Cyberwall Blog · October 4, 2021

Top 10 High Profile Cybercrimes in 2021

From Colonial Pipeline to a municipal water supply, 2021 showed that ransomware and supply chain attacks had moved well past stealing data into disrupting real world operations.

By Alex Plotkin, CEO

2021 was the year ransomware stopped being an IT problem and started being a business continuity and public safety problem. Ransomware itself had also evolved into a service industry of its own: rather than one group building and operating every attack, ransomware-as-a-service arrangements let developers license their tools to affiliates who carried out the actual intrusions, splitting the payout. That model, combined with double extortion (encrypting a victim’s systems and threatening to leak stolen data even if the ransom was paid), meant more actors could run large-scale attacks with less technical skill of their own. A look back at some of the year’s most significant incidents shows the range of what was at stake:

The throughline across all of these: attackers increasingly went after the systems and vendors an organization depends on to function, not just the data it stores. A pipeline company, a meat processor, and a water treatment facility don’t hold especially attractive data by breach standards, but each one runs infrastructure that has no acceptable downtime, which makes them exactly the kind of target that can pay a ransom quickly just to get moving again. That same logic extends to the supply chain incidents on this list: compromising one shared vendor or piece of software can reach dozens of downstream organizations that never had a direct relationship with the attacker at all.

For an IT Director, the lesson isn’t that any one of these specific incidents will repeat exactly. It’s that the categories they represent, operational technology that can’t tolerate downtime, widely used enterprise software with a single point of failure, and vendors who sit in the middle of a supply chain, are permanent categories of risk, not one-off headlines. That’s the same reasoning behind why incident response and tested recovery plans matter as much as prevention, because at this scale, some of these organizations were always going to be targeted eventually, and the difference between a bad week and a bad year came down to how fast and how cleanly they could respond once it happened.

Related reading: A Wake-Up Call for Critical Infrastructure Security

Not ready to wait on a blog post?

Book a preparedness call and get a straight answer for your specific situation, no searching required.