RPD Rapid7 Inc.

Rapid7 Ransomware Radar Report Charts Ransomware Group Activity and Methodologies for Fresh Insights

Rapid7 Ransomware Radar Report Charts Ransomware Group Activity and Methodologies for Fresh Insights

New Rapid7 research analyzes more than 70 active ransomware groups, 21 of which were new in 2024

LAS VEGAS, Aug. 06, 2024 (GLOBE NEWSWIRE) -- (NASDAQ: RPD), a leader in extended risk and threat detection, today announced the release of its in conjunction with the company’s presence at . The all-new research report provides a fresh perspective on the global ransomware threat by analyzing, comparing, and contrasting attacker activity and techniques over an 18-month period ending June 30, 2024.

According to the report, ransomware groups continue to refine their craft, building and scaling business models that resemble legitimate corporate enterprises. They market their services to prospective buyers, offer company insiders commissions in exchange for access, and run formal bug bounty programs. In addition, Rapid7 researchers found three major clusters of ransomware families with similar source code, indicating that ransomware groups are focusing their development efforts on quality over quantity.

“The Ransomware Radar Report uses data to tell the story of how ransomware and the threat actors that wield it are evolving,” said Christiaan Beek, senior director, threat analytics at Rapid7. “For example, the related source code, combined with a continuing decline in the number of unique ransomware families, suggests a move toward more specialized and highly effective ransomware variants, rather than a broad array of less sophisticated malware.”

Additional key findings from the Ransomware Radar Report include:

  • 21 new groups have surfaced: Within the first six months of 2024, Rapid7 observed 21 new ransomware groups entering the scene. Some of these groups are brand new while others are previously known groups rebranding under a new name. One of the most notable of these new groups, RansomHub, has quickly established itself as a prominent extortion group by making 181 posts to its leak site between February 10 and June 30, 2024.
  • Leak site posts are up 23%: Each leak site post represents an extortion attempt. The number of ransomware groups actively posting to leak sites is increasing, from an average of 24 groups posting per month in the first half (H1) of 2023 to 40 per month in H1 2024. Furthermore, 68 ransomware groups made a total of 2,611 leak site posts between January and June, representing a 23% increase in the number of posts made in H1 2023.
  • Smaller organizations have become a more frequent target: In examining the revenue distribution of companies listed within access broker postings, Rapid7 noted that companies with annual revenues around $5 million are falling victim to ransomware twice as often as those in the $30-50 million range and five times more frequently than those with a $100 million revenue. This finding could suggest that such companies are large enough to hold valuable data but not as well protected as their larger counterparts.

“The report’s insights into the ransomware landscape are crucial for informing Defenders’ cybersecurity strategies,” said Beek. “From our own detection engineering point of view, the clusters and additional report information, such as the usage and type of encryption algorithms, help us uplevel hunting techniques and prevention, detection, and response technologies. Rapid7 continually investigates new techniques used by threat actors and ransomware operators, tests them against our patented Ransomware Prevention technology, and creates new preventions to ensure customers are protected against the latest threats.”

Security practitioners and other stakeholders fighting ransomware can access the full report now at . The schedule of Rapid7’s Black Hat USA events and on-site meeting request form are both available here: .

About the Ransomware Radar Report

The Rapid7 Ransomware Radar Report provides a comprehensive analysis of ransomware incidents and binaries recorded and gathered globally, offering insights into trends, attacker profiles, ransomware families, and the implications for cybersecurity defenses. The data used for the report comes from Rapid7’s incident response teams and independent Rapid7 Labs research. The ransomware sample dataset used consists of (i) prevalent and available ransomware families from 2023 which continued their operations into 2024, and (ii) new 2024 ransomware samples that were observed until the end of June, 2024.

About Rapid7

Rapid7, Inc. (NASDAQ: RPD) is on a mission to create a safer digital world by making cybersecurity simpler and more accessible. We empower security professionals to manage a modern attack surface through our best-in-class technology, leading-edge research, and broad, strategic expertise. Rapid7’s comprehensive security solutions help more than 11,000 global customers unite cloud risk management with threat detection and response to reduce attack surfaces and eliminate threats with speed and precision. For more information, visit our , check out our , or follow us on or .

Rapid7 Media Relations

Stacey Holleran

Sr. Manager, Global Communications



(857) 216-7804

Rapid7 Investor Contact

Elizabeth Chwalk

Sr. Director, Investor Relations



(617) 865-4277



EN
06/08/2024

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on Rapid7 Inc.

 PRESS RELEASE

Rapid7 Announces 2026 Partner of the Year Award Winners

Rapid7 Announces 2026 Partner of the Year Award Winners BOSTON, Feb. 11, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: RPD), a global leader in AI-powered managed cybersecurity operations, today announced the winners of its 2026 Partner of the Year Awards. The annual awards program recognizes and honors partners around the globe for excellence in helping customers evolve their security programs to reduce risk earlier, operate more efficiently, and build lasting cyber resilience. “Our partners play a critical role in helping customers shift from reactive security to a more preemptive, outcomes-drive...

 PRESS RELEASE

Rapid7 Announces Fourth Quarter and Full-Year 2025 Financial Results

Rapid7 Announces Fourth Quarter and Full-Year 2025 Financial Results Annualized recurring revenue (“ARR”) of $840 millionFull-year revenue of $860 million, increased 2% year-over-yearFull-year net cash provided by operating activities of $154 million; free cash flow of $130 million BOSTON, Feb. 10, 2026 (GLOBE NEWSWIRE) -- . (Nasdaq: RPD), a global leader in AI-powered managed cybersecurity operations, today announced its financial results for the fourth quarter and full year 2025. "Rapid7 exited 2025 delivering outperformance against fourth quarter ARR, revenue, and profitability g...

 PRESS RELEASE

Rapid7 to Report Fourth Quarter and Full Year 2025 Financial Results o...

Rapid7 to Report Fourth Quarter and Full Year 2025 Financial Results on February 10 BOSTON, Jan. 15, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: RPD), a leader in threat detection and exposure management, today announced that the company will release its fourth quarter and full year 2025 financial results on Tuesday, February 10, 2026, after the financial markets close. The company will host a conference call that same day to discuss its results and business outlook at 4:30 p.m. Eastern Time. To register for the live event please visit: . A live webcast of the conference call and the financial r...

 PRESS RELEASE

Rapid7 and ARMO Enable Organizations to Stop Cloud Attacks Earlier wit...

Rapid7 and ARMO Enable Organizations to Stop Cloud Attacks Earlier with Runtime Security New runtime security capabilities reduce cloud risk faster and help security teams respond to active threats with confidence BOSTON, Jan. 14, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: RPD), a leader in threat detection and exposure management, announced a strategic partnership with , the creators of the open-source cloud-native security platform Kubescape and Cloud Application Detection & Response (CADR) innovator, to bring full cloud and application runtime security to the Rapid7 Command Platform. This m...

 PRESS RELEASE

Rapid7 2026 Cybersecurity Trends Outlook: Geopolitical Tensions and In...

Rapid7 2026 Cybersecurity Trends Outlook: Geopolitical Tensions and Insider Threats Among Top Risks BOSTON, Dec. 11, 2025 (GLOBE NEWSWIRE) -- (NASDAQ: RPD), a leader in threat detection and exposure management, today released its top cybersecurity predictions for 2026 from executives , , and during its . Rapid7’s insights reveal the myriad impacts of geopolitical conflicts, highlight insiders as an increasing cybersecurity threat, and emphasize that contextual awareness will be vital for effective cyber defense in the year ahead. “Cybersecurity is intelligence. It's the ability to gath...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch