The Evolution of Ransomware Gangs and How to Prepare for New Tactics
Ransomware has shifted from opportunistic malware into a mature criminal business. Modern gangs steal data before encrypting systems, pressure executives through public leak sites, and outsource key tasks through affiliate programmes. The result is a threat that targets business continuity, reputation and customer trust as aggressively as it targets files.
Australian organisations face added pressure because many rely on connected cloud platforms, outsourced IT providers and always-on digital services. A disruption affecting a hospital in Brisbane, a retailer in Melbourne or a local council in regional New South Wales can quickly become a public and operational crisis.
Preparation therefore needs to move beyond installing endpoint protection. Strong security combines identity controls, tested backups, vulnerability management, network visibility, staff awareness and a response plan that works during a stressful, fast-moving incident.
How Ransomware Operations Changed
Early ransomware campaigns often depended on mass phishing and basic file encryption. Today’s operators study their victims before deployment, buying stolen credentials, exploiting exposed remote services and spending weeks moving through an environment. They may disable security tools, locate backups and identify systems that are essential to daily operations.
Criminal groups increasingly operate as specialised ecosystems. One actor may gain access, another may broker credentials, and an affiliate may conduct the intrusion. Ransomware-as-a-service kits lower the technical barrier, while negotiators and data publication teams help turn an attack into a coordinated extortion campaign.
The Business Model Behind Modern Extortion
Double extortion remains common: attackers copy sensitive information and threaten to release it after encrypting systems. Some groups add further pressure by contacting customers, suppliers or employees. Others use triple extortion, targeting internet-facing services or launching denial-of-service attacks to amplify disruption.
The financial impact can extend well beyond a ransom demand. Organisations may face forensic costs, legal advice, notification obligations, lost revenue and contractual penalties. Under Australia’s Notifiable Data Breaches scheme, an eligible data breach may require notification to affected individuals and the Office of the Australian Information Commissioner, making early investigation essential.
What New Attacks Look Like In Australia
Australian businesses commonly operate across Microsoft 365, cloud workloads, branch offices and managed service providers. Attackers exploit this interconnected model through stolen administrator credentials, insecure remote access, unpatched appliances and third-party access. A compromise at an IT provider can create a pathway into several customers at once.
Local context matters during response planning. An organisation in Perth may need to coordinate across distant technology teams, while a healthcare provider in Adelaide must protect clinical availability as well as patient records. Businesses should also account for Australian Eastern, Central and Western time zones when arranging escalation and 24/7 monitoring.
The Australian Signals Directorate’s Essential Eight provides a practical baseline, but ransomware preparation should go further. Controls must reflect the organisation’s actual attack surface, including mobile devices, cloud identities, operational technology, suppliers and public-facing applications.
Build Resilience Before An Incident
Reliable, isolated backups are central to recovery, yet backup systems are frequent targets. Maintain multiple copies using a tested retention strategy, restrict administrative access and keep at least one copy disconnected or protected against unauthorised deletion. Recovery exercises should measure how long critical services take to restore, rather than simply confirming that backups exist.
Identity security deserves equal attention. Enforce phishing-resistant multi-factor authentication for privileged accounts, remove dormant users and apply least-privilege access. Network segmentation can limit lateral movement, while centralised logging helps analysts recognise suspicious authentication, privilege escalation and data transfers.
Readiness Checks For Security Teams
- Confirm which systems are critical to safety, revenue and customer service
- Test restoration from protected backups at scheduled intervals
- Review administrator accounts, service accounts and third-party access
- Validate emergency contacts for executives, legal teams and technology suppliers
- Record decisions and evidence during simulated ransomware exercises
Reduce Exposure Across The Attack Surface
A vulnerability assessment can identify outdated software, exposed services and weak configurations before criminals find them. Penetration testing adds an adversarial perspective by showing how separate weaknesses could be combined to reach sensitive systems. Testing should cover external infrastructure, internal networks, APIs, cloud environments and mobile applications where relevant.
Continuous monitoring is especially valuable when an organisation lacks a large in-house security team. A managed security service can correlate endpoint, identity, firewall and cloud events, then escalate suspicious activity at any hour. This matters for Australian organisations operating overnight, across public holidays or with teams distributed between Sydney, Canberra and remote locations.
Security and compliance work should support each other rather than run as separate projects. Organisations preparing for certification or improving governance can use an ISO 27001 checklist to connect risk treatment, access management, incident response and evidence collection.
Turn Response Into Recovery
A ransomware playbook should define who can isolate systems, approve emergency actions, contact regulators and communicate with customers. It should include technical decision points, such as when to disable an account, disconnect a device or block a segment of the network. Clear authority reduces delays when normal communication channels are unavailable.
Incident response also requires careful evidence handling. Preserve logs, affected devices and relevant cloud records so investigators can establish the initial access route and determine whether data was stolen. Avoid rushing to rebuild every system before understanding persistence mechanisms, as attackers may retain access through compromised accounts or scheduled tasks.
Priorities During A Suspected Attack
- Isolate affected endpoints without destroying useful forensic evidence
- Disable compromised credentials and review recent privileged activity
- Protect backup systems and restrict unnecessary administrative access
- Engage incident responders, legal advisers and cyber insurance contacts
- Assess whether personal information or regulated data was accessed
Ransomware preparation is an ongoing security discipline, not a once-a-year compliance exercise. Infoziant Security can help assess vulnerabilities, test real-world attack paths, monitor environments around the clock and strengthen response capability. Arrange a security assessment or request a free VAPT report to identify the gaps attackers are most likely to exploit.