Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallYes—Mandiant’s 2023 investigations showed a sharp increase in ransomware activity and data-leak pressure, but the figures describe what Mandiant observed, not a count of every ransomware incident worldwide. A June 5, 2024 SecurityWeek summary of Mandiant’s analysis also shows why defenders must prepare for data theft and publication threats as well as file encryption.
What Mandiant observed in 2023
Mandiant reported investigating more than 20% more ransomware cases in 2023 than in 2022. It also observed 75% more data-leak-site postings and more than 30% more data leak sites. These are separate measures: investigations, postings, and sites. They should not be read as a universal tally of attacks or victims.
Mandiant observed more than 50 new ransomware families and variants in 2023, a level described as similar to 2022 and 2021. The share of variants relative to new families increased. Mandiant interpreted that pattern as evidence that some operators were upgrading existing tools rather than relying only on entirely new families.
How extortion expanded beyond encryption
Many incidents involved several forms of pressure: encrypting files, stealing data, and threatening to publish it. Data leak sites let criminals shame breached organizations publicly and increase pressure to pay. This means that restoring files from backups does not, by itself, address the risk that stolen information may be disclosed.
#1 Best Overall
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Some actors explored other ways to pressure victims. The SecurityWeek account describes attackers contacting patients at affected healthcare facilities. In November 2023, ALPHV/BlackCat-affiliated actors claimed they had lodged a complaint with the U.S. Securities and Exchange Commission against MeridianLink. That was the actors’ claim; the available account does not establish that the SEC substantiated it.
Some newer ransomware-as-a-service operations also explored cryptocurrency choices as part of monetization. Kuiper operators reportedly offered a discount for payment in Monero rather than Bitcoin. The reported behavior may reflect an attempt to make activity harder to trace, but it does not establish how commonly Monero was used across ransomware incidents.
Rank #2
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
How attackers gained access
In Mandiant’s observed incidents, nearly 40% involved stolen credentials or brute-force attempts to gain initial access, mostly through corporate VPN infrastructure. Almost 30% involved exploitation of public-facing systems; those cases used known vulnerabilities for which exploits were publicly available.
These figures point to two distinct defensive priorities: protect remote access against credential abuse, and promptly fix exposed systems affected by known, exploitable vulnerabilities. They are proportions within Mandiant’s dataset as summarized by SecurityWeek, not universal estimates for all organizations.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
How long defenders had before deployment
The median time from initial access to ransomware deployment in Mandiant’s observations was six days in 2023, compared with five days in 2022. The median varied substantially by whether data theft was involved: 6.11 days when exfiltration was confirmed or suspected, and 1.76 days when it was not. SecurityWeek quotes Mandiant’s report: “The median time between initial access and ransomware deployment in incidents with confirmed or suspected data theft was 6.11 days, while the median time in incidents without data exfiltration was 1.76 days.”
The longer median in incidents involving suspected or confirmed theft is an association in this dataset, not proof that data theft causes attackers to wait longer in every case. Nor is a median a safe response window: individual intrusions may move faster.
Rank #4
- World’s First 6TB 2.5” Portable Hard Drive
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
When and how ransomware was deployed
About 75% of deployments in the reported observations occurred outside standard business hours. PsExec appeared in nearly 40% of analyzed intrusions. The summary also describes manual execution through interactive access and use of remote-management tools.
Legitimate utilities can therefore be part of an attack, not just an organization’s normal IT workflow. Mandiant’s dataset, as relayed by SecurityWeek, showed legitimate remote-access tools in 35% of incidents. Rclone was used for data theft in about 30% of observed incidents, and Megasync was another named tool. Beacon use to maintain presence declined from 37% in 2022 to 14% in 2023, even as legitimate tools remained common.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
What organizations should prioritize
- Patch exposed systems: prioritize known vulnerabilities on public-facing services when working exploits are available.
- Protect VPN access: reduce the chance that stolen credentials or brute-force attempts will provide a route into corporate networks.
- Prepare for both encryption and theft: include data exposure and publication threats in incident response plans, not only restoration of encrypted files.
- Maintain regular backups: backups support recovery from encryption, but do not prevent disclosure of information already stolen.
- Use endpoint detection and response: investigate suspicious activity involving common administrative and remote-management utilities, including outside normal business hours.
- Train staff in cybersecurity awareness: awareness is one part of reducing opportunities for credential theft and other initial-access routes.
How to interpret the figures
The available account is a June 5, 2024 secondary summary of Mandiant’s analysis of 2023 tactics, techniques, and procedures. It does not provide the primary report’s full methodology, sample details, or collection approach. The percentages and comparisons above should therefore be understood as Mandiant-observed figures as reported by SecurityWeek, not a census or a direct measure of every organization’s risk.

