A new report published by the US Government Accountability Office states that ransomware is having ‘increasingly devastating impacts’ on critical infrastructure in the United States.
‘Critical Infrastructure Protection: Agencies Need to Enhance Oversight of Ransomware Practices and Assess Federal Support’ (GAO-24-106221) includes figures from the Department of the Treasury, which report that the total value of US ransomware-related incidents reached $886 million in 2021, a 68 percent increase compared to 2020.
The report also states that the FBI reported that 870 critical infrastructure organizations were victims of ransomware in 2022, affecting 14 of the 16 critical infrastructure sectors. Among those incidents, almost half were from four sectors: critical manufacturing, energy, healthcare and public health, and transportation systems.
The full impact of ransomware is not known because reporting is generally voluntary, a situation that will change imminently as The Department of Homeland Security is planning to issue new reporting rules by March 2024.
Recommendations
GAO is making 11 recommendations to four agencies to, among other things, determine the selected sectors’ adoption of cyber security practices.






