Ransomware seems to be everywhere, and banks and financial institutions are at risk of attacks like those last week on a major natural gas pipeline and the release of sensitive information stolen from the Washington D.C. Police Department.

At its core, ransomware is malicious software that can be used to encrypt an organization’s data and lock it away until a ‘ransom’ payment is made to restore access, keep it from being publicized, thereby safeguarding a firm’s intellectual property and ensure that their business stays in operation.
“Ransomware does seem to be the vehicle of choice for bad actors this year,” Bob Maley, chief information security officer Black Kite, told Bank Automation News. But ransomware alone isn’t enough to carry out an attack; malicious actors need a way into the system’s IT infrastructure and that’s where techniques like phishing, email exploits and social engineering play a role.
According to data compiled by DarkTracer, a dark web criminal intelligence platform, the ransomware gang that attacked the Colonial gas pipeline has been linked to more than 90 similar attacks, including on banks like $1 billion Oak Valley Community Bank, Indonesia-based Exim Bank and insurance carriers like OneDigital and the Leavitt Group.
Oak Valley, OneDigital and Leavitt Group did not respond to a request for comment by press time.
“In recent months, we’re not only starting to see this in the financial [sector] but health care as well,” Brandon Potter, chief technology officer at cybersecurity firm ProCircular, told BAN. Increasingly, instead of just locking up the data by encrypting it, attackers may modify items like account balances, authorized signers or even histories of patient allergies maintained in health care records.
“So it’s ‘Oh, and by the way, we made three changes to your 50,000 records and I’m not going to tell you which ones they are until you pay me,’” Potter said.
Although ransomware isn’t a novel exploit, it appears to have grown in popularity, evidenced by the rise of ransomware-as-a-service providers who are white-labeling the software that enables attacks. DarkSide, the group involved with the natural gas pipeline attack, runs such a service.
“The bad guys have certainly banded together,” Justin Estadt, head of product in the IT division at wealth and investment management firm SEI, told BAN. He added that malicious software designed by one group often can make it into the hands of others who may deploy it as well. On the other hand, organizations tend to have a hard time “quantifying the risk” they may face from cybercrime and fall behind on keeping up with the threats.
Getting off the dirt
The attack is only part of the story, though; restoring operations and negotiating a way out of the exploit can be tricky.
“The cost of recovery and the resulting downtime in the aftermath of a ransomware attack, as well as reputational damage, can be 10 to 15 times more than the ransom,” noted a research paper compiled by advisory firm Gartner.
“The first thing you want to do is obviously contain the threat,” Potter said, adding that evicting the attackers and isolating the data buckets they breached are also priority items. “We’ve seen infiltration to full domain compromise and encryption within hours. So a lot of it is automated [to an extent],” he added.
While rigorously testing points of penetration may be a safe bet to guard against attacks, Maley said it’s key to understand the risk exposure arising out of connections with third-party service providers that many enterprise — including financial institutions — use.
Although the financial sector is “ahead of the curve” in cybersecurity, said Potter, their security measures aren’t foolproof. He added that regulations and oversight have made financial institutions more focused on digital security, and new techniques using artificial intelligence (AI) systems to monitor threats may also enhance preparedness. “I like to think FIs are one of the pioneers of … where we go,” he said.
But as the history of cyberattacks shows, bad actors tend to be good at getting around new controls. For now, the rising frequency of such attacks also demonstrates how susceptible enterprises are and how important it is to stay on top of cyber-hygiene.
“Everybody’s a target in one way, shape or form,” Potter added.






