/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Analysis: 740 organizations faced ransomware attacks and had their data posted to leak sites in Q2 2021, up 47% QoQ; attacks on retail sector grew 183% QoQ

ZDNet Jonathan Greig

Context & Ripple Effects

Leak-site victim counts have become the clearest public gauge of ransomware pressure, and they keep climbing: Trustwave found attacks overtook credit card theft as the most common cybercrime in 2019, after years of network-wide targeting replacing single-PC infections. By H1 2020, ransomware drove 41% of cyber insurance claims while average demands rose 47%.

The Q2 2021 analysis adds a sector dimension to that arc — a 183% QoQ jump in retail alongside 740 organizations total exposed on leak sites — and later coverage confirms it is not a blip: Unit 42 counted 49% YoY growth in leak-site victims through 2023 even after law-enforcement takedowns, and NCC Group logged a record 502 attacks in July 2023.

First-order effects

  • Retailers become the fastest-growing target class this quarter at +183% QoQ, and the 740 exposed organizations now face extortion leverage beyond encryption: published stolen data.
  • Victims deciding whether to pay are operating against evidence that payment does not close the incident — a June 2021 study found 80% of ransom payers were hit again and most reported revenue or brand damage.

Second-order effects

  • With ransomware already the largest claim category for cyber insurers, quarterly victim growth at this rate pushes carriers toward repricing and tighter underwriting scrutiny of security controls.
  • The leak-site model rewards gangs for volume, so rivals copy the publish-or-pay playbook — consistent with RaaS operators like Cl0p later driving record monthly attack counts.

Third-order effects

  • If leak-site counts keep rising despite service takedowns, extortion economics — not malware technique — become the industry's structural problem, sustaining multi-year growth from 2016's quadrupling through 2023's records.
  • Double extortion hardens into the default attack template, making pre-breach data protection rather than backup-only recovery the baseline buyers and insurers demand.

The trend: Ransomware is consolidating around leak-site extortion as a scalable business model whose victim counts rise across years regardless of takedowns or ransom payments.