ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Ransomware Attacks Ramp Up

September 9, 2021
Reading Time: 3 mins read
Ransomware Attacks Ramp Up

By Paul Benda

In March 2021, CNA Financial Corp.—one of the nation’s largest insurance companies—paid $40 million in the wake of a ransomware attack that crippled its network, according to a Bloomberg report. A few months later, cybercriminals targeted the Colonial Pipeline, which supplies fuel to much of the East Coast, with a ransomware attack that led to Colonial paying out almost $5 million.

SVP Paul Benda hosts the weekly ABA Pandemic Update podcast.
These instances are just two high-profile examples of a growing problem: the proliferation of ransomware and extortion-ware. These types of cyberattacks occur when cyber criminals use malware to encrypt files on a device or information on a network, rendering them unusable. Criminals then demand payment in exchange for decryption.

Over the past several years, ransomware attacks have grown in scope and scale, and are now targeting critical infrastructure entities, including financial services providers. According to an eWeek security analysis, more than half of companies faced ransomware attacks and of those, 26 percent paid the requested ransom. Even if companies choose not to pay, ransomware attacks can still be costly and devastating. For example, after the University of Vermont Health Network was compromised by ransomware in June 2021, it lost an estimated $63 million in the process of rebuilding its network infrastructure and restoring compromised hard drives.

Unfortunately, even for those that do pay, obtaining a decryption key is not a panacea—firms must still conduct testing on every machine and network endpoint to ensure that the malware has been successfully removed. One global survey of 5,400 IT decision makers found that around half of those who paid ransom recovered just 65 percent of the encrypted data compromised in the attack. Another 29 percent said they only recovered half of the data.

The staggering cost and increasing frequency of ransomware attacks would seemingly make the case for cyber insurance—but, surprisingly, anecdotal evidence suggests that a majority of financial institutions are not cyber-insured. And with cyberattacks on the rise, the cost of cyber insurance is also increasing, and ransom payments as an insurable risk may not be sustainable in the long run.

The federal government has taken several steps to address the growing problem of ransomware, including establishing a new Department of Justice task force that centralizes the DOJ’s efforts to track cyberattacks and digital extortion schemes. FBI Director Christopher Wray even went so far as to compare the threat of ransomware to the terror threat that followed in the wake of 9/11.

“There are a lot of parallels, there’s a lot of importance, and a lot of focus by us on disruption and prevention,” Wray told the Wall Street Journal. “There’s a shared responsibility, not just across government agencies but across the private sector and even the average American.”

Banks can find information on ransomware by visiting a new, dedicated website created by the Cybersecurity and Infrastructure Security Agency, cisa.gov/stopransomware. The site provides resources to help evaluate risk and harden systems against potential attacks. It also includes a reporting portal that banks and other companies can use to report cyber incidents to the appropriate authorities.

In addition to these efforts, bank regulators have issued a notice of proposed rulemaking that would direct banks to notify their federal regulator within 36 hours after developing a good-faith belief of a “computer security incident” that will materially disrupt, degrade or impair banking operations. Importantly, this would not replace Gramm-Leach-Bliley consumer data breach notice requirements. Additionally, the rule places a burden on a bank’s third-party providers to provide immediate notice to a bank of a disruptive incident.

While this proposal is a step toward ensuring clarity and consistency around the reporting of cyber incidents, ABA raised concerns that as written the definition of “computer security incident” is overly broad and recommended targeted changes before the rule is finalized—which is not expected until the end of 2021. ABA also continues to monitor legislative activity around ransomware and the prevention of cyberattacks and will continue to update members as new developments arise.

Government efforts aside, now is the time for banks to take steps to ensure their cyber preparedness and review best practices for securing their data infrastructure. Extra vigilance today can help prevent a costly incident tomorrow.

Paul Benda is SVP, cybersecurity and operational risk at ABA.

Tags: CybersecurityRansomwareRisk management
ShareTweetPin

Related Posts

Five tips to juice community bank board performance

New survey probes community banks’ plans for digital assets

Community Banking
October 6, 2026

Double-digit shares of community bankers intend to offer tokenized deposits and stablecoin solutions within the next 12 months, according to the Conference of State Bank Supervisors' 2026 community bank survey released today. 

ABA seeks more coordination among banking agencies in rewriting disclosure rules

ABA seeks more coordination among banking agencies in rewriting disclosure rules

Compliance and Risk
October 6, 2026

As they restructure the processes for making confidential bank information available for public review, regulators should better coordinate their efforts to ensure banks do not face differing disclosure requirements, ABA said.

Fed’s Bowman to keynote ABA Conference for Community Bankers

Fed to split bank supervision into five regions

Community Banking
October 6, 2026

The Federal Reserve will divide its bank supervision into five geographic regions rather than splitting it among the 12 Reserve Bank districts, Vice Chair for Supervision Michelle Bowman said. The Fed also plans to revisit the criteria used...

ABA highlights banker comments seeking stronger ‘know your customer’ rules for originating providers

Lawmakers propose banning SIM boxes used in scam calls

Compliance and Risk
October 5, 2026

A proposed bill would ban the sale and manufacturing of machines that help scammers disguise their phone calls and texts.

Fed, FDIC withdraw statements on managing risks for crypto

FinCEN withdraws proposals on crypto recordkeeping

Compliance and Risk
October 5, 2026

FinCEN is withdrawing two proposed rules that would have created new recordkeeping requirements for financial institutions for certain transactions involving convertible virtual currencies.

Fed releases agenda for upcoming conference on large bank capital requirements

Fed extends comment deadline for proposed updates to bank insider regulation

Compliance and Risk
October 2, 2026

The Federal Reserve has extended the comment period by a month for proposed changes to its regulation governing extensions of credit to bank “insiders,” such as board directors, executives and major shareholders.

NEWSBYTES

ABA, MBA release ad encouraging Sen. Hyde-Smith to continue championing economic growth

October 6, 2026

ABA seeks more coordination among banking agencies in rewriting disclosure rules

October 6, 2026

ABA announces investment in BankTech Ventures

October 6, 2026

SPONSORED CONTENT

The Shift from Demographic Marketing

The Shift from Demographic Marketing

October 1, 2026
Meeting Ag Lending Goals Without Going It Alone

Meeting Ag Lending Goals Without Going It Alone

October 1, 2026
Beyond the Portfolio: The Wealth Manager’s New Role in a Multigenerational World

Beyond the Portfolio: The Wealth Manager’s New Role in a Multigenerational World

September 17, 2026
Banking Technology at a Strategic Crossroads

Banking Technology at a Strategic Crossroads

September 8, 2026

PODCASTS

Podcast: Creating seamless customer experiences

September 30, 2026

Podcast: Telling a different kind of story about community banks

September 28, 2026

Podcast: Making the jump from a high performer to a high-performing leader

September 16, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.