ZeroFox Intelligence Assessment - 2024 Ransomware and Digital Extortion Overview
|by Alpha Team

ZeroFox Intelligence Assessment - 2024 Ransomware and Digital Extortion Overview
Product Serial: A-2025-01-08a
TLP:CLEAR
In this Intelligence Assessment, ZeroFox researchers provide an overview of the 2024 Ransomware and Digital Extortion threat landscape, analyzing the activities and targeting patterns of the most prominent threat collectives.
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- ZeroFox observed at least 4,950 separate ransomware and digital extortion (R&DE) incidents throughout 2024—significantly more than the approximately 4,000 incidents observed during 2023. As this total accounts primarily for incidents in which a victim has either failed to pay or remains in negotiations with the attackers, the true total is almost certainly significantly higher.
- LockBit, the most prominent threat collective in 2023, was responsible for a significantly lessened proportion of R&DE activity in 2024, owing to early-2024 law enforcement (LE) disruption operations.
- RansomHub very likely poses a greater threat to organizations across the globe than any other R&DE threat collective, having been the most prominent R&DE collective in 2024.
- ZeroFox identified 45 new R&DE collectives during 2024, compared to 35 during 2023. Many of these commenced operations, demonstrated consistency, and posed a prominent threat faster than that observed in previous years.
Tags: tlp:clear, dark web, threat actor