Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - ‘Bluff’ Ransomware Attacks Con British Businesses With Cyber Criminals Raking In An Average Of Over £13,000 Per Sham Attack
Study & Research

‘Bluff’ Ransomware Attacks Con British Businesses With Cyber Criminals Raking In An Average Of Over £13,000 Per Sham Attack

ISBuzz TeamBy ISBuzz TeamJanuary 26, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Microsoft Outlook Zero-Day Vulnerabilities Exposed
Microsoft Outlook Zero-Day Vulnerabilities Exposed
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

New Citrix research reveals two in five large UK businesses have now fallen victim to a ‘bluff’ ransomware campaign

LONDON, United Kingdom. Today, new research has revealed that two in five (39 per cent) large UK businesses have fallen victim to a ‘bluff’ ransomware attack, with almost two thirds (61 per cent) of those organisations paying out a ransom as a result.

The research – commissioned by Citrix and carried out by One Poll – quizzed 500 IT decision makers in companies with 250 or more employees across the UK to glean further insights into the threat of ‘bluff’ ransomware attacks. This refers to a criminal falsely stating that malicious software has successfully blocked access to an organisation’s computer system or data but still demanding a sum of money to return access to the data. The research also considered the extent to which ransoms are being paid by British businesses as a result of these incidents and whether – and with whom – affected businesses are sharing this information.

‘Bluff’ ransomware, real ransoms

This latest research revealed that UK businesses hit with a ‘bluff’ ransomware attack are paying the cyber criminals responsible for the incident an average of £13,412.29. While almost two thirds of large British businesses have paid out between £10,000-25,000 following this type of scam, one in 20 (6 per cent) ended up paying over £25,000 as a result of these faked ransomware campaigns.

 

Calling the bluff

The poll also found that almost half (42 per cent) of large British businesses have experienced a cyber-criminal claiming to have successfully launched a ransomware attack against their company system – and demanding payment. When faced with this situation, the majority (93 per cent) have considered whether it might be a ‘bluff’. Despite so many companies considering this possibility, just 37 per cent of affected organisations avoided ‘falling for the bluff’ and chose not to pay out a ransom.

Chris Mayers, chief security architect, Citrix, said:

“Cyber criminals on the lookout for easy wins and lucrative targets are taking advantage of fears around ransomware to make money from ‘bluff’ ransomware attacks. With so many UK businesses falling victim to these scams, learning to distinguish real threats from a false attack can save considerable sums.

“Organisations can pinpoint a real attack and completely eradicate it with the correct technical expertise – but this expertise is in short supply. Good cyber hygiene, on the other hand, is readily available. By committing to the most robust cybersecurity techniques, companies can lessen the chances of falling prey to a real ransomware attack or creating any vulnerabilities which could lead them to believe their system has been hacked by cyber-attackers when it has not.”

Other key findings

With an increased focus on sharing threat intelligence across the security sector, the vast majority of affected businesses did share information on ‘bluff’ ransomware attacks. Over half of large UK businesses shared that information with police forces (57 per cent) and cybersecurity organisations, such as the National Cyber Security Centre (59 per cent). Cybersecurity initiatives, such as No More Ransom, were also a key sharing avenue with 45 per cent of affected businesses sharing information with these groups. Yet, surprisingly, less than a quarter (24 per cent) of affected UK businesses shared that information with stakeholders, such as customers, partners and suppliers.

Chris Mayers added:

“This research leaves a worrying impression that organisations may be treating ransomware as a cost of doing business – just like shrinkage and fraud in some sectors. Yet this mentality may be resulting in British businesses paying out when it is not necessary, while simultaneously supporting cybercriminal activity.

“Businesses faced with a ransom demand are forced into a difficult position. If the attack is real, paying up does not guarantee that the cyber thieves will return access to company data. Yet affected companies may not feel they have the luxury of hoping the attack is not real and refusing to pay the ransom. Whether they pay the ransom or not, sharing information on the ‘bluff’ attack is key to ensuring that other organisations do not fall victim to the same scam.” 

Methodology

Citrix commissioned One Poll to conduct an online survey of 500 IT decision makers at companies across the UK with 250 or more employees between 18th November and 25th November 2016.

[su_box title=”About Citrix” style=”noise” box_color=”#336588″][short_info id=’71012′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}