
Breaking Bad Actors: Transforming Threat Intelligence into RaaS Resilience
Source: YouTube · SANS Digital Forensics and Incident Response · published Jun 26, 2025 · 27:10
PWC's Global Threat Intelligence team demonstrates that granular, localized ransomware intelligence is critical for defense, as high-level global trends often obscure specific regional and sectoral threats. 05:30
Key Takeaways:
• Global ransomware activity has shifted to a "death by a thousand cuts" model, with 80 smaller operators accounting for 67% of leak site victims in 2024. 15:20
• High-level statistics can mislead; while education saw an overall decrease in 2024, groups like Fog remained highly active in that sector in specific regions like the US and Australia. 25:15
• Deep analysis reveals distinct geographic and sectoral preferences—such as Kilsec targeting US/India healthcare or Arcus Media focusing on Brazil—vital for targeted defense. 32:10
• Sectors like maritime (200% increase), chemicals, and construction experienced significant victim growth due to digital transformation and expanded attack surfaces. 35:20
Organizations must move beyond broad global trends to analyze granular victimology data for their specific industry and location to effectively prioritize defenses against the dispersed ransomware landscape.
Sources:
- 02:15 Introduction of speakers and background on GTI team expertise
- 05:30 Contextualizing ransomware as opportunistic crime requiring data analysis
- 08:45 2023-2025 leak site victim statistics and trends
- 12:10 Impact of law enforcement operations on Lockbit and Alpha V
- 15:20 "Death by a thousand cuts" phenomenon and rise of smaller actors
- 18:30 Analysis of top-tier actors (Lockbit, RansomHub, Play, Akira)
- 22:00 Case study: LeakedData's targeting of the legal sector
- 25:15 Case study: Fog's focus on education sector in US/Australia
- 28:40 Case study: Everest's shift from healthcare to professional services
- 32:10 Case study: Arcus Media's dominance in Brazil
- 35:20 Case study: Kilsec's focus on US/India and sector victim
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
My name is Tina. Uh with me today is Sohan. Uh we are from PWC's GTI team. So global threat intelligence team. Uh as Ryan alluded to, we are going to be talking about statistics, but we are going to try and make it as uh interesting as possible. Uh before we get into it, um I'll just give a little bit of background about uh myself and Sohan about himself. So uh yes, a little bit about me. Um, I've been with the GTI team for just over a year now. I'm the strategic crime lead. Uh, and I focus largely on producing strategic, uh, operational and tactical type of intelligence reports. Uh, before that, uh, I have about 10 or 11 years working in a more of a traditional criminal intelligence space. Uh, so coming into cyber has been a really cool experience. Um, and quite a big learning curve. Uh b…