A joint advisory from the FBI, CISA, NSA, the Australian Cyber Security Centre and the UK National Cyber Security Centre warned that ransomware became more sophisticated and globally disruptive during 2021. Attacks affected 14 of the 16 U.S. critical infrastructure sectors, alongside widespread targeting of Australian and UK organizations. Phishing, compromised Remote Desktop Protocol access and exploitation of software vulnerabilities remained the leading entry points. An increasingly professional ransomware-as-a-service ecosystem enabled attackers to share victim information and apply multiple forms of extortion.
Attackers extended their reach into cloud environments, managed service providers, software supply chains and industrial processes, increasing the potential for disruption beyond individual victims. The agencies urged organizations to prioritize timely patching, multifactor authentication, restricted remote access, network segmentation and least privilege. They also recommended monitoring cloud environments and maintaining tested offline backups to support recovery, while strongly discouraging ransom payments. For security leaders, the advisory highlights the need to address both common initial-access weaknesses and dependencies that can amplify an attack’s impact.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
On February 9, 2022, the FBI, CISA, NSA, ACSC and NCSC-UK jointly issued an advisory describing increasingly sophisticated, high-impact ransomware activity observed during 2021. It reported incidents affecting 14 of the 16 U.S. critical infrastructure sectors and recommended defensive measures while strongly discouraging ransom payments.
Conti ransomware actors began selling access to victims' networks in October 2021, enabling follow-on attacks by other threat actors.
Following disruptions by U.S. authorities in mid-2021, the FBI observed some ransomware actors shifting toward mid-sized victims to reduce scrutiny. Australian and UK authorities continued to observe targeting of organizations of all sizes.
Kaseya Limited was cited as a high-profile ransomware victim in the advisory's discussion of first-half 2021 targeting of high-value organizations and critical-service providers.
JBS Foods was among the high-profile ransomware victims cited in the advisory as examples of first-half 2021 targeting of high-value organizations and critical-service providers.
Colonial Pipeline Company was among the high-profile ransomware victims cited in the advisory as examples of first-half 2021 targeting of high-value organizations and critical-service providers.
After announcing its shutdown, BlackMatter transferred its existing victims to infrastructure owned by LockBit 2.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.