New ransomware trend? Gangs are more reliant on stolen logins and malware-as-a-service, per law enforcement. Last year, nearly three in 10 ransomware attacks started with attackers using a stolen password, according to Sophos’ “State of Ransomware” report. How about this from Axios:
Before the 2021 ransomware attack on Colonial Pipeline, many more attacks started through malicious deployment tools, such as cracked versions of Cobalt Strike, Don Smith, vice president of threat research at SecureWorks, told Axios.
Now, most gangs have ditched those tools — which have also attracted law enforcement and private sector attention — in favor of stolen passwords and infostealer malware.
“It’s growing significantly,” Smith said. “It’s healthy; you would almost argue that it’s mature.”
With the tactics of ransomware gangs shifting to keep up with changing defense strategies, I wanted to pose this question today.
How many vendors in this space are embracing passkeys? The standard is in the market; the technology is increasingly available. And if the number is low, why aren’t providers pushing vendors on this?
I’ve long observed that IT providers are squeezed on security liability between customers needing help and vendors assuming little to no risk for their products. While that may change (particularly as we consider the recent executive orders from the White House), it hasn’t yet, and providers should immediately see the benefits from the products they use being protected by passkeys and moving onto customers. Just saying. While acknowledging user education is a headline solution, eliminating passwords is right there in the mix.

