Skip to main content
Ransomware Groups

1. Which ransomware group is most active in 2024?

LockBit maintained the highest attack volume through early 2024, though law enforcement disruption reduced their capacity. Black Basta and Akira have increased activity in the vacuum.

2. Do ransomware groups actually delete stolen data after payment?

There is no guarantee, and no way to verify it. Law enforcement and security researchers have documented cases where groups continued threatening victims or sold data even after receiving payment.

3. Can ransomware groups be negotiated with?

Yes, most groups operate negotiation portals, but engaging without legal counsel and cyber insurance coordination is risky. Organizations should never negotiate without professional guidance.

4. Are smaller businesses targeted by these groups?

Yes. RaaS affiliates often prefer smaller organizations with weaker defenses. Mid-market and SMB companies represent a significant share of ransomware victims.

5. What should we do if we recognize the ransomware group from the ransom note?

Note the group name and contact your incident response provider immediately, identification helps inform negotiation strategy, data exfiltration risk, and recovery approach.

If your network has already been accessed, identifying the attackers is step one, but step two is knowing what to do next. Our ransomware attack response guide covers the first 24 hours in detail.

John Angelotti

John Angelotti is the President of DCG Technical Solutions, beginning his technology journey on a Commodore 64 and at swap meets with his mother. For more than two decades, he has helped businesses grow through secure, strategic, and cost-effective IT leadership.

At DCG, he works to ensure clients can grow without worrying about downtime. As the leader of a security-forward MSP, he develops tailored solutions that safeguard each client’s operations and reputation.

John is known for making complex technology easy to understand and guiding organizations through key improvements, from cloud migrations to cybersecurity hardening. Outside of work, he enjoys building things with his hands, archery, hiking, and competitive custom car audio.