Ransomware attacks are becoming a pressing issue for businesses as well as public institutions.

Allan Liska, threat intelligence analyst at Recorded Future, examines current ransomware trends, highlighting how attackers are refining their tactics and how companies are shifting towards actively identifying threats – instead of simply reacting to them.

The damaging effects of cyber attacks have dominated headlines in recent months, with businesses facing financial losses, severe hits to brand reputation, and erosion of customer trust. The UK government has identified ransomware as the most significant organised cybercrime threat and is proposing measures to strengthen defences across all sectors.

Plans include banning ransom payments by public bodies and introducing restrictions for private organisations. While these initiatives aim to deter criminal groups, they raise critical questions for businesses: if attackers know public bodies cannot pay, will they increasingly target companies outside the scope of such legislation? From our experience, many businesses, no matter their size or sector, are not prepared to gamble with that risk.

Ransomware: a growing threat

Ransomware remains, by far, the most profitable type of cybercriminal activity with the lowest barrier of entry and the fastest payout. Other types of cybercrime, such as Business Email Compromise or Romance Scams can be more profitable but they usually take months for payout and they require a lot of time and patience.

Ransomware groups have a well-documented blueprint for initial access, movement within a victim network, accepting payment and laundering funds. Even less capable threat actors, which make up the vast majority of new ransomware groups, can easily outsource these activities because there is an entire ecosystem of secondary and tertiary groups built up around supporting ransomware attacks. Attackers are rapidly changing and developing tactics to crack even the most robust defences.

The evolving tactics in a cyber criminal’s arsenal

Help desk attacks

Ransomware groups are increasingly targeting help desks as an entry point into corporate systems. These attacks rely on impersonation and social engineering to bypass security measures.

One common tactic involves overwhelming an employee with phishing emails, then calling them while posing as the help desk to “resolve” the issue. Groups such as Black Basta have used this approach to gain direct access to systems.

Another method sees criminals impersonating employees when contacting the help desk, persuading staff to reset passwords or disable multi-factor authentication. This type of attack was observed in the Clorox breach, where attackers exploited human trust and procedural gaps rather than technical vulnerabilities.

Advanced social engineering tactics

Generative Artificial Intelligence (AI) is giving cybercriminals sophisticated tools to manipulate trust and influence human behaviour. These attacks extend well beyond basic phishing emails, evolving into highly personalised campaigns that persuade employees to act in ways they ordinarily would not.

The process often begins with footprinting, where attackers analyse a target’s digital presence — from professional profiles to casual social posts — to learn how individuals communicate, who they interact with, and which topics resonate with them.

AI then amplifies this intelligence. Criminals can craft messages in a company’s style, clone voices with local accents, and reference real colleagues or workplace events. These capabilities make scams appear authentic enough for victims to bypass security protocols, share login codes, or authorise unusual actions in the belief they are helping a trusted contact.

AI also broadens access to these tactics. For example, while help desk attacks were once largely associated with Western groups such as Scattered Spider or ShinyHunters, Russian threat actors are now using AI to translate scripts and impersonate employees in native languages. This ability to convincingly adopt any persona makes such attacks far more difficult to detect and resist.

The real risk lies not in AI itself, but in its fusion with social engineering. By exploiting human instincts such as trust, helpfulness, and urgency, attackers can influence decisions that would normally trigger suspicion.

Exposing weak links in supply chains

Rather than directly attacking a target business, cybercriminals are increasingly focusing on finding gateways in supply chains. For example, hackers might find software partners, which they know their victim will trust and rely on. An attack will then leverage zero-day flaws in software or hardware to gain undetected access to the partner’s network and create a hard-to-detect route into the main target’s secure systems, to deploy ransomware.

How are companies reacting?

We’re seeing a growing number of businesses evolving cybersecurity strategies from a robust defensive posture to a more proactive approach. This involves cyber threat intelligence, which is turning companies into threat hunters. Cybersecurity teams are actively monitoring the cyber threat landscape to better understand what attacks could look like.

By building knowledge and insight about criminals’ tactics, businesses can better predict, prioritise and prevent possible attacks. Action can be taken to mitigate risks, before they have the chance to materialise into events that cause critical disruption and destruction.

Ransomware threats evolve at pace and cyber threat intelligence can provide businesses with enhanced visibility of what they are up against. There are four ransomware trends in particular that show just how quickly attackers are adapting tactics.

The key steps to defend against evolving ransomware tactics

Multilayered threat intelligence

A multi-layered, threat intelligence programme can monitor and determine how ransomware threats are changing shape. This creates opportunity for proactive mitigation. For example, against wiper-style attacks, the most critical action is to ensure the recoverability of core systems and data, regardless of whether ransomware is deployed.

This includes implementing immutable, offline backups that cannot be altered or deleted by attackers, as well as regularly testing restoration procedures under simulated attack conditions. Since data exfiltration typically occurs before destruction, organisations must also strengthen data loss prevention and insider threat detection capabilities, ensuring sensitive assets are tagged, monitored, and access is tightly controlled.

Moreover, every month there are tens of millions of leaked credentials from infostealer malware dumped on criminal marketplaces, making it incredibly likely that credentials from organisations are available to anyone who wants them, cheaply. Organisations need to monitor for these leaked credentials and take action when they are discovered. Of course, multi factor authentication is important, but so it means taking action and forcing password changes as soon as leaked credentials are discovered or reported.

Supply chain management

Defending against ransomware attacks delivered via zero-day vulnerabilities requires full supply chain risk management. This can include tracking third-party dependencies, validating update integrity through code signing, and requiring vendors to demonstrate secure development practices.

Additionally, organisations must maintain a mature vulnerability management programme capable of rapidly ingesting threat intelligence, assessing exploitability, and deploying emergency patches or compensating controls before widespread abuse occurs. This means being able to act within days, not weeks.

When a new vulnerability is announced, especially for common platforms targeted by ransomware groups and the initial access brokers that support them – such as SSL VPNs or certain firewalls – scanning for that vulnerability starts almost immediately and exploitation starts within 24-48 hours.

Don’t underestimate ‘lower risk’ groups

The emergence of ‘lone wolf’ ransomware attackers can mean that the successful takedown or disruption of an RaaS group by law enforcement, doesn’t necessarily spell the end of a group’s ransomware. Organisations need to be alert to this and continue to monitor for code, tools and techniques from RaaS groups they believe to be defunct or lower risk.

Keep up with AI ransomware trends

Being aware of how attackers are using AI in ransomware attacks is crucial to adapting and testing defences. For example, regular employee training and communications should be informed by changing criminal techniques. Staff have to be shown realistic examples of the risks they face, with simulated exercises creating awareness of how convincing AI-assisted attacks can be.

A call to arms

Ransomware attacks now target companies of every size and sector, making it critical for business leaders to treat cyber security as a core strategic risk. There is no single defence against these threats, as they can emerge from multiple directions. Strong protection depends on a clear view of the threat landscape and a coordinated response across the business.

The good news is that many companies already have the right tools – the challenge lies in refining and integrating them to protect the business, its workforce, and the customers who depend on it.