NCC Group measured a record 459 ransomware attacks in March 2023, up 91% MoM and 62% YoY, saying the surge is likely due to exploits of Fortra's GoAnywhere MFT
March 2023 was the most prolific month recorded by cybersecurity analysts in recent years, measuring 459 attacks …
Context & Ripple Effects
March 2023's record month did not come out of nowhere: days earlier the Russia-linked Clop gang had claimed credit for hitting 130 companies through Fortra's GoAnywhere file transfer tool, and Fortra had assured customers their data was safe even as at least two reported receiving ransom demands afterward. NCC Group's 459 measured attacks — up 91% month over month — is the first hard dataset tying that single-product campaign to an industry-wide spike.
The pattern held: five months later NCC Group logged an even higher record of 502 attacks in July, with the Cl0p ransomware-as-a-service operation alone tied to 171 of them. That makes the GoAnywhere episode less a one-off breach than the template for how a single exploited product can bend the whole monthly curve.
First-order effects
- Organizations running Fortra's GoAnywhere MFT became the immediate target pool for the March surge — NCC Group attributes the 91% jump largely to exploitation of that one product, meaning exposure was concentrated among its customer base rather than spread evenly across industries.
- Fortra faces a direct credibility problem: it told GoAnywhere customers their data was safe, yet multiple customers subsequently received ransom demands, forcing the vendor into crisis communications while attacks traced to its tool drove the record.
Second-order effects
- Cl0p demonstrated the campaign was repeatable rather than opportunistic — the same gang was tied to 171 of the 502 attacks in NCC Group's July record, signaling that mass exploitation of widely deployed file-transfer software is now a core business model for ransomware crews.
- Other managed file transfer vendors and similar enterprise data-mover products move up attackers' priority lists, since the GoAnywhere case showed one vulnerability can generate hundreds of victims across many organizations at once.
Third-order effects
- If single-product exploitation campaigns keep setting monthly records, ransomware measurement itself shifts: aggregate attack counts increasingly track the exploit cycle of a handful of enterprise products, pushing defenders toward patch-velocity and third-party software risk as primary metrics.
- The economics are reinforcing the pattern — downstream coverage shows ransomware payments reaching a record $1.1B in 2023 and leak-site victims growing 49% year over year despite law-enforcement takedowns, suggesting volume-driven campaigns like Cl0p's will persist.
The trend: Ransomware operations are industrializing around mass exploitation of widely deployed enterprise file-transfer tools, letting a single vulnerability drive record attack months — a dynamic visible in both NCC Group's March and July 2023 tallies.