ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Ransomware Attacks Ramp Up

September 9, 2021
Reading Time: 3 mins read
Ransomware Attacks Ramp Up

By Paul Benda

In March 2021, CNA Financial Corp.—one of the nation’s largest insurance companies—paid $40 million in the wake of a ransomware attack that crippled its network, according to a Bloomberg report. A few months later, cybercriminals targeted the Colonial Pipeline, which supplies fuel to much of the East Coast, with a ransomware attack that led to Colonial paying out almost $5 million.

SVP Paul Benda hosts the weekly ABA Pandemic Update podcast.
These instances are just two high-profile examples of a growing problem: the proliferation of ransomware and extortion-ware. These types of cyberattacks occur when cyber criminals use malware to encrypt files on a device or information on a network, rendering them unusable. Criminals then demand payment in exchange for decryption.

Over the past several years, ransomware attacks have grown in scope and scale, and are now targeting critical infrastructure entities, including financial services providers. According to an eWeek security analysis, more than half of companies faced ransomware attacks and of those, 26 percent paid the requested ransom. Even if companies choose not to pay, ransomware attacks can still be costly and devastating. For example, after the University of Vermont Health Network was compromised by ransomware in June 2021, it lost an estimated $63 million in the process of rebuilding its network infrastructure and restoring compromised hard drives.

Unfortunately, even for those that do pay, obtaining a decryption key is not a panacea—firms must still conduct testing on every machine and network endpoint to ensure that the malware has been successfully removed. One global survey of 5,400 IT decision makers found that around half of those who paid ransom recovered just 65 percent of the encrypted data compromised in the attack. Another 29 percent said they only recovered half of the data.

The staggering cost and increasing frequency of ransomware attacks would seemingly make the case for cyber insurance—but, surprisingly, anecdotal evidence suggests that a majority of financial institutions are not cyber-insured. And with cyberattacks on the rise, the cost of cyber insurance is also increasing, and ransom payments as an insurable risk may not be sustainable in the long run.

The federal government has taken several steps to address the growing problem of ransomware, including establishing a new Department of Justice task force that centralizes the DOJ’s efforts to track cyberattacks and digital extortion schemes. FBI Director Christopher Wray even went so far as to compare the threat of ransomware to the terror threat that followed in the wake of 9/11.

“There are a lot of parallels, there’s a lot of importance, and a lot of focus by us on disruption and prevention,” Wray told the Wall Street Journal. “There’s a shared responsibility, not just across government agencies but across the private sector and even the average American.”

Banks can find information on ransomware by visiting a new, dedicated website created by the Cybersecurity and Infrastructure Security Agency, cisa.gov/stopransomware. The site provides resources to help evaluate risk and harden systems against potential attacks. It also includes a reporting portal that banks and other companies can use to report cyber incidents to the appropriate authorities.

In addition to these efforts, bank regulators have issued a notice of proposed rulemaking that would direct banks to notify their federal regulator within 36 hours after developing a good-faith belief of a “computer security incident” that will materially disrupt, degrade or impair banking operations. Importantly, this would not replace Gramm-Leach-Bliley consumer data breach notice requirements. Additionally, the rule places a burden on a bank’s third-party providers to provide immediate notice to a bank of a disruptive incident.

While this proposal is a step toward ensuring clarity and consistency around the reporting of cyber incidents, ABA raised concerns that as written the definition of “computer security incident” is overly broad and recommended targeted changes before the rule is finalized—which is not expected until the end of 2021. ABA also continues to monitor legislative activity around ransomware and the prevention of cyberattacks and will continue to update members as new developments arise.

Government efforts aside, now is the time for banks to take steps to ensure their cyber preparedness and review best practices for securing their data infrastructure. Extra vigilance today can help prevent a costly incident tomorrow.

Paul Benda is SVP, cybersecurity and operational risk at ABA.

Tags: CybersecurityRansomwareRisk management
ShareTweetPin

Related Posts

ABA urges FinCEN to reevaluate BOI collection burden on banks

FinCEN updates guidance for financial institutions on sharing information about fraud

Compliance and Risk
June 12, 2026

FinCEN issued an updated fact sheet to clarify how financial institutions can share information with each other about suspected fraud under the provisions of the USA PATRIOT Act.

Reports explore information exposure, costs of data breaches

Report: Software vulnerabilities become top vector for data breaches

Compliance and Risk
June 12, 2026

Exploitation of software vulnerabilities has become the most common initial access vector for data breaches, according to the most recent Data Breach Investigations Report by Verizon.

CFPB, DOJ warn against using immigration status to determine creditworthiness

Podcast: Understanding bank regulators’ guidance on illegal immigration

ABA Banking Journal Podcast
June 11, 2026

On the ABA Banking Journal Podcast, ABA's Heather Trew breaks down recent news about the president's executive order on illegal immigration and the financial system and the FinCEN advisory on red flags associated with the employment of illegal...

OCC to merge community bank, large bank supervision departments

OCC publishes draft reporting forms for stablecoin issuers

Compliance and Risk
June 11, 2026

The OCC has released for public review draft forms that will be used to collect information from payment stablecoin issuers under its jurisdiction.

With AI threats, CISA offers agencies guidelines for patching software vulnerabilities

With AI threats, CISA offers agencies guidelines for patching software vulnerabilities

Compliance and Risk
June 11, 2026

CISA released a new framework for federal civilian agencies in determining how quickly to patch software vulnerabilities, noting that artificial intelligence is “vastly increasing” the pace at which such vulnerabilities are discovered.

CFPB claims ‘complex’ pricing drives up cost of financial products

Trump nominates Johnson to lead CFPB

Compliance and Risk
June 10, 2026

President Trump nominated bank executive Brian Johnson to lead the CFPB, which has been without a full-time leader since the firing of Rohit Chopra last year.

NEWSBYTES

FinCEN updates guidance for financial institutions on sharing information about fraud

June 12, 2026

Report: Software vulnerabilities become top vector for data breaches

June 12, 2026

ABA DataBank: A tale of two cabins

June 12, 2026

SPONSORED CONTENT

Why Your Systems Keep Slowing Down — and What to Do About It

Examiners Are Now Looking at Your Non-Core Systems

June 11, 2026
Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

June 1, 2026
A Modern Blueprint for Serving High-Net-Worth Families

A Modern Blueprint for Serving High-Net-Worth Families

May 28, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

AI Is in Your Bank. Is Your Cloud Contract Governing It?

May 20, 2026

PODCASTS

Podcast: Understanding bank regulators’ guidance on illegal immigration

June 11, 2026

Podcast: Creating a feeling of welcome, for customers and new bankers

May 28, 2026

Podcast: How consumer deposits drive full relationship banking

May 14, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.