/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

NCC Group measured a record 459 ransomware attacks in March 2023, up 91% MoM and 62% YoY, saying the surge is likely due to exploits of Fortra's GoAnywhere MFT

March 2023 was the most prolific month recorded by cybersecurity analysts in recent years, measuring 459 attacks …

BleepingComputer Bill Toulas

Context & Ripple Effects

March 2023's record month did not come out of nowhere: days earlier the Russia-linked Clop gang had claimed credit for hitting 130 companies through Fortra's GoAnywhere file transfer tool, and Fortra had assured customers their data was safe even as at least two reported receiving ransom demands afterward. NCC Group's 459 measured attacks — up 91% month over month — is the first hard dataset tying that single-product campaign to an industry-wide spike.

The pattern held: five months later NCC Group logged an even higher record of 502 attacks in July, with the Cl0p ransomware-as-a-service operation alone tied to 171 of them. That makes the GoAnywhere episode less a one-off breach than the template for how a single exploited product can bend the whole monthly curve.

First-order effects

  • Organizations running Fortra's GoAnywhere MFT became the immediate target pool for the March surge — NCC Group attributes the 91% jump largely to exploitation of that one product, meaning exposure was concentrated among its customer base rather than spread evenly across industries.
  • Fortra faces a direct credibility problem: it told GoAnywhere customers their data was safe, yet multiple customers subsequently received ransom demands, forcing the vendor into crisis communications while attacks traced to its tool drove the record.

Second-order effects

  • Cl0p demonstrated the campaign was repeatable rather than opportunistic — the same gang was tied to 171 of the 502 attacks in NCC Group's July record, signaling that mass exploitation of widely deployed file-transfer software is now a core business model for ransomware crews.
  • Other managed file transfer vendors and similar enterprise data-mover products move up attackers' priority lists, since the GoAnywhere case showed one vulnerability can generate hundreds of victims across many organizations at once.

Third-order effects

  • If single-product exploitation campaigns keep setting monthly records, ransomware measurement itself shifts: aggregate attack counts increasingly track the exploit cycle of a handful of enterprise products, pushing defenders toward patch-velocity and third-party software risk as primary metrics.
  • The economics are reinforcing the pattern — downstream coverage shows ransomware payments reaching a record $1.1B in 2023 and leak-site victims growing 49% year over year despite law-enforcement takedowns, suggesting volume-driven campaigns like Cl0p's will persist.

The trend: Ransomware operations are industrializing around mass exploitation of widely deployed enterprise file-transfer tools, letting a single vulnerability drive record attack months — a dynamic visible in both NCC Group's March and July 2023 tallies.

Discussion

  • @cglyer Christopher Glyer on x
    Ransomware operators using proceeds to buy zero-day exploits is happening more often than many realize “unauthorized party used...zero-day...(RCE) vulnerability to access certain GoAnywhere customers' systems. This vulnerability was assigned CVE-2023-0669” https://www.fortra.com/…