Article

2018 Verizon Data Breach Report: Ransomware Most Common Malware

Written by Michael Peters

Topic: Business NetworkingPublished Recently added
No ratings yet1,254 viewsSign in to rate
While cryptominers are on the rise, ransomware was the most prevalent form of malware in 2017, according to the 2018 Verizon Data Breach Report, released last week. Ransomware made its first appearance in Verizon’s 2013 report, and this is the second year in a row in which ransomware incidents doubled. The 2018 Verizon Data Breach Report, which analyzed over 53,000 security incidents and more than 2,200 breaches, explained that the enduring popularity of ransomware makes sense from a cyber criminal’s perspective: * Ransomware attacks are inexpensive to launch and pose very little risk to attackers. * Attackers get paid right away instead of having to wait to sell stolen data. * Ransomware is flexible; it can be used against both individuals and organizations. * When used against organizations, it can cripple multiple computers at once, thus giving the attackers leverage to demand very large ransoms. The healthcare industry continues to be plagued by ransomware attacks. While ransomware was responsible for 39% of incidents involving malicious code overall, in the healthcare industry, that figure was 85%. Further, 24% of breaches in the 2018 Verizon Data Breach report involved healthcare organizations, and healthcare was the only industry in which the majority of threat actors were insiders. It is important to note that while ransomware was the most common type of malicious software, denial of service (DoS) attacks were 27 times more common. Other notable findings from the 2018 Verizon Data Breach Report include: * When breaches are successful, the time to compromise is very short, measured in seconds or minutes. Conversely, discovery takes weeks or months; 68% of breaches take months or longer to detect. Breach mitigation takes weeks or months more. * About three-quarters of cyber attacks are financially motivated. However, in the public sector and the manufacturing industry, the majority of breaches were cyber espionage attacks that sought to steal secrets. * 58% of victims were categorized as small businesses. * While nation-state hackers continue to grab headlines, and the threat they pose shouldn’t be ignored, they represented only 12% of all breaches in the Verizon report. Cyber attacks by organized crime groups were far more common; they were responsible for half of all breaches. * While 78% of people did not click on a single phishing email all year, an average of 4% of people will click—and it only takes one click for a hacker to get into an enterprise system. Further, those same 4% of people tend to be repeat offenders; they’ve never seen a phishing link they didn’t like, and they’ll click again and again. * Companies are three times more likely to be breached as the result of a social engineering attack than an actual vulnerability. Lessons from the 2018 Verizon Data Breach Report When developing proactive cyber security defenses, it is critical to understand the specific threats that organizations in your industry are most likely to face. For example, the healthcare industry is struggling with ransomware; the public sector and the manufacturing industry are most likely to face cyber espionage threats; and accommodation and food services attacks are dominated by POS system breaches. Cyber security tips that apply to all industries include: * Stay on top of your systems and users; monitor your network for suspicious behavior. * Give employees the minimum amount of system access they need to perform their jobs, and no more. * Ensure that your employees receive comprehensive and ongoing training in best cyber security practices. * Employ two-factor authentication to prevent hackers from being able to use stolen credentials. * Always back up your systems and data, and encrypt sensitive data so that it’s useless even if it is stolen.

Article author

About the Author

Michael Peters is the CEO of Lazarus Alliance, Inc., the Proactive Cyber Security™ firm, and Continuum GRC. He has served as an independent information security consultant, executive, researcher, and author. He is an internationally recognized and awarded security expert with years of IT and business leadership experience and many previous executive leadership positions. He has contributed significantly to curriculum development for graduate degree programs in information security, advanced technology, cyberspace law, and privacy, and to industry standard professional certifications. He has been featured in many publications and broadcast media outlets as the “Go-to Guy” for executive leadership, information security, cyberspace law, and governance.

Further reading

Further Reading

4 total

Article

Introduction There was a time when the call center was seen as a place where phones rang endlessly and agents simply answered questions. That picture has changed dramatically. Today the modern call center sits at the center of customer experience, quietly coordinating returns, managing fulfillment concerns, and shaping how customers feel about every interaction with a brand. Instead of reacting to problems, teams now guide customers through complex journeys. Their role has gr

February 6, 2026

Article

Choosing the right POS terminal is more important now than ever. With customer expectations rising and payment methods changing quickly, businesses need a device that works fast, stays secure, and handles different payment types. The PAX A30 is a popular Android POS terminal that has gained attention for its modern design and strong features. In this review, we look at how well it performs in real life, what makes it stand out, and whether it can truly be called the best Andr

January 17, 2026

Article

Healthcare organizations face increasing pressure to safeguard medications, vaccines, and biological samples while meeting strict regulatory standards. Even minor temperature fluctuations can compromise drug efficacy, lead to costly waste, or create compliance concerns. As a result, many facilities are turning to advanced Drug Monitoring technologies that provide continuous visibility into storage conditions without relying on manual checks. TempGenius delivers monitoring sol

January 12, 2026

Article

In an ever-evolving global market, staying ahead of cultural trends has become a vital task for businesses and marketers alike. Market updates are crucial for understanding how different sectors are changing, and how these shifts are influencing cultural trends worldwide. From changes in consumer behavior to the rise of new technologies and innovations, market trends in cultural research play a pivotal role in shaping the cultural landscape. Industry news, top culture analysi

January 8, 2026