the first half of 2026. According to the report's tally, global ransomware victims in the first half of this year totaled 4,744, up from 4,131 in the same period last year.
The year-over-year increase was 14.84%. The first quarter fell slightly from last year, but the second quarter rose about 48% from 1,556 cases in the same period last year.
SK Shieldus said the sharp increase in the second quarter of 2026 was driven by a base effect from the unusually low number of cases in the second quarter of 2025. It also said that, on a quarterly trend basis, the overall high level was maintained in the first half of 2026.
Ransomware attack tactics changed this year. Targets shifted to core infrastructure such as VPNs, work platforms, and management systems. If an attack succeeds, the attacker can access the internal network, secure administrator privileges, and steal data, causing severe damage to companies.
Infrastructure access methods also shifted away from malware distribution and toward exploiting security vulnerabilities and stealing accounts. The main targets of exploitation were Zero-day vulnerabilities and high-risk vulnerabilities that could bypass authentication procedures. The successive emergence of high-risk vulnerabilities led to larger-scale attacks and faster attack speeds.
In this quarter's ransomware trends, the Clop ransomware group was cited for allegedly exploiting a Zero-day vulnerability in Oracle E-Business Suite. The group said the scale of the damage was around 100 organizations, and it also disclosed a Torrent distribution route for the stolen data. As the data distribution route was disclosed, the intensity of the extortion also appears to have increased.
Ransomware attacks targeting the medical industry also stood out. The medical industry was identified as a sector vulnerable to extortion because interruptions in treatment can create patient safety issues. In fact, the University of Mississippi Medical Center was hit by an attack from the Medusa group, and the resulting fallout forced the closure of 36 affiliated clinics, disrupting care. In South Korea, Chonnam National University Hospital and Kangwon National University Hospital were also infected by ransomware in January, and both hospitals had problems operating their PACS systems.
SK Shieldus urged companies to prepare for such infrastructure-targeting attack strategies. It recommended promptly applying security patches to externally exposed business systems and emphasized strengthening MFA for all account authentication. It also stressed the need for regular checks of authentication tokens related to third-party products and dormant accounts.
Kim Byung-moo, head of SK Shieldus's Cyber Business Division and vice president, said recent ransomware targets are shifting from individual companies to shared infrastructure used by multiple organizations. He said that in such an environment, a single vulnerability or account compromise could trigger cascading damage, and he cited inspection of externally exposed assets, review of account management systems, and strengthening real-time detection and response capabilities as corporate priorities.
Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241128
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.