Why Financial Institutions Should Watch Lockbit In 2025?
If you’re advising clients in the financial sector—especially those based in North America—one question should be front and center as we head into 2025: Which ransomware group poses the most significant risk to their business? Ransomware-as-a-Service (RaaS) models have made it easier for threat actors to launch attacks, and one name stands out: LockBit. In this post, we’ll explore why LockBit remains one of the most active and dangerous ransomware actors, its impact on financial institutions, key targeting trends, and what organizations can do today to defend themselves against this evolving threat.
The Rising Threat of Ransomware to the Financial Sector
Ransomware remains one of the most significant cybersecurity threats these days. Threat groups evolve their techniques and expand. Every year there’s a raise of victims with targeted attacks across various sectors, today we want to focus on the Financial sector. As we can see below, the graph points to the share of financial organizations worldwide hit by ransomware attacks from 2021 to 2024.
LockBit: A Leading RaaS Operator in 2024
One of the most active threat actor groups adopting new models, lowering the barrier to entry for new attackers and expanding the scope of ransomware operations. This model is called “Ransomware as a service” or RaaS. Raas supplied infrastructure to new players getting in and attacking from day one without having unique development skills. This threat actor is called ‘LockBit’ and they one of the most active actors these days. On the graph below there are the number of victims declared by the top three RaaS groups per month in Q1 of 2024.
North America in the Crosshairs
The United States is the most targeted country by RaaS groups, leak sites analysis (by Tred threat intelligence) revealing 521 declared victim organizations from the States. Abnormal amount compared to the United Kingdom, Canada and the others. The three most active RaaS groups’ leak sites revealed it targeted North America the most, but also focused on Europe and the Asia Pacific region.
Industry Focus: Financial Sector Under Fire
At this point, we know the share of financial organizations worldwide hit by ransomware attacks from 2021 to 2024. We know LockBit is one of the most active ransomware actors using RaaS models to expand their activities and genes. We notice the United States, especially North America, is targeted number 1 by LockBit. Now, let’s correlate our data even more and look into the top six industries targeted by ransomware families in Q1 of 2024.
After we revealed that LockBit is one of the most active ransomware threat actors for the Financial industry, expanding and developing more every year, we have to understand how to defend our systems. For solving this we need to understand how the LockBit operator works on the surface.
Defensive Measures: How to Prepare for LockBit
As LockBit continues to evolve and expand its reach—especially in targeting financial institutions—defenders must be prepared. In this section, we’ll break down recommended actions into two parts: general security practices every organization should follow, and specific techniques to mitigate known LockBit attack vectors.
General Mitigation Tactics
We will separate the remediation for 2: The first - general mitigation actions such as ‘implement MFA’ in organization, automate backup data process, keep systems up to date and analyze / sanitise and sandboxing mails inbound the organization.
LockBit-Specific Exploits to Watch For
The second - LockBit is known to exploit specific the CVE-2018-13379 vulnerability, with a score of 9.8 CVSS record. The vulnerability can exploit “Path Traversal” in FortiOS systems and FortiProxy in some versions under SSL VPN web portal that allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
Source: TrendMicro Website.
In conclusion, ransomware threats continue to evolve, organizations must adopt a proactive and multi layered defense strategy to mitigate risks, monitoring and initial Intelligence to protect themself.