Black Kite is a finalist in the 2026 SC Awards for continued innovation and leadership in third-party cyber risk intelligence.Learn more
BlackKite: Home
Menu

Ransomware Report January 2024

An In-Depth Analysis of the Latest Ransomware Trends and Threat Landscape

Dive into the constantly shifting world of ransomware, as we uncover the latest tactics, dissect the most prolific actors, and offer insights to keep your organization one step ahead.

The number of victims of ransomware attacks that were announced by the threat actors decreased from over 360 last month to 295 this month. It seems that the groups behind these attacks are experiencing a slow start to the year, much like any other business.

The group known as AlphV/Black Cat is still trying to recover from the damage they sustained from the FBI and other law enforcement agencies. They are not as effective as they once were, but with the help of other groups, we expect to see more victims targeted by them in the coming months. Akira and 8base are now in second and third place, respectively, while Lockbit remains the dominant player.

Lockbit appears to be less strict about their ground rules regarding not attacking NGOs and hospitals.

Although the number of victims is similar to that of last month, the educational sector has become the third most attacked sector this month, having been in fifth place last month.

At least one record found in stealer logs
63
Open RDP or SMB ports publicly visible
150
Use of out-of-date services/products with possible vulnerabilities of high exploitability
177
At least one possible phishing domain
152
At least one credential leaked in the last 90 days
170
MX and DNS misconfiguration that may allow spoofing and phishing attacks
249

01Threat Actor Distribution

  • Other accounted for 59 victims, representing 17.8% of total activity.
  • Play followed with 36 disclosures.
  • RansomHub and Akira remained consistently active.

02Geographic Distribution

  • USA represented 52.5% of all tracked victims.
  • Others was among the next most impacted countries.
  • UK and Canada also saw notable activity.

03Industry Distribution

  • Manufacturing remained the most targeted sector.
  • Professional Services followed as a heavily impacted sector.
  • Construction and Health Care continued to be operationally critical targets.

04Threat Actor × Country Matrix

The matrix below shows how leading ransomware groups distributed their activity geographically.

Others
Arcus Media
El Dorado
Black Suit
Cactus
Qilin
INC Ransom
Medusa
Akira
RansomHub
Play
USA
59
4
11
12
6
13
14
12
7
5
26
UK
8
2
3
2
2
2
1
Canada
7
2
1
3
2
4
Germany
3
1
3
2
1
Italy
7
1
2
1
4
Brazil
2
1
4
India
2
2
Spain
4
1
1
France
4
1
Japan
5
1
1
Argentina
2
1
1
Australia
1
2
1
Ireland
1
1
2
Others
29
6
2
1
2
1
2
5
6
4
  • USA activity was heavily concentrated in Others.
  • Some actors demonstrated narrow targeting patterns.

05Threat Actor × Industry Matrix

This view highlights sector specialization across leading ransomware groups.

Others
RansomHub
Arcus Media
BlackSuit
Akira
Play
El Dorado
Qilin
Cactus
Medusa
INC Ransom
Agriculture & Fishing
1
1
Mining
2
1
1
2
1
Utilities
1
2
Construction
7
1
1
1
8
3
3
3
1
Manufacturing
32
8
1
9
7
1
2
6
3
4
Wholesale Trade
1
1
1
4
1
1
1
Retail Trade
7
1
1
1
1
Transportation
11
3
1
1
1
2
1
2
Information
1
1
Finance and Insurance
1
1
Real Estate
1
1
Professional Services
1
1
Administrative
1
1
Educational Services
1
1
Health Care
1
1
Arts & Entertainment
1
1
2
Accommodation
1
1
Other
14
1
1
2
2
2
1
Public Administration
6
1
1
3
  • Manufacturing activity was heavily concentrated in Others.
  • Some actors demonstrated narrow targeting patterns.

06Six Month Trend Context

07Key Takeaways

  • 332 ransomware disclosures were observed in January 2024.
  • Other led activity with 59 victims.
  • USA accounted for 52.5% of disclosures.
  • Manufacturing remained the most targeted industry.

08Data Methodology and Sources

  • Victim counts are based on publicly disclosed ransomware leak site postings tracked during the reporting period.
  • Each victim is attributed to a single threat actor based on disclosure source.
  • Industry classification is assigned using standardized sector mapping.
  • Country attribution is based on headquarters location where identifiable.

Accelerate Risk Decisions, Cut the Noise.

Join leading teams using Black Kite to slash assessment timelines, eliminate manual reviews, and onboard vendors with confidence.