Threat Monitor Annual Report 2023

Sectors Targeted BlackCat’s 2023 distribution of focus amongst business sectors is only slightly different to what was seen in 2022. Industrials remain the most targeted sector with 142 attacks representing 33% of the group’s total activity. The second most targeted sector is, once again, Consumer Cyclicals with 64 attacks representing 15% of the group’s 2023 activity. The third most targeted sector in 2023, taking the place of 2022’s Technology sector, is the Healthcare sector which received 53 attacks, or 12% of their total activity for the year. Industries Targeted The specifics of targeted industries within overall sectors have also undergone a shift since 2022. The most targeted industry remains Professional & Commercial Services with 77 attacks, 18% of the group’s yearly total. The second most targeted industry is Healthcare Providers & Services with 34 attacks, less than half the total of those levied against Professional & Commercial Services, representing 8% of the group’s total. The third most targeted industry for BlackCat in 2023 was Software & IT Services, the industry which was in joint-second position in 2022.

There has been much speculation about what caused the 5-day disruption with some speculating that it is the result of law enforcement interventions, whilst the operators at BlackCat maintain it was simply a hardware issue which is in the process of being solved. Members of BlackCat have had a turbulent career in cybercrime: affiliates of the DarkSide group formed BlackMatter upon DarkSide’s disbandment; affiliates of BlackMatter helped to form BlackCat/ALPHV in early 2022; and now LockBit 3.0 has started to poach some affiliates of BlackCat and even displaying some of BlackCat’s victims on their leak site (see LockBit section above).

This industry was attacked by BlackCat 31 times in 2023, 7% of their total activity for the year.

47

Made with FlippingBook - PDF hosting