CyOne Security AG
Luzern
Important Ransomware Trends 2023
- 07 August 2026
- 100%
- Permanent position
- Luzern
Job summary
Ransomware threats are escalating in 2023, impacting various sectors. Cybercriminals are evolving their tactics, presenting new challenges for organizations.
Tasks
- Understand emerging ransomware trends and their implications.
- Analyze the rise of double and triple extortion tactics.
- Explore the Ransomware as a Service (RaaS) industry growth.
Skills
- Experience in cybersecurity and threat analysis is essential.
- Strong analytical skills to assess cyber threats.
- Ability to stay updated on evolving cybercrime strategies.
Is this helpful?
About the job
The threat of ransomware continues to increase in 2023. Relevant software is spreading rapidly and cybercriminals are constantly developing their methods. Learn in the blog post which other ransomware trends will shape the coming year.
Ransomware made headlines in 2022. Many companies and authorities experienced a nasty surprise in recent months: they received a ransom demand and found that their data was encrypted – a nightmare for any organisation.
According to the National Cyber Security Centre (NCSC), ransomware is currently the greatest threat to Swiss organisations. In addition to the private sector, the public sector is also affected: in 2022, for example, Swissport, the Swiss Hospital Association, and the Lucerne Transport Network were extorted by cybercriminals.
"Hack-and-leak" extortion with double leverage
The threat of ransomware will continue to increase in 2023, also because the extortionists are constantly evolving their strategies. The dominant leverage for a long time was the key to make the encrypted data readable again. However, since victims sometimes manage to restore data from backups, additional leverage is now being used.
Often, data encryption is combined with a threat of publication ("hack-and-leak"): the cybercriminals announce the hack on their blog and run a countdown to the publication date. Such attacks are called double extortion because the perpetrators have two levers at their disposal.
The ransomware business is booming
Accordingly, current ransomware is not only capable of encrypting data but also exfiltrating it. The demand for such ransomware is so great that a real industry has emerged: Ransomware as a Service (RaaS) is now offered by various groups. These groups are active as hacktivists and cybercriminals themselves but also sell their software on the dark web.
The most popular RaaS solution is Lockbit. According to current reports from cybersecurity specialists, the "market leader" was responsible for the majority of ransomware attacks in 2022. Among the over 160 companies that appeared on Lockbit's extortion blog in October 2022 were also Swiss organisations.
Methods are becoming more radical
In 2023, attacks with multiple levers are expected to increase further. Triple extortion attacks are already being observed, where a Distributed Denial of Service (DDoS) attack is threatened as a third lever – an attack that would disable the website or other parts of the IT infrastructure. Another lever is the publication of customer data. Ransomware is also increasingly combined with wiper malware, which deliberately deletes data.
The number of ransomware attacks has recently increased steadily, as have the ransom amounts demanded. And the supply of RaaS solutions will continue to grow – not least because in September 2022 a frustrated Lockbit developer made the code of version 3.0 public. This is likely to cause ransomware to spread and develop even faster.
Which other malware trends will shape the current year? Read our knowledge update "Outlook 2023: The five most important malware trends".