5 and 10 million dollars: these are the ransoms demanded by the cybercriminals who attacked Brunoy Town Hall and Corbeil-Essonnes Hospital a few months ago. While many laws are being passed in Europe to strengthen the overall level of protection for organisations, attackers are also becoming more innovative and resourceful. According to a 2022 study on the subject conducted by Proofpoint, France is the country most affected by ransomware attacks worldwide. Indeed, 81% of French organisations reported having faced at least one ransomware infection. Should you pay a ransom in the event of a cyberattack? How can you protect yourself against these attacks that target all types of organisations?
What is ransomware?
Ransomware is the most widespread cyber threat in 2022 (source: Threat Landscape 2022). It consists of malicious software that blocks access to a computer or files by encrypting them and demands that the victim pay a ransom to regain access. The purpose of this attack is to extort money from the targeted organisation in exchange for the promise of regaining access to the stolen data. Furthermore, data is not always returned when the funds are handed over to the cybercriminal. In addition, some data may be published in order to put pressure on the target organisation and recover the funds more quickly. This was the case during the attack on the Alpes-Maritimes Departmental Council in early November. The hackers, who had stolen 290 GB of data, published 13 GB of it.
Indeed, this is a new trend that has been observed for several months. Hackers now take the time to exfiltrate the organisation's data—sometimes sensitive data, such as personal data, health data or other confidential files—before making it unreadable. With a copy of the data in hand, these cyberattackers threaten to publish it publicly if they do not receive the requested amount before a deadline, often two weeks. The LockBit cybercriminal gang is well known for this type of blackmail, which it does not hesitate to publicise in order to put even more pressure on the targeted organisation.
What should you do in the event of an attack?
31% of French organisations that paid a ransom did not regain access to their data. 20% of those that paid an initial ransom were extorted for one or more additional ransom payments before recovering their data. Paying the ransom is therefore not the best solution, as it does not guarantee data recovery. It is even discouraged by the French National Agency for the Security of Information Systems (ANSSI). It should be noted that, on average, the ransom demanded following an attack is 2.2 million dollars.
Furthermore, paying ransoms encourages and funds cybercriminal activity. It motivates attackers to continue seeking new methods to exploit systems, leading to further infections.
If your organisation were affected by such an attack, here are the recommendations to follow:
- Do not pay the ransom
- Disconnect the machine from the internet and the local network
- File a complaint
- Identify and remedy the source of the infection
- Identify the type of ransomware and try to decrypt the data: Europol has created a tool called Crypto Sheriff that helps you determine the type of ransomware you are facing. This allows you to check whether a decryption solution exists.
- Reinstall the system and restore the data
- Seek assistance from professionals.
How can you protect yourself against these attacks?
Cyberattackers primarily use email channels for their ransomware attacks. It is therefore essential to raise your employees' awareness of the risks associated with using email. Indeed, security software alone cannot thwart cyberattacks.
When browsing the internet, it is recommended not to click on links from unknown websites that could download malware, and not to share any personal information with an untrusted source.
To prevent an infection within your organisation, also ensure that all software and systems in use are kept up to date. Attackers often take advantage of a vulnerability in an IT system for which the vendor has released a patch, but for which the update has not yet been deployed.
Finally, it is essential to have a sound backup strategy. Such as the golden 3-2-1 rule, which consists of having at least 3 copies of your data, on at least 2 different media, and keeping 1 copy off-site. It is essential that one of these copies is also “offline”, also known as “cold”, meaning disconnected from any network.
This backup isolation is vital, as in more than 20% of attacks, cybercriminals target connected (“hot”) backup servers in order to render them unusable.
Finally, remember to regularly test backup restoration and plan to establish a Business Continuity Plan (BCP) so that you know how to respond in the event of a crisis.
The BlueSecure solution
BlueSecure offers ransomware awareness training through e-learning courses and phishing campaigns via email, SMS and USB drives.
Protect your organisation by training your employees with our offering that combines theory and practice. Make people the strongest link in your information security.
Contact us for more information:



