all-in-one privacy solution":["Proton Unlimited — комплексное решение для защиты данных"],"Black Friday":["Черная пятница"],"No ads. Privacy by default.":["Без рекламы. Гарантия конфиденциальности"],"People before profits":["Люди важнее прибыли"],"Security through transparency":["Безопасность, основанная на прозрачности"],"The best Proton Mail ${ BLACK_FRIDAY } deals":["${ BLACK_FRIDAY }: лучшие предложения Proton Mail"],"The world’s only community- supported email service":["Единственный в мире сервис электронной почты с поддержкой сообщества"]},"specialoffer:limited":{"${ hours } hour":["${ hours } час","${ hours } часа","${ hours } часов","${ hours } часа"],"${ hoursLeft }, ${ minutesLeft } and ${ secondsLeft } left":["Осталось ${ hoursLeft }, ${ minutesLeft } и ${ secondsLeft }"],"${ minutes } minute":["${ minutes } минута","${ minutes } минуты","${ minutes } минут","${ minutes } минуты"],"${ seconds } second":["${ seconds } секунда","${ seconds } секунды","${ seconds } секунд","${ seconds } секунды"],"Limited time offer":["Ограниченное по времени предложение"]},"specialoffer:listitem":{"Create multiple addresses":["Создавайте несколько адресов"],"Hide-my-email aliases":["Создавайте алиасы hide-my-email"],"Quickly unsubscribe from newsletters":["С легкостью отменяйте подписку на рассылки"],"Use your own domain name":["Используйте собственное доменное имя"]},"specialoffer:logos":{"As featured in":["О нас в СМИ"]},"specialoffer:metadescription":{"Get an encrypted email that protects your privacy":["Электронная почта, защищающая вашу конфиденциальность"]},"specialoffer:metatitle":{"Proton Mail Black Friday Sale - Up to 40% off":["Черная пятница в Proton Mail: скидки до 40 %"]},"specialoffer:newmetadescription":{"Get up to 40% off Proton Mail subscriptions this Black Friday. Find great deals on our secure end-to-end encrypted email plans.":["Получите Proton Mail со скидкой до 40 %. Не пропустите выгодные предложения на планы безопасной электронной почты, зашифрованной сквозным шифрованием, в честь «черной пятницы»."]},"specialoffer:newmetatitle":{"Proton Mail Black Friday sale | Up to 40% off secure email":["«Черная пятница» в Proton Mail | Скидки до 40 %"]},"specialoffer:note":{"* Billed at ${ TOTAL_SUM } for the first year":["* ${ TOTAL_SUM } за первый год."],"*Billed at ${ TOTAL_SUM } for the first 2 years":["* ${ TOTAL_SUM } за первые два года."],"30-day money-back guarantee":["Гарантия возврата средств в течение 30 дней"],"Billed at ${ TOTAL_SUM } for the first 2 years":["${ TOTAL_SUM } за первые 2 года"],"Billed at ${ TOTAL_SUM } for the first year":["${ TOTAL_SUM } за первый год"],"You save ${ SAVE_SUM }":["Вы экономите ${ SAVE_SUM }."]},"specialoffer:off":{"${ PERCENT_OFF } off":["–${ PERCENT_OFF }"]},"specialoffer:testimonial":{"I love my ProtonMail":["Обожаю ProtonMail!"],"My favorite email service":["Мой любимый сервис электронной почты"],"Thanks Proton for keeping us all safe in the complicated internet universe.":["Спасибо Proton за защиту в запутанном интернет-пространстве."],"You get what you pay for. In the case of big tech, if you pay nothing, you get used. I quit using Gmail and switched to @ProtonMail":["Полностью оправданное вложение денег. Бигтех-компании используют тебя, если ты им не платишь. Поэтому я перешла с Gmail на @ProtonMail."]},"specialoffer:time":{"Days":["дн."],"Hours":["ч."],"Min":["мин."]},"specialoffer:title":{"And much more":["И многое другое"],"Safe from trackers":["Защита от трекеров"],"Stay organized":["Будьте организованными"],"Black Friday email deals":["Безопасная почта для покупок в «черную пятницу»"],"Don’t just take our word for it":["Отзывы наших клиентов"],"Make your inbox yours":["Сделайте свой почтовый ящик вашим"],"Our story":["Наша история"],"Transfer your data from Google in one click":["Перенесите данные из Gmail в одно нажатие"]},"specialoffer:tooltip":{"Access blocked content and browse privately. Includes ${ TOTAL_VPN_SERVERS }+ servers in ${ TOTAL_VPN_COUNTRIES }+ countries, connect up to 10 devices, access worldwide streaming services, malware and ad-blocker, and more.":["Сохраняйте конфиденциальность в интернете и получайте доступ к заблокированному контенту. Включает ${ TOTAL_VPN_SERVERS } серверов более чем в ${ TOTAL_VPN_COUNTRIES } странах с возможностью подключения на 10 устройствах, доступ к стриминговым платформам со всего мира, блокировщик рекламы, функцию защиты от вредоносных программ и другие преимущества."],"Easily share your calendar with your family, friends or colleagues, and view external calendars.":["Предоставляйте доступ к календарю родственникам, друзьям и коллегам, а также просматривайте календари других сервисов"],"Includes support for 1 custom email domain, 10 email addresses, 10 hide-my-email aliases, calendar sharing, and more.":["Включает поддержку 1 пользовательского домена, 10 адресов электронной почты, 10 алиасов hide-my-email, совместный доступ к календарю и другие преимущества."],"Includes support for 3 custom email domains, 15 email addresses, unlimited hide-my-email aliases, calendar sharing, and more.":["Включает поддержку трех пользовательских доменов, 15 адресов электронной почты, неограниченного числа алиасов hide-my-email, совместный доступ к календарю и другие преимущества."],"Manage up to 25 calendars, mobile apps, secured with end-to-end encryption, 1-click calendar import from Google, and more.":["До 25 календарей, мобильные приложения, сквозное шифрование, удобный перенос данных из Google Календаря и другие преимущества"]},"Status banner":{"Learn more":["Подробнее"],"Please note that at the moment we are experiencing issues with the ${ issues[0] } service.":["Сейчас при использовании сервиса ${ issues[0] } могут возникать проблемы."],"We are experiencing issues with one or more services at the moment.":["При использовании одного или нескольких сервисов могут возникать проблемы."]},"Status Banner":{"At the moment we are experiencing issues with the Proton VPN service":["При использовании сервиса Proton VPN могут возникать проблемы"],"Learn more":["Подробнее"]},"steps":{"Step":["Шаг"]},"suggestions":{"Suggestions":["Предложения"]},"Support":{"Sub category":["Подкатегория","Подкатегории","Подкатегорий","Подкатегорий"]},"Support article":{"${ readingTime } min":["${ readingTime } мин.","${ readingTime } мин.","${ readingTime } мин.","${ readingTime } мин."],"Category":["Категория","Категории","Категорий","Категорий"],"Didn’t find what you were looking for?":["Не нашли желаемый контент?"],"General contact":["Общие контакты"],"Get help":["Получить помощь"],"Legal contact":["Контакты юридического отдела"],"Media contact":["Контакты для прессы"],"Partnerships contact":["Контакты по вопросам партнерства"],"Reading":["Чтение"]},"Support Form Platform option":{"VPN for Android TV":["VPN для Android TV"],"VPN for Apple TV":["VPN для Apple TV"],"VPN for Chromebook":["VPN для Chromebook"]},"Support troubleshooting":{"App version":["Версия приложения"],"Browser":["Браузер"],"Check if this helps":["Возможно, нужный ответ найдется здесь"],"Choose a product":["Выберите продукт"],"Did this solve your issue?":["Удалось ли нам решить вашу проблему?"],"Faster assistance is just a few clicks away":["Пара нажатий, и вы получите быструю помощь"],"How can we help?":["Чем мы можем помочь?"],"No, contact support":["Нет, связаться со службой поддержки"],"Please fill out one field after another":["Заполните поля по порядку"],"Please make your selections":["Отметьте подходящие варианты"],"Proton account":["Аккаунт Proton"],"Proton for Business":["Proton for Business"],"Thank you for your feedback":["Спасибо за отзыв!"],"What can we help with?":["Какая помощь требуется?"],"Yes":["Да"]},"support_modal_search_query":{"Search query":["Поисковый запрос"]},"support_search_button":{"Search":["Найти"]},"support_search_i_am_looking_for":{"I'm looking for":["Я ищу"]},"SupportForm":{"For a faster resolution, please report the issue from the Bridge app: Help > Report a problem.":["Чтобы быстро устранить проблему в приложении Bridge, выберите «Справка» > «Сообщить о проблеме»."],"Information":["Информация"]},"SupportForm:option":{"Account Security":["Безопасность аккаунта"],"Contacts":["Контакты"],"Custom email domain":["Пользовательский домен адреса электронной почты"],"Email delivery and Spam":["Доставка электронных писем и спам"],"Encryption":["Шифрование"],"Login and password":["Имя пользователя и пароль"],"Merge aliases and accounts":["Объединение псевдонимов и аккаунтов"],"Migrate to Proton":["Переход на Proton"],"Notifications":["Уведомления"],"Other":["Другое"],"Plans and billing":["Тарифы и оплата"],"Proton for Business":["Proton for Business"],"Sign up":["Регистрация"],"Storage":["Хранилище"],"Users, addresses, and identities":["Пользователи, адреса и личные данные"]},"SupportForm:optionIntro":{"Select a topic":["Выберите тему"]},"Testimonial":{"Awards":["Награды"],"Customers":["Клиенты"],"Featured":["Что о нас говорят"],"Go to testimonial source":["Перейти к источнику отзыва"],"Open source of award":["Узнать, кто выдал награду"],"Open source of quote":["Узнать, откуда цитата"],"Reviews":["Отзывы"],"Videos":["видео."],"Watch on TikTok":["Смотреть в TikTok"],"Watch on YouTube":["Смотреть на YouTube"]},"TestimonialCategory":{"Awards":["Награды"],"Customers":["Клиенты"],"Featured":["Что о нас говорят"],"Media":["СМИ"],"Reviews":["Отзывы"],"Videos":["видео."]},"Text":{"If you need help, check out our ${ supportLink }.":["Если вам нужна помощь, перейдите в ${ supportLink }."],"The page you’re looking for might have been removed, or it could be an\nold link.":["Возможно, страница удалена\nили у вас устаревшая ссылка."],"Your question may already have an answer in our knowledge base:":["Возможно, ответ на ваш вопрос уже есть в нашей базе знаний:"]},"Title":{"On this page":["На этой странице"],"Related articles":["Статьи по теме"],"Share ${ thisPage }":["Поделиться ${ thisPage }"],"Switch to Proton Pass - Contact us":["Переход на Proton Pass — свяжитесь с нами"],"Thank you!":["Спасибо!"],"this page":["этой страницей"]},"tooltip_vpn":{"Access blocked content and browse privately. Includes ${ TOTAL_VPN_SERVERS }+ servers in ${ TOTAL_VPN_COUNTRIES }+ countries, highest VPN speed, ${ TOTAL_VPN_CONNECTIONS } VPN connections, worldwide streaming services, malware and ad-blocker, and more.":["Получайте доступ к заблокированному контенту, просматривайте страницы анонимно и пользуйтесь стриминговыми сервисами со всего мира. Мы предлагаем ${ TOTAL_VPN_SERVERS } серверов более чем в ${ TOTAL_VPN_COUNTRIES } странах, высочайшую скорость VPN, ${ TOTAL_VPN_CONNECTIONS } VPN-подключений, защиту от вредоносных программ, блокировщик рекламы и многое другое."]},"vpn_servers":{"Get Proton VPN Plus":["Получить Proton VPN Plus"]},"wallet_signup_2024:Action":{"Get Proton Wallet":["Получить Proton Wallet"]},"wallet_signup_2024:Homepage hero product link title":{"Wallet":["Wallet"]},"wallet_signup_2024:Homepage product navigation bar":{"Wallet":["Wallet"]},"wallet_signup_2024:menu item":{"Bitcoin guide":["Руководство по Bitcoin"],"Proton Wallet news":["Proton Wallet: новости"],"Proton Wallet support":["Proton Wallet: поддержка"]},"wallet_signup_2024:Pricing":{"Includes everything in Proton Unlimited and":["Включены все функции Proton Unlimited и"],"Limited availability":["Доступ ограничен"],"The easiest way to securely own, send, and receive Bitcoin":["Самый простой способ безопасно хранить, получать и отправлять Bitcoin"]},"wallet_signup_2024:ProductRange":{"Discover Proton Wallet":["Знакомство с Proton Wallet"],"Store and transact Bitcoin privately with an encrypted self-custody wallet.":["Храните и переводите Bitcoin с помощью некастодиального кошелька с шифрованием."]},"wallet_signup_2024:wallet bitcoin":{"Learn about Bitcoin, the Internet's value network.":["Рассказываем о сети создания ценности в Интернете — Bitcoin."]},"wallet_signup_2024:wallet overview":{"Ensure you're always in control of your Bitcoin.":["Обеспечьте полный контроль над своими средствами в Bitcoin."]},"wallet_signup_2024:wallet security":{"The encrypted, open-source wallet that puts you in control.":["Кошелёк с шифрованием и открытым исходным кодом, который контролируете только вы."]}}},"base":"blog","cdn":{"enabledForAssets":true,"enabledForImages":true,"url":"https://pmecdn.protonweb.com/"},"unleashApi":"https://account.proton.me/api"};
window.frameworkContext = frameworkContext;
const context = frameworkContext.base === '' ? '' : `${frameworkContext.base}/`;
window.__toAssetUrl = (filename) => {
if (frameworkContext.cdn !== undefined && frameworkContext.cdn.enabledForAssets === true) {
return `${frameworkContext.cdn.url}${context}${filename}`;
} else {
return `/${context}${filename}`;
}
};
})();
What is a ransomware attack? (and 11 famous examples) | Proton
Ransomware attacks are a serious concern for organizations. In these attacks, cybercriminals typically encrypt a company’s data, making it inaccessible until a ransom is paid.
These breaches can do far more than disrupt daily operations. Suffering a ransomware attack both exposes an organization’s security shortcomings and allows sensitive information to fall into the hands of bad actors. It can cause significant financial and reputational damage that can be harder to recover than the data itself — many organizations lose thousands, if not millions, of dollars in the aftermath.
This article will explore what a ransomware attack is, recount some of the most well-known incidents, and outline how you can protect yourself and your organization from an attack by using secure business solutions.
Ransomware is a form of malware that encrypts a victim’s data or locks them out of their files and systems. The attackers behind it usually demand payment from their victims (often in cryptocurrency) to let them regain access and avoid sensitive data leaks.
Attack methods often involve exposed passwords or phishing emails and malicious downloads that act as Trojan horses for bad actors to gain access to an organization’s systems. Common targets include government institutions, corporations, hospitals, and prominent individuals for whom such attacks can cause major financial losses and operational disruptions.
Most legal authorities encourage victims not to give in to ransom requests. Even if you pay the ransom, there is no guarantee the attackers will release the data, and paying creates an incentive to target you again. Ultimately, the decision whether to pay depends on your circumstances and should only be a last resort. The best way to avoid paying a ransom is to keep your network secure in the first place.
Famous ransomware attacks
In 2023, the total amount of money received by ransomware attackers amounted to $1.1 billion(новое окно) — an increase of over 140% from the previous year. These attacks are why many organizations enforce security measures such as end-to-end encryption or multi-factor authentication. Some even hold dedicated budgets to pay attackers whenever they strike.
Here are some of the most well-known ransomware attacks to occur throughout the past decade.
Johnson Controls ransomware attack
In 2023, attackers targeted the US building automation and security company Johnson Controls. The attackers, believed to be ransomware group Dark Angels, caused significant disruptions and limitations to the organization’s operations. It is reported that the attackers stole 27 TB of data and encrypted the company’s servers and other devices. They then demanded a $51 million ransom(новое окно). This breach was particularly concerning for the Department of Homeland Security(новое окно), with which Johnson Controls holds classified contracts. While it is unclear whether Johnson Controls paid the ransom, the company reported(новое окно) that the response and remediation costs were approximately $27 million.
ICBC Bank ransomware attack
The Industrial and Commercial Bank of China (ICBC) is the largest bank in the world(новое окно) with assets amounting to 6.3 trillion dollars in 2023 — the same year that ICBC’s US unit was victim of a ransomware attack claimed by cybercriminal group LockBit. The attack disrupted the bank’s financial services, blocking access to customer data and transaction systems. As a result ICBC became temporarily indebted to BNY Mellon for $9 billion(новое окно) in unsettled trades, and employees were forced to use Gmail because their corporate email was no longer available — further exposing the bank to the Pandora’s box of Google privacy concerns. According to LockBit, ICBC paid a ransom to minimize the significant disruption already caused; however, the exact value of the payment has not been confirmed.
WannaCry ransomware attack
In 2017, attackers used the WannaCry ransomware cryptoworm to exploit a vulnerability in Windows operating systems. The attack affected over 200,000 systems globally, including hospitals, governments, and businesses. It resulted in an estimated $4 billion in damages worldwide and was one of the largest ransomware attacks in history. Victims included the National Health Service (NHS) in England and Scotland. Around 70,000 NHS devices, including MRI scanners and blood-storage refrigerators, are estimated to have been affected by WannaCry, which resulted in some non-critical patients having to be turned away for care. The attack caused controversy when it was revealed that the The National Security Agency already knew about the vulnerability but, rather than share the information with Microsoft, used it for their own advantage.
Fulton County ransomware attack
The 2017 attack on government infrastructure in Fulton County, Georgia(новое окно) led to numerous public service disruptions, partially within the county court system. The attack was claimed by LockBit, which, in a bid for ransom, threatened(новое окно) to “demonstrate how local structures negligently handled information protection” and reveal documents marked as confidential alongside lists of those responsible for that confidentiality. The data accessed by LockBit included Fulton County residents’ personal information and records relating to former President Donald Trump’s pending criminal case. Despite the threat, the county — which was working with legal officials — refused to pay the ransom(новое окно) and worked to gradually restore its systems.
Philhealth Medusa ransomware attack
Philhealth is a state-owned corporation that provides universal health coverage in the Philippines. In 2023, ransomware group Medusa stole almost 750 GB of data from the corporation, potentially affecting millions(новое окно) of Philhealth members. The stolen data included sensitive medical information, patient names, dates of birth, and addresses. In response to the ransomware attack, the corporation refused to pay the demanded ransom of $300,000, and instead issued an alert(новое окно) to those who may have been affected, informing them of the need to monitor their credit card reports and financial accounts.
British Library ransomware attack
In 2023, a ransomware attack encrypted the British Library’s data and systems, disrupting access to digital resources and archives. When the library did not give in to the attacker’s demands for payment, the data — which included the personal data of the library’s staff and users — was put up for auction and later dumped on the dark web. The attackers also destroyed some servers to inhibit system recovery and to cover their tracks, deleting around 600 GB of data in the process. A report(новое окно) published by the British Library identified several vulnerabilities that may have facilitated the attack. These included a reliance on third-party support and a lack of multi-factor authentication measures for internal systems. However, the exact point and method of entry has not been confirmed.
Colonial Pipeline ransomware attack
Colonial Pipeline is the largest fuel pipeline in the US and supplies almost half of the gasoline on the East Coast. A 2021 ransomware attack on the corporation caused widespread fuel shortages as it ceased operations for several days, prompting gasoline panic-buying and price spikes(новое окно) in some states. Colonial Pipeline paid a ransom(новое окно) of $4.4 million in the form of 75 bitcoin to the attackers, however around 64 bitcoin of the ransom was later recovered by the DOJ. The attack is believed to have been facilitated by an employee password that was found on the dark web and demonstrates the importance of secure password management for businesses.
HCL Technologies ransomware attack
In 2023, one of the world’s largest IT companies, HCL Technologies, was hit by a ransomware attack that impacted its global operations, disrupted client services, and lost confidential data.
On the day the attack occurred, shares of the company fell on the National Stock Exchange of India. While the attack did not seem to significantly disrupt HCL Technologies’ operations, it does highlight the potential vulnerabilities of cloud environments, which can be targets for attackers who identify vulnerabilities during the data upload and retrieval process. End-to-end encrypted cloud environments, like Proton Drive, protect against these risks by encrypting data throughout its journey, so that even if it is intercepted, it cannot be accessed without authorization.
CDK ransomware attack
Automotive software company CDK Global suffered what it called a “cyber ransom event(новое окно)” in 2023. The attackers encrypted CDK Global’s data, disrupting thousands of auto dealerships that use the company’s software for operations, including scheduling, sales, and orders. It is reported that the company paid a $25 million ransom(новое окно) to the attackers two days after the attack. Despite this it still faced a lengthy recovery process, reputational damage, and questions surrounding potential customer data breaches. Multiple dealerships affected by the breach filed complaints(новое окно) with the Securities and Exchange Commission.
Ascension ransomware attack
In 2022, major US healthcare organization Ascension(новое окно) was attacked by Black Basta.The attack disrupted access to digital health records, phone systems, and systems used to order tests, procedures, and medication. As a result, doctors and nurses were faced with significant challenges in their ability to treat patients for multiple weeks. The attack is believed to have occurred after an individual working in one of Ascension’s facilities accidentally downloaded a malicious file(новое окно).
Sony ransomware attack
In 2014, Sony Pictures was attacked by a group dubbed Guardians of Peace. During the attack, vast amounts of confidential information were lost or leaked, including sensitive employee data and unreleased media. US investigators have attributed blame for the attack to North Korean hackers and believe it was in response to plans to release The Interview, a movie that depicts the fictional assassination of leader Kim Jong Un. In response to the attack, Sony Pictures(новое окно) canceled its plans to release the movie in theaters as planned, which raised numerous questions on the topic of free speech and expression.
Protect your organization from a ransomware attack
From accidental downloads to exposed passwords, many ransomware attacks occur as a result of human error. So, the best way to protect your organization from a ransomware attack is by implementing strict security practices for you and your employees to follow — such as not downloading files sent by external email addresses or using multi-factor authentication to access internal systems.
Alongside this, one of the most reliable ways to secure your organization’s data is by using an end-to-end encrypted cloud storage solution like Proton Drive. Unlike cloud storage services like Google Drive or Dropbox, your files and folders are encrypted with a key that only you possess — not even Proton can access your data. This makes it far less susceptible to attackers in the event of a server breach.
If your organization does ever experience data loss, Proton Drive’s version history feature lets you restore older versions of files that may have been accidentally overwritten or altered. And, as Proton Drive is part of a suite of solutions, you may also consider using Proton’s encrypted email, password manager, or virtual private network(новое окно) to strengthen your organization’s security across your entire network.
Защитите свои файлы и обменивайтесь ими безопасным способом